Technical and Organisational Implementation of Data Protection
摘要
There is a large number of concepts and frameworks for implementing the data protection requirements into (IT and other) systems. Individual measures to do so are often summarised as technical and organisational measures. Technologies that support privacy, often by allowing to process data while limiting data access, are known as privacy-enhancing technologies. Examples of such technologies include anonymisation, federated learning or synthetic data generation. A very fundamental approach to implementing data protection is data protection by design, as required by the GDPR. This is based on the idea that data protection needs to be implemented in the development of systems from the start. Data protection needs to be integrated into the design of a system from the outset and across the entire life cycle, not as an issue that is implemented at the end through a data protection review and subsequent adaptation of the system.