Assessing Software Privacy using the Privacy Flow-Graph

09/07/2022
by   Feiyang Tang, et al.
0

We increasingly rely on digital services and the conveniences they provide. Processing of personal data is integral to such services and thus privacy and data protection are a growing concern, and governments have responded with regulations such as the EU's GDPR. Following this, organisations that make software have legal obligations to document the privacy and data protection of their software. This work must involve both software developers that understand the code and the organisation's data protection officer or legal department that understands privacy and the requirements of a Data Protection and Impact Assessment (DPIA). To help developers and non-technical people such as lawyers document the privacy and data protection behaviour of software, we have developed an automatic software analysis technique. This technique is based on static program analysis to characterise the flow of privacy-related data. The results of the analysis can be presented as a graph of privacy flows and operations - that is understandable also for non-technical people. We argue that our technique facilitates collaboration between technical and non-technical people in documenting the privacy behaviour of the software. We explain how to use the results produced by our technique to answer a series of privacy-relevant questions needed for a DPIA. To illustrate our work, we show both detailed and abstract analysis results from applying our analysis technique to the secure messaging service Signal and to the client of the cloud service NextCloud and show how their privacy flow-graphs inform the writing of a DPIA.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
03/22/2020

Annotation-Based Static Analysis for Personal Data Protection

This paper elaborates the use of static source code analysis in the cont...
research
03/16/2023

Static Analysis for Android GDPR Compliance Assurance

Many Android applications collect data from users. When they do, they mu...
research
12/21/2022

PABAU: Privacy Analysis of Biometric API Usage

Biometric data privacy is becoming a major concern for many organization...
research
08/25/2022

Embedding Privacy Into Design Through Software Developers: Challenges Solutions

To make privacy a first-class citizen in software, we argue for equippin...
research
01/18/2021

Data Protection Impact Assessment for the Corona App

Since SARS-CoV-2 started spreading in Europe in early 2020, there has be...
research
11/26/2021

A Proposal for Amending Privacy Regulations to Tackle the Challenges Stemming from Combining Data Sets

Modern information and communication technology practices present novel ...
research
10/14/2021

Privacy Impact Assessment: Comparing methodologies with a focus on practicality

Privacy and data protection have become more and more important in recen...

Please sign up or login with your details

Forgot password? Click here to reset