Axel Polleres http://polleres.net Twitter: @AxelPolleres Technical aspects vs. Innovation challenges of Enabling and Enhancing Privacy Axel Polleres http://polleres.net.

Slides:



Advertisements
Similar presentations
ICT10 - Collective Awareness Platforms for Sustainability and Social Innovation.
Advertisements

This project is partially funded by the European Union’s Seventh Framework Programme: FP7-ICT and Grant agreement no: REPUBLIC OF SLOVENIA.
FI-WARE – Future Internet Core Platform FI-WARE Security July 2011 High-level Description.
CREATING THE ENTERPRISE SOCIAL MEDIA GAME PLAN September 2013.
Enforcing Policies on Social Media Data Extracted from the Web Nicoletta Fornara and Truc-Vien T. Nguyen Università della Svizzera italiana Lugano, Switzerland.
1 Privacy issues on pan-European White Pages service 4rd TF-LSD Meeting Amsterdam, Peter Gietz
WORKSHOP, Nicosia 2-3rd July 2008 “Extension of SAFETY & QUALITY Common Requirements to the EMAC States” Item 3 : Regulatory Context Peter Stastny EUROCONTROL.
IBT - Electronic Commerce Privacy Concerns Victor H. Bouganim WCL, American University.
Europe's work in progress: quality of mHealth Pēteris Zilgalvis, J.D., Head of Unit, Health and Well-Being, DG CONNECT Voka Health Community 29 September.
What’s MPEG-21 ? (a short summary of available papers by OCCAMM)
Authentication and Authorisation for Research and Collaboration Licia Florio AARC Workshop The AARC Project Brussels, 26 October.
Vienna Music Business Research Days The Proposal of the EU Commission for a Directive on Collecting Societies and Cultural Diversity – a Missed Opportunity.
19-20 October 2010 IT Directors’ Group meeting 1 Item 6 of the agenda ISA programme Pascal JACQUES Unit B2 - Methodology/Research Local Informatics Security.
Presentation Title Data Protection The new EU Regulation Insert your logo here.
Your Code of Conduct: Data Protection & Compliance Your Code of Conduct: Data Protection & Compliance for Charities.
Business Challenges in the evolution of HOME AUTOMATION (IoT)
Protection of Personal Information Act An Analysis on the impact.
František Nonnemann Skopje, 10th October 2012 JHA Data protection and re-use of PSI as a tool for public control–CZ approach.
Digital Single Market Valentinas KVIETKUS Baltic Assembly, Ryga
General Data Protection Regulation (EU 2016/679)
Profile & Privacy Management Dashboard
Consent and Contract under EU Data Protection Law
Key changes with the GDPR
General Data Protection Regulations: The Key Changes
EU General Data Protection regulation (GDPR)
Axel Polleres, Vienna University of Economics and Business (WU Wien)
Update from the Faster Payments Task Force
10 year investment plan ERGEG approach and contribution
THE 6TH ANNUAL BCLT PRIVACY LAW FORUM: Silicon Valley
General Data Protection Regulation (GDPR)
Presentation to GTMC on GDPR
Similarities between Grid-enabled Medical and Engineering Applications
GDPR – Legal Aspects Desislava Krusteva, Attorney-at-Law, CIPP/E
ServiceNow Implementation Knowledge Management
General Data Protection Regulation
IEEE Initiatives in Artificial Intelligence and Autonomous Systems
KEY CHANGES TO THE DATA PROTECTION LANDSCAPE
Museums + Heritage webinar, 30 November 2017
12: :00     Welcome   13: :55     Terumo and Flexso will share insights on the successful implementation of SuccessFactors Compensation module.
Three Reasons Why Land Solutions Should be Open and Interoperable
Bob Siegel President Privacy Ref, Inc.
GENERAL DATA PROTECTION REGULATION (GDPR)
6 Principles of the GDPR and SQL Provision
Scalable Policy-awarE Linked Data arChitecture for prIvacy, trAnsparency and compLiance H2020-ICT Big Data PPP: privacy-preserving Big Data technologies.
Introduction to GDPR 09/11/2018.
Before starting with your Pitch Deck please
Are you processing personal data lawfully?
EOSC Governance Development Forum
State of the privacy union
From DPA to GDPR: the key elements
PLUG-N-HARVEST ID: H2020-EU
The GDPR & Schools - An Introduction -
Privacy: Standards and Vocabularies for Transparency & Interoperability Axel Polleres Joint work with: Piero Bonatti, Bert Bos, Stefan Decker, Javier D.
The ERA.Net instrument Aims and benefits
Institutional Framework, Resources and Management
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
Privacy and Transparency Interoperability, Standards and Vocabularies
Information technologies/NBIC and Big data
GDPR Workshop MEU Symposium Prague 2018
GDPR enforcement begins
BMV Leisure & Shaftesbury Luxury Lodges GDPR Statement
Information Handling Research Student Induction Day
The General Data Protection Regulation: Are You Ready?
IEEE Initiatives in Artificial Intelligence and Autonomous Systems
General Data Protection regulation (GDPR)
INNOVATION DEALS: A NEW APPROACH TO REGULATION
General Data Protection Regulation (GDPR)
Protection of Privacy Online CAIGF2017-Dushanbe, Tajikistan
Data Privacy by Design Expanding Security for bepress Users
AB 1755 The Open and Transparent Water Data Act
Presentation transcript:

