PRIVACY IMPACT ASSESSMENT

Haris Hamidović

Abstract


Integrating the privacy requirement in the information system design is not an easy task. First of all, privacy is a complex, multiple, and contextual concept in itself. In addition, the issue of privacy is not a primary requirement of the system, and sometimes even this requirement can come into conflict with other (functional or non-functional) requirements of the information system. Therefore, it is of utmost importance to precisely define the objectives of privacy in the process of realizing privacy by design. One way to define the objectives of the information system in terms of the privacy requirement is to conduct a privacy impact assessment or a privacy risk analysis. Conducting a privacy impact assessment is in line with the principles of technical and integrated data protection under Article 25 of the General Data Protection Regulation – GDPR. In accordance with the principles of technical and integrated data protection, a privacy impact assessment should be carried out before the processing itself with the aim of using it as a tool for decision-making, in particular for the selection of appropriate technical protection measures. Although the General Data Protection Regulation does not prescribe any specific methodology or standard for privacy impact assessment in the guidelines of the Article 29 Working Group on Data Protection, there are recommendations for the use of international standards. This paper presents the method of privacy impact assessment based on the recommendations of the French Data Protection Agency and the recommendations of international standards ISO/IEC 29134 and ISO/IEC 27005.

Keywords


privacy, personal data, data protection, privacy impact assessment, GDPR, PIA, ISO/IEC 29134

Full Text:

PDF (Serbian)

References


Breaux T. (2015). Introduction to IT Privacy: A Handbook for Technologists, International Association of Privacy Professionals (IAPP)

CNIL. (2018). Privacy Impact Assessment (PIA) 3 : knowledge bases. Commission Nationale de l'Informatique et des Libertés

CNIL. (2012). Methodology for Privacy Risk Management. Commission Nationale de l'Informatique et des Libertés

Hamidovic, H. (2010). An Introduction to the Privacy Impact Assessment Based on ISO 22307. ISACA Journal. Volume 4, 2010, The Information Systems Audit and Control Association

Hamidović, H. (2010). Priručnik za izradu i reviziju plana sigurnosti osobnih podataka u automatskoj obradi, Info Press, Zagreb,

Hamidović, H. (2019). Obaveza poduzimanja tehničkih mjera zaštite podataka temeljem EU uredbe o zaštiti podataka. FBIM Transactions, 15 04, 7(1), pp. 67-73

Smjernica. (2017). Guidelines on Data Protection Impact Assessment (DPIA) and determining whether processing is “likely to result in a high risk” for the purposes of Regulation 2016/679, Article 29 Working Party

Standard. (2017). ISO/IEC 29134:2017 Information technology -- Security techniques -- Guidelines for privacy impact assessment. International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC)

Standard. (2018). ISO/IEC 27005:2018 Information technology -- Security techniques -- Information security risk management. International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC)

Uredba. (2016, maj 4). Uredba (EU) 2016/679 Europskog parlamenta i Vijeća od 27. aprila 2016. o zaštiti pojedinaca u vezi s obradom osobnih podataka i o slobodnom kretanju takvih podataka te o stavljanju izvan snage Direktive 95/46/EZ (Opća uredba o zaštiti podataka). Službeni list Europske unije, L 119/1

ZIH. (2019). Seminar - Primjena Uredbe o zaštiti osobnih podataka – Radni materijali, Zavod za informatičku djelatnost Hrvatske, Zagreb


Refbacks

  • There are currently no refbacks.