Data Processing Diagrams
摘要
Modern software systems can feature complex data processing, with multiple parties processing various data for different purposes, including training or application of AI. Development of such systems typically involves a multidisciplinary team with different viewpoints. To effectively and efficiently design for privacy requires a multidisciplinary and coordinated effort. We introduce Data Processing Diagrams, an extension of popular Data Flow Diagrams, with standardized notation for fundamental forms of data processing such as data deletion, distribution, encryption and pseudonymization/anonymization. With these extensions, application of well-known privacy design strategies and tactics in complex data processing systems can be reflected. We consider this crucial for unambiguous communication, especially in the earliest design phases of new systems, to quickly compare different architectures and use the models as blueprints for development. We validate the effectiveness of our technique as a shared language between multidisciplinary stakeholders in the context of different co-creation projects that are part of the Dutch National Education Lab AI (NOLAI).