论文标题
公共服务应用程序中隐私设计的操作架构
An operational architecture for privacy-by-design in public service applications
论文作者
论文摘要
全球各国政府正在试图建立大型数据注册机构,以有效地提供各种公共服务。但是,由于对与个人身份信息的收集和处理有关的隐私风险的严重关注,这些努力经常受到破坏。尽管计算机科学中存在着丰富的特殊性隐私技术,但在没有总体操作架构的情况下,他们无法与法律原则保持端到端保护,以确保目的限制和保护内幕攻击。这要么导致大型设计中的隐私保护薄弱,要么采用过度防御性的策略来通过妥协实用性来保护隐私。 在本文中,我们根据大多数数据保护制度,规范的访问控制,目的限制和数据最小化规定的独立监管监督,介绍了一种逐设计的操作体系结构。我们简要讨论基于现有技术实施架构的可行性。我们还提供了一些挑战公共服务应用程序的隐私设计草图的示例案例研究。
Governments around the world are trying to build large data registries for effective delivery of a variety of public services. However, these efforts are often undermined due to serious concerns over privacy risks associated with collection and processing of personally identifiable information. While a rich set of special-purpose privacy-preserving techniques exist in computer science, they are unable to provide end-to-end protection in alignment with legal principles in the absence of an overarching operational architecture to ensure purpose limitation and protection against insider attacks. This either leads to weak privacy protection in large designs, or adoption of overly defensive strategies to protect privacy by compromising on utility. In this paper, we present an operational architecture for privacy-by-design based on independent regulatory oversight stipulated by most data protection regimes, regulated access control, purpose limitation and data minimisation. We briefly discuss the feasibility of implementing our architecture based on existing techniques. We also present some sample case studies of privacy-preserving design sketches of challenging public service applications.