Consent Verification Under Evolving Privacy Policies
- Marco Robol,
- Travis D. Breaux,
- ,
- Paolo Giorgini
- Department of Information Engineering and Computer Science, University of Trento,
- Carnegie Mellon University,
- ,
Research Output:
Conference Article in Proceeding or Book/Report chapter
Article in proceedings
Peer-reviewOpen access
Publication Information
Output type
Research Output:
Conference Article in Proceeding or Book/Report chapter
Article in proceedings
Peer-reviewOriginal language
EnglishPages from-to (Number of pages)
Pages 422-427 (6 pages)Publication milestones
- Published - 23/09/2019
Publication status
Published - 23/09/2019
Place of publication
Conf. Location: Jeju Island, Korea (South)Publisher
IEEE, United StatesISBN (Print)
978-1-7281-3913-5ISBN (Electronic)
978-1-7281-3912-8Publication IDs
- Scopus: 85076903260
Host publication title
Proceedings of the IEEE 27th International Requirements Engineering Conference (RE'19)Abstract
Personal data provides important business value, for example, in the personalization of services. In addition, companies are moving toward new business models, in which products and services are offered without charge to users, but in exchange for targeted advertising revenue. New privacy regulations require organizations to explicitly state their data practices in privacy policies, including which data types will be collected. By consenting to data collections described in a policy, the user acknowledges that he or she is granting the company the authorizations needed to access their data. When data practices change, a new version of the policy is released. This release can occur a few times a year, when requirements are rapidly changing for the collection and processing of personal data. Furthermore, the user may change his or her privacy consent by opting in or out of the policy. We propose a formal framework to support companies and users in their understanding of policies evolution under consent regime that supports both retroactive and non-retroactive consent and consent revocation. Preliminary results include an ontology for policy evolution, expressed in Description Logic, that can be used to formalize consent and data collection logs and then query for which data types can be legally accessed.
Publication metrics
PlumX, opens in new tab
Citations
8
Captures
22
Access to documents
Accepted author manuscript, 398.98 KB
