Privacy protection is a fundamental right in the EU, codified in regulations such as the GDPR, and a key prerequisite for developing compliant AI-powered Cyber-Physical Systems. However, its complexity poses major implementation challenges for organizations. Privacy Patterns (PP) offer best practices for addressing privacy concerns, but critical gaps remain: missing legal links, fragmented knowledge, limited centralized access, and insufficient guidance for selection and application. This research introduces the early-stage conceptual framework, the Data & Process Privacy Pattern Model (DPPPM), to bridge these gaps by linking PP to GDPR requirements, while illustrating best practices through privacy workflows. The DPPPM is embedded within a PP Toolkit, featuring a centralized online catalog with context-sensitive selection capabilities. Initial evaluations indicate that privacy workflows based on this framework support privacy-by-design, connecting legal obligations with operational processes and enhancing data protection in business processes and information systems.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Pattern-Based Approach to Data Privacy in Business Processes

  • Lukas Waidelich,
  • Thomas Schuster

摘要

Privacy protection is a fundamental right in the EU, codified in regulations such as the GDPR, and a key prerequisite for developing compliant AI-powered Cyber-Physical Systems. However, its complexity poses major implementation challenges for organizations. Privacy Patterns (PP) offer best practices for addressing privacy concerns, but critical gaps remain: missing legal links, fragmented knowledge, limited centralized access, and insufficient guidance for selection and application. This research introduces the early-stage conceptual framework, the Data & Process Privacy Pattern Model (DPPPM), to bridge these gaps by linking PP to GDPR requirements, while illustrating best practices through privacy workflows. The DPPPM is embedded within a PP Toolkit, featuring a centralized online catalog with context-sensitive selection capabilities. Initial evaluations indicate that privacy workflows based on this framework support privacy-by-design, connecting legal obligations with operational processes and enhancing data protection in business processes and information systems.