{"title":"运用MCDA选择符合LGPD的个人资料保安标准","authors":"Renato Carauta Ribeiro, E. Canedo","doi":"10.1145/3396956.3398252","DOIUrl":null,"url":null,"abstract":"The protection of personal data is a problem that has been discussed in several countries. Most countries create laws and regulations to protect fundamental rights and privacy. The main data protection regulation approved by the European Union (EU) is the General Data Protection Regulation (GDPR). This regulation regulates how personal data should be protected and how data may be shared between other countries. Brazil recently enacted the Brazilian General Data Protection Law (LGPD) with various standards for security and privacy of personal data. This paper aims to select the best alternatives for the implementation of security criteria at the University of Brasília (UnB). We use the Multiple Criteria Decision Analysis (MCDA) process with the Preference Ranking Organization Method for Enriched Evaluation (PROMETHEE) II method to select the best to worst alternatives, according to the criteria selected in the MCDA process using the method Analytic Hierarchy Process (AHP). The results found demonstrate that the Data Privacy Risks criterion is the highest priority criterion for the implementation of personal data security at UnB since LGPD’s main objective is to keep personal data private and accessible only to the data subject. Furthermore, it was found that the LGPD principles with the highest implementation priority were: 0.28 Priority Security, 0.26 Priority Needs and 0.25 Priority Prevention.","PeriodicalId":93488,"journal":{"name":"Proceedings of the ... International Conference on Digital Government Research. International Conference on Digital Government Research","volume":null,"pages":null},"PeriodicalIF":0.0000,"publicationDate":"2020-06-15","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"12","resultStr":"{\"title\":\"Using MCDA for Selecting Criteria of LGPD Compliant Personal Data Security\",\"authors\":\"Renato Carauta Ribeiro, E. Canedo\",\"doi\":\"10.1145/3396956.3398252\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The protection of personal data is a problem that has been discussed in several countries. Most countries create laws and regulations to protect fundamental rights and privacy. The main data protection regulation approved by the European Union (EU) is the General Data Protection Regulation (GDPR). This regulation regulates how personal data should be protected and how data may be shared between other countries. Brazil recently enacted the Brazilian General Data Protection Law (LGPD) with various standards for security and privacy of personal data. This paper aims to select the best alternatives for the implementation of security criteria at the University of Brasília (UnB). We use the Multiple Criteria Decision Analysis (MCDA) process with the Preference Ranking Organization Method for Enriched Evaluation (PROMETHEE) II method to select the best to worst alternatives, according to the criteria selected in the MCDA process using the method Analytic Hierarchy Process (AHP). The results found demonstrate that the Data Privacy Risks criterion is the highest priority criterion for the implementation of personal data security at UnB since LGPD’s main objective is to keep personal data private and accessible only to the data subject. Furthermore, it was found that the LGPD principles with the highest implementation priority were: 0.28 Priority Security, 0.26 Priority Needs and 0.25 Priority Prevention.\",\"PeriodicalId\":93488,\"journal\":{\"name\":\"Proceedings of the ... International Conference on Digital Government Research. International Conference on Digital Government Research\",\"volume\":null,\"pages\":null},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2020-06-15\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"12\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Proceedings of the ... International Conference on Digital Government Research. International Conference on Digital Government Research\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1145/3396956.3398252\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the ... International Conference on Digital Government Research. International Conference on Digital Government Research","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3396956.3398252","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Using MCDA for Selecting Criteria of LGPD Compliant Personal Data Security
The protection of personal data is a problem that has been discussed in several countries. Most countries create laws and regulations to protect fundamental rights and privacy. The main data protection regulation approved by the European Union (EU) is the General Data Protection Regulation (GDPR). This regulation regulates how personal data should be protected and how data may be shared between other countries. Brazil recently enacted the Brazilian General Data Protection Law (LGPD) with various standards for security and privacy of personal data. This paper aims to select the best alternatives for the implementation of security criteria at the University of Brasília (UnB). We use the Multiple Criteria Decision Analysis (MCDA) process with the Preference Ranking Organization Method for Enriched Evaluation (PROMETHEE) II method to select the best to worst alternatives, according to the criteria selected in the MCDA process using the method Analytic Hierarchy Process (AHP). The results found demonstrate that the Data Privacy Risks criterion is the highest priority criterion for the implementation of personal data security at UnB since LGPD’s main objective is to keep personal data private and accessible only to the data subject. Furthermore, it was found that the LGPD principles with the highest implementation priority were: 0.28 Priority Security, 0.26 Priority Needs and 0.25 Priority Prevention.