Implementation of privacy by design model to an eHealth information system

Matjaž Drev, D. Stanimirović, Boštjan Delak
{"title":"Implementation of privacy by design model to an eHealth information system","authors":"Matjaž Drev, D. Stanimirović, Boštjan Delak","doi":"10.36965/ojakm.2022.10(1)77-87","DOIUrl":null,"url":null,"abstract":"This paper reports ongoing research on the process and results of implementing a conceptual model of privacy by design. The model is based on building blocks derived from a comparative analysis of approaches to privacy by design by different authors. We then implemented the model to the data processing operations of Slovenia's central health information system (eHealth). The main goal of our research was to ensure personal data processing compliance with the General Data Protection Regulation (GDPR) and privacy by design criteria set by the model. Findings were used to answer the research questions: whether the proposed conceptual model is general enough to be used in most personal data processing operations, regardless of context; does the successful implementation of conceptual model requirements in personal data processing operations lead to compliance with the GDPR and with the additional requirements of privacy by design, and is the efficiency of complying with personal data processing higher when using the conceptual model compared to other approaches. Current results show that the model is robust enough to be used in a complex system of personal data processing. It also enables a relatively quick assessment of the gap between the actual and target situation, while suggesting which measures should be taken to comply. However, the model still must be tested in several organizations and other contexts of personal data processing, as only a comparative meta-analysis can provide reliable answers to the questions posed.","PeriodicalId":325473,"journal":{"name":"Online Journal of Applied Knowledge Management","volume":"469 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-09-06","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Online Journal of Applied Knowledge Management","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.36965/ojakm.2022.10(1)77-87","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

This paper reports ongoing research on the process and results of implementing a conceptual model of privacy by design. The model is based on building blocks derived from a comparative analysis of approaches to privacy by design by different authors. We then implemented the model to the data processing operations of Slovenia's central health information system (eHealth). The main goal of our research was to ensure personal data processing compliance with the General Data Protection Regulation (GDPR) and privacy by design criteria set by the model. Findings were used to answer the research questions: whether the proposed conceptual model is general enough to be used in most personal data processing operations, regardless of context; does the successful implementation of conceptual model requirements in personal data processing operations lead to compliance with the GDPR and with the additional requirements of privacy by design, and is the efficiency of complying with personal data processing higher when using the conceptual model compared to other approaches. Current results show that the model is robust enough to be used in a complex system of personal data processing. It also enables a relatively quick assessment of the gap between the actual and target situation, while suggesting which measures should be taken to comply. However, the model still must be tested in several organizations and other contexts of personal data processing, as only a comparative meta-analysis can provide reliable answers to the questions posed.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
隐私设计模型在电子健康信息系统中的实现
本文报告了通过设计实现隐私概念模型的过程和结果。该模型基于不同作者对隐私设计方法的比较分析得出的构建块。然后,我们将该模型应用到斯洛文尼亚中央卫生信息系统(eHealth)的数据处理操作中。我们研究的主要目标是通过模型设定的设计标准确保个人数据处理符合通用数据保护条例(GDPR)和隐私。研究结果被用来回答研究问题:所提出的概念模型是否足够普遍,可以在大多数个人数据处理操作中使用,而不考虑上下文;在个人数据处理操作中成功实施概念模型要求是否会导致遵守GDPR和设计上的额外隐私要求,并且与其他方法相比,使用概念模型时遵守个人数据处理的效率是否更高。目前的结果表明,该模型具有足够的鲁棒性,可以用于复杂的个人数据处理系统。它还能够相对迅速地评估实际情况与目标情况之间的差距,同时建议应采取哪些措施予以遵守。然而,该模型仍然必须在几个组织和其他个人数据处理环境中进行测试,因为只有比较元分析才能为所提出的问题提供可靠的答案。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Understanding knowledge hiding behaviors in the workplace using a serious game data collection approach Special issue editorial: Knowledge hiding and knowledge hoarding in different environments Knowledge hiding and knowledge hoarding: Using grounded theory for conceptual development The impact of knowledge hiding and toxic leadership on knowledge worker productivity – Evidence from IT sector of Pakistan Pilot testing of experimental procedures to measure user's judgment errors in simulated social engineering attacks
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1