Toward Compliance Implications and Security Objectives: A Qualitative Study
Dmitry Prokhorenkov · 2023
Presently, personal data protection and supplementary methods delivering the required level of confidentiality may not fulfil the existing European Union legal standards. Moreover, it still has numerous research gaps. Therefore, the most crucial objective demanded by multiple stakeholders is securing the correct application of privacy-enhancing technology (PET) methods concerning General Data Protection Regulation (GDPR) compliance. However, no review and analysis of the overlap exist between the PET and compliance domains focusing on security goals and the anonymization level. Consequently, this study focuses on the implications of security goals and Data Privacy Impact Assessment (DPIA) introduced in GDPR to enhance personal data security from the respondent’s group standpoint, namely data protection officers, software developers, privacy legal practitioners and privacy researchers. Additionally, the consequence of different levels of anonymization, security goals, and PET method (Differential Privacy) concerning appropriate compliance will be studied. More importantly, our research method relies on a literature review and a detailed survey with a specific group of respondents. Therefore, this review provides a snapshot of the current situation between the needs of a particular group of respondents and security goals, with an additional focus on different anonymization levels and compliance requirements.