Changes in Conducting Data Protection Risk Assessment and After GDPR implementation

04/24/2023
by   Fatemeh Zarrabi, et al.
0

Based on Article 35 of the EU (European Union) General Data Protection Regulation, a Data Protection Impact Assessment (DPIA) is necessary whenever there is a possibility of a high privacy and data protection risk to individuals caused by a new project under development. A similar process to DPIA had been previously known as Privacy Impact Assessment (PIA). We are investigating here to find out if GDPR and DPIA specifically as its privacy risk assessment tool have resolved the challenges privacy practitioners were previously facing in implementing PIA. To do so, our methodology is based on comparison and thematic analysis on two sets of focus groups we held with privacy professionals back in January 2018 (four months before GDPR came into effect) and then in November 2019 (18 months after GDPR implementation).

READ FULL TEXT
research
10/14/2021

Privacy Impact Assessment: Comparing methodologies with a focus on practicality

Privacy and data protection have become more and more important in recen...
research
03/31/2021

The Kaleidoscope of Privacy: Differences across French, German, UK, and US GDPR Media Discourse

Conceptions of privacy differ by culture. In the Internet age, digital t...
research
08/31/2022

Connecticut Redistricting Analysis

Connecticut passed their new state House of Representatives district pla...
research
09/13/2021

Fairness and Data Protection Impact Assessments

In this paper, we critically examine the effectiveness of the requiremen...
research
11/20/2021

You Overtrust Your Printer

Printers are common devices whose networked use is vastly unsecured, per...
research
02/20/2023

A Text Mining Analysis of Data Protection Politics: The Case of Plenary Sessions of the European Parliament

Data protection laws and policies have been studied extensively in recen...

Please sign up or login with your details

Forgot password? Click here to reset