Download as pdf or txt
Download as pdf or txt
You are on page 1of 9

Mapping Legal Privacy Principles to PETs

Introduction to Privacy and the GDPR

Simone Fischer-Hübner

CC-BY-4.0
Principles relating to processing of
personal data

(Art. 5 GDPR):
• lawfulness, fairness and transparency
• purpose limitation
• data minimisation
• data accuracy
• storage limitation
• integrity and confidentiality
• accountability
Mapping to PETs

Privacy Principles (Art. 5 GDPR):


• lawfulness, fairness and Algorithmic Transparency & Ethical Data Management,
Fairness by Design,
transparency Ex ante and ex post Transparency Enhancing Tools,…
• purpose limitation
• data minimisation
• data accuracy
• storage limitation
• integrity and confidentiality
• accountability
Mapping to PETs

Privacy Principles (Art. 5 GDPR):


• lawfulness, fairness and
transparency Privacy policy languages, sticky policies,
Functional separation,…
• purpose limitation
• data minimisation
• data accuracy
• storage limitation
• integrity and confidentiality
• accountability
Mapping to PETs

Privacy Principles (Art. 5 GDPR):


• lawfulness, fairness and PETs for achieving Anonymity / Pseudonymity on:
transparency Communication level: Mixes, DC-nets, Tor,
Steganographic Tools …
• purpose limitation
• data minimisation Application level: Anonymous Credentials, Anonymous
Payment schemes, Private Information Retrieval,…
• data accuracy Data level: k-Anoymity & Differential Privacy
• storage limitation tools/applications, Secret Sharing,….

• integrity and confidentiality


• accountability
Mapping to PETs

Privacy Principles (Art. 5 GDPR):


• lawfulness, fairness and
transparency
• purpose limitation
• data minimisation Integrity controls,
Intervenability tools allowing online corrections/deletions,…
• data accuracy
• storage limitation
• integrity and confidentiality
• accountability
Mapping to PETs

Privacy Principles (Art. 5 GDPR):


• lawfulness, fairness and
transparency
• purpose limitation
• data minimisation Anonymisation tools (e.g., k-anonymity based),
Obligations for data deletions in privacy policy/access
• data accuracy control languages,…
• storage limitation
• integrity and confidentiality
• accountability
Mapping to PETs

Privacy Principles (Art. 5 GDPR):


• lawfulness, fairness and
transparency
• purpose limitation
• data minimisation
Security controls, incl. access control, authentication,
• data accuracy encryption (e.g., TLS), logging,…
• storage limitation
• integrity and confidentiality
• accountability
Mapping to PETs

Privacy Principles (Art. 5 GDPR):


• lawfulness, fairness and
transparency
• purpose limitation
• data minimisation
• data accuracy
• storage limitation
• integrity and confidentiality Privacy-preserving transparency logging, provenence,
consent management…
• accountability

You might also like