Skip to main content
Top

2018 | OriginalPaper | Chapter

Designing a GDPR-Compliant and Usable Privacy Dashboard

Authors : Philip Raschke, Axel Küpper, Olha Drozd, Sabrina Kirrane

Published in: Privacy and Identity Management. The Smart Revolution

Publisher: Springer International Publishing

Activate our intelligent search to find suitable subject content or patents.

search-config
loading …

Abstract

The role of personal data gained significance across all business domains in past decades. Despite strict legal restrictions that processing personal data is subject to, users tend to respond to the extensive collection of data by service providers with distrust. Legal battles between data subjects and processors emphasized the need of adaptations by the current law to face today’s challenges. The European Union has taken action by introducing the General Data Protection Regulation (GDPR), which was adopted in April 2016 and will inure in May 2018. The GDPR extends existing data privacy rights of EU citizens and simultaneously puts pressure on controllers and processors by defining high penalties in case of non-compliance. Uncertainties remain to which extent controllers and processors need to adjust their existing technologies in order to conform to the new law. This work designs, implements, and evaluates a privacy dashboard for data subjects intending to enable and ease the execution of data privacy rights granted by the GDPR.

Dont have a licence yet? Then find out more about our products and how to get one now:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Footnotes
2
What is Snowden effect? - Definition from WhatIs.com. http://​whatis.​techtarget.​com/​definition/​Snowden-effect, last accessed: 07/17/2017.
 
4
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), OJ L 119, 4.5.2016, p. 1–88 [hereinafter GDPR].
 
5
Council Directive 95/46, 1995 O.J. (L 281) 31 (EC) [hereinafter Directive 95/46].
 
6
GDPR art. 5(1)(a).
 
7
GDPR Recital 39.
 
8
GDPR art. 3(2).
 
9
GDPR art. 6(1)(a).
 
10
GDPR art. 6(1)(c).
 
11
GDPR art. 6(1)(e).
 
12
Directive 95/46 art. 6(1)(a).
 
13
GDPR art. 5(1)(a).
 
14
GDPR art. 15(1).
 
15
GDPR art. 16.
 
16
GDPR art. 17(1).
 
17
GDPR art. 12(3).
 
18
Directive 95/46 art. 7(a).
 
19
GDPR art. 6(1)(a).
 
20
GDPR Recital 32.
 
21
GDPR art. 7(3).
 
22
Privacy Bird. http://​www.​privacybird.​org, last accessed: 07/20/2017.
 
23
Privacy Icons. https://​disconnect.​me/​icons, last accessed: 07/20/2017.
 
25
Google Dashboard. https://​myaccount.​google.​com/​dashboard, last accessed: 07/20/2017.
 
26
Lightbeam for Firefox - Mozilla. https://​www.​mozilla.​org/​en-US/​lightbeam, last accessed: 07/20/2017.
 
27
netograph. http://​netograph.​com, last accessed: 07/20/2017.
 
28
WOT (Web of Trust). https://​www.​mywot.​com, last accessed: 07/20/2017.
 
29
Me and my Shadow. https://​myshadow.​org, last accessed: 07/20/2017.
 
30
Firesheep - codebutler. http://​codebutler.​com/​firesheep, last accessed: 07/20/2017.
 
31
Panopticlick. https://​panopticlick.​eff.​org, last accessed: 07/20/2017.
 
32
Creepy by ilektrojohn. http://​www.​geocreepy.​com, last accessed: 07/20/2017.
 
33
mfredrik/Privacy-Bucket Wiki. https://​github.​com/​mfredrik/​Privacy-Bucket/​wiki, last accessed: 07/20/2017.
 
34
pylls/datatrack: A tool that visualizes your data disclosures. https://​github.​com/​pylls/​datatrack, last accessed: 07/20/2017.
 
35
WAI-ARIA (Web Accessibility Initiative). https://​www.​w3.​org/​WAI/​intro/​aria.​php, last accessed: 07/25/2017.
 
39
Eurostat - Internet use and activities. http://​ec.​europa.​eu/​eurostat/​web/​products-datasets/​-/​isoc_​bde15cua, last accessed: 07/25/2017.
 
41
Eurostat - Purpose of mobile internet use. http://​ec.​europa.​eu/​eurostat/​web/​products-datasets/​-/​isoc_​cimobi_​purp, last accessed: 07/25/2017.
 
43
GDPR art. 20.
 
44
React - A JavaScript library for building user interfaces. https://​reactjs.​org/​, last accessed: 11/13/2017.
 
45
Material-UI. http://​www.​material-ui.​com/​, last accessed: 11/13/2017.
 
46
Material Design. https://​material.​io/​, last accessed: 11/13/2017.
 
47
Privacy dashboard | IFIP Summer