A Quantitative Methodology for Business Process-Based Data Privacy Risk Computation

Asmita Manna,Anirban Sengupta,Chandan Mazumdar
DOI: https://doi.org/10.1007/978-981-13-8969-6_2
2019-08-29
Abstract:The imminent introduction of the Data Protection Act in India would make it necessary for almost all enterprises, dealing with personal data, to implement privacy-specific controls. These controls would serve to mitigate the risks that breach the privacy properties of user data. Hence, the first step toward implementing such controls is the execution of privacy risk assessment procedures that would help elicit the privacy risks to user data. All user data are processed/managed by one or more business processes. Hence, assessment of privacy risks to user data should consider the vulnerabilities within, and threats to, corresponding business process. It should also consider different perspectives, namely business, legal and contractual needs, and users’ expectations, during the computation of data privacy values. This paper proposes such a comprehensive methodology for identifying data privacy risks and quantifying the same. The risk values are computed at different levels (privacy property level, business process level, etc.) to help both senior management and operational personnel, in assessing and mitigating privacy risks.
What problem does this paper attempt to address?