Privacy Policy Referencing

  • Audun Jøsang
  • Lothar Fritsch
  • Tobias Mahler

Publikasjonsdetaljer

  • Journal: Lecture Notes in Computer Science (LNCS), vol. 6264, p. 129–140–12, 2010
  • Utgiver: Springer
  • Internasjonale standardnumre:
    • Trykt: 0302-9743
    • Elektronisk: 1611-3349

Data protection legislation was originally defined for a context where personal information is mostly stored on centralized servers with limited connectivity and openness to 3rd party access. Currently, servers are connected to the Internet, where a large amount of personal information is continuously being exchanged as part of application transactions. This is very different from the original context of data protection regulation. Even though there are rather strict data protection laws in an increasing number of countries, it is in practice rather challenging to ensure an adequate protection for personal data that is communicated on-line. The enforcement of privacy legislation and policies therefore might require a technological basis, which is integrated with adequate amendments to the legal framework. This article describes a new approach called Privacy Policy Referencing, and outlines the technical and the complementary legal framework that needs to be established to support it.