The International Association of Privacy Professionals opening remark when addressing the question “What does privacy mean?” perhaps quizzically state “Well, it depends who you ask.” While privacy is multifaceted we advocate utilisation of definitions from UK and European data protection law, the accompanying data protection principles, data protection impact assessment/privacy by design and default, and practical learnings from case law. There is a common language and body of knowledge which can be applied to inform and embed privacy by design and default into the thinking and work of engineers, organisations, where privacy (practical application and responses to each of the data protection principles) is suitably hardcoded into the fabric of product/service design, and operation. The language, jurisprudence and practical application of data protection law should not remain siloed and the sole preserve of data protection officers. To provide effective privacy to individuals as technologies, data, big data, the Internet of Things, and Artificial Intelligence become ubiquitous across all aspects of our lives, we advocate that a multidisciplinary approach is fundamental. Privacy by design and by default is a realistic methodology to meet current and future privacy challenges. However, essentially the language, thinking and practical application of data protection law is largely isolated and evident from the work of data protection practitioners. Where the language and knowledge gap is bridged across both disciplines, essentially developing and applying a multidisciplinary approach to data protection by design and default, we may create pathways where privacy solutions can be usefully identified, developed, applied and operate at component, product, data, system and service levels. The argument that privacy law needs to catch-up with technology is often played out. Arguably not; perhaps multidisciplinary thinking and working is needed?

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Privacy

  • Christopher Milne,
  • Steven A. Watt

摘要

The International Association of Privacy Professionals opening remark when addressing the question “What does privacy mean?” perhaps quizzically state “Well, it depends who you ask.” While privacy is multifaceted we advocate utilisation of definitions from UK and European data protection law, the accompanying data protection principles, data protection impact assessment/privacy by design and default, and practical learnings from case law. There is a common language and body of knowledge which can be applied to inform and embed privacy by design and default into the thinking and work of engineers, organisations, where privacy (practical application and responses to each of the data protection principles) is suitably hardcoded into the fabric of product/service design, and operation. The language, jurisprudence and practical application of data protection law should not remain siloed and the sole preserve of data protection officers. To provide effective privacy to individuals as technologies, data, big data, the Internet of Things, and Artificial Intelligence become ubiquitous across all aspects of our lives, we advocate that a multidisciplinary approach is fundamental. Privacy by design and by default is a realistic methodology to meet current and future privacy challenges. However, essentially the language, thinking and practical application of data protection law is largely isolated and evident from the work of data protection practitioners. Where the language and knowledge gap is bridged across both disciplines, essentially developing and applying a multidisciplinary approach to data protection by design and default, we may create pathways where privacy solutions can be usefully identified, developed, applied and operate at component, product, data, system and service levels. The argument that privacy law needs to catch-up with technology is often played out. Arguably not; perhaps multidisciplinary thinking and working is needed?