Axel Polleres http://polleres.net Twitter: @AxelPolleres Technical aspects vs. Innovation challenges of Enabling and Enhancing Privacy Axel Polleres http://polleres.net Twitter: @AxelPolleres (Thanks for their contributions to: Sabrina Kirrane, Erwin Filtz, Sushant Agarwal, Javier Fernandez,…)

Where I am coming from, collaborators… Privacy & Sustainable Computing Lab http://www.privacylab.at/ Launched September 2016, launch event with various important stakeholders: technologists, standardization, activists… Goal: setting new standards in research, education and practice to address ethical issues in computing. Dr. Sabrina Kirrane (Lab Director) Prof. Sarah Spiekermann (co-founder) Prof. Axel Polleres (co-founder)

Privacy in the EU: all about the upcoming GDPR, various national and European research efforts… Trilogue starts 6/24/2015 Draft of the regulation EU Council finalises the chapters Comes into force 7/22/2012 8/6/2015 5/15/2018 Revisions in the draft Discussions in the EU Council Trilogue agrees 3/12/2013 5/19/2014 12/17/2015 2013 2014 2015 2016 2017 2018

Main technical challenges (prioritized from our point of view) Informed Consent & Policies Transparency, Deletion Subjectivity Anonymization Last, but not least, and for all these challenges: Protection vs. Innovation?

Consent & Policies GDPR requirements: Opt-in, consent declarations Demonstrate consent Freely given Clearly distinguishable Withdraw consent at any time Article # Title Description 7 Conditions for consent Controllers should be able to demonstrate the 'freely given' consent from data subjects and should provide the right to withdraw consent any time Discussion: How to guarantee opt-in has been understood? Policy templates, “Privacy Icons” Research proposes that opt-out, interactive processes, and partial consent are more intuitive than opt-in by monolithic consent forms Giving consent online has many behavioural and UI components! Can I delegate consent to a personal agent? How to express and execute consent policies in provable machine readable form? Would that legally hold? backup

Transparency, Access, Rectification, Deletion Article # Title Description 12 Transparent information, communication and modalities for the exercise of the rights of the data subject To provide info related to processing in concise, transparent, intelligible and easily accessible form, using clear and plain language.. 15 Right of access for the data subject Right to access personal data which is collected and processed and to know which data is processed 16 Right to rectification Right to ask controllers to rectify any inaccurate personal data regarding them 17 Right to erasure (“right to be forgotten”) Right to ask controllers to delete their personal data 18 Right to restriction of processing Right to ask controllers to restrict processing of personal data Trust via Transparency Concise, transparent, intelligible and easily accessible information about processing Using clear and plain language Standardized icons (machine-readable) Discussion: Develop agreed models to present transparency data in a standardized manner, allowing the user to access the data collected about them in an integrated manner (e.g. Linked Data, PROV, extensions…) Open questions in terms of deletes (e.g. feasibility of Hard deletes in cloud environments) vs. transparency demands. Protocols to store transparency information (Blockchain is not the only option!) Transparent Personal Data Processing: The Road Ahead Piero Bonatti, Sabrina Kirrane, Axel Polleres, and Rigo Wenning TELERISE: 3rd International Workshop on TEchnical and LEgal aspects of data pRIvacy and SEcurity @ SAFECOMP2017 (to appear)

? > Subjectivity Ambiguity/Room for interpretation in the GDPR e.g. conflicting(national) laws with the GDPR Different national interpretations ? > Rights to protection of property Rights of privacy Directive on electronic commerce (2000/31/EC) Copyright directive (2001/29/EC) Directive on the enforcement of intellectual property rights (2004/48/EC) Charter of Fundamental Rights of the European Union (Art 17(2)) Data Protection Directive (95/46/EC) Directive on privacy and electronic communications (2002/58/EC) Charter of Fundamental Rights of the European Union (Art 7, 8) Discussion: Metrics for e.g. understandability of privacy terms Standardization? Investigate/analyze case law

Anonymization for Innovation? Which K should we use for K-Anonymity? K-Anonymity is not enough! Best practices and industry strength tools needed! The GDPR does not apply to anonymous data where the data subject is no longer identifiable.

Our current solution approach: The SPECIAL project https://www.specialprivacy.eu/

Our current solution approach: The SPECIAL project Objectives Policy management framework Gives users control of their personal data Represents access/usage policies and legislative requirements in a machine readable format Transparency and compliance framework Provides information on how data is processed and with whom it is shared Allows data subjects to take corrective action Scalable policy-aware Linked Data architecture Build on top of the Big Data Europe (BDE) platform scalability and elasticity mechanisms Extended BDE with robust policy, transparency and compliance protocols

SPECIAL Technical components: Big Data Europe scalability and elasticity PrimeLife policy languages, access control policies, release policies and data handling policies

Technical aspects vs. Innovation challenges Summary and input for discussion: Technical support for privacy should be understood as an innovation driver/asset, not an obstacle! Many opportunities for tools and algorithmic support E.g. formalizing and reasoning about Policies + data analytics about case law (=Rules + Data Science) UIs, Standards, Best Practices Linked Data for Privacy! Take the enterprise view of Big Data analysis into account! Harmonization on Privacy law alone is not enough, but also on the national interpretations and conflicting laws! Thank you!