Trust Management XIII - 13th IFIP WG 11.11 International Conference, IFIPTM 2019, Copenhagen, Denmark, July 17-19, 2019, Proceedings

Trust Management XIII - 13th IFIP WG 11.11 International Conference, IFIPTM 2019, Copenhagen, Denmark, July 17-19, 2019, Proceedings
复制标题

信托管理 XIII - 第 13 届 IFIP WG 11.11 国际会议,IFIPTM 2019,丹麦哥本哈根,2019 年 7 月 17-19 日,会议记录

DOI:
10.1007/978-3-030-33716-2_3
复制
发表时间:
2019
期刊:
--
影响因子:
--
通讯作者:
Schuler Scott A
Schuler Scott A
中科院分区:
--
文献类型:
--
作者:
Schuler Scott A

文献摘要

相似文献

动态同意在理论上已经被讨论过,作为一种在出于研究目的访问和共享数据时考虑用户偏好的方式。该机制基于撤销和参与的原则-参与者可以随时撤销或编辑他们的权限,如果他们选择这样做,他们会收到关于他们正在贡献的项目的反馈。动态同意提供的精细控制水平意味着个人对他们与研究共享的内容以及数据可以进一步使用的程度拥有信息控制权。而不是试图重新定义隐私,本文采取的立场,数据控制者有一定的义务,以保护数据主体的信息,必须显示值得信赖的行为,以鼓励研究参与。我们的隐私模型基于规范的、基于交易的要求。我们认为,动态同意是一种机制,为数据控制者提供了一种证明遵守个人隐私偏好的方法,并为数据主体提供了在需要时进行控制的方法。动态同意与由具有主体撤销访问能力的数据集组成的“丰富”数据库之间的关键区别是人类参与或信任关系。我们必须重新思考如何自上而下(基于策略)和自下而上(技术架构)实施同意,以开发有用的隐私控制。
Dynamic consent has been discussed in theory as a way to show user preferences being taken into account when data is accessed and shared for research purposes. The mechanism is grounded in principles of revocation and engagement – participants may withdraw or edit their permissions at any time, and they receive feedback on the project they are contributing to if they have chosen to do so. The level of granular control offered by dynamic consent means that individuals have informational control over what they are sharing with the study, and to what extent that data can be used further. Rather than attempt to redefine privacy, this paper takes the position that data controllers have certain obligations to protect a data subject’s information and must show trustworthy behaviour to encourage research participation. Our model of privacy is grounded in normative, transaction-based requirements. We argue that dynamic consent is a mechanism that offers data controllers a way to evidence compliance with individual privacy preferences, and data subjects with control as and when they require it. The key difference between dynamic consent and a “rich” database consisting of a dataset with the ability for a subject to revoke access is human engagement, or relations of trust. We must re-think how consent is implemented from the top-down (policy-based) and bottom up (technical architecture) to develop useful privacy controls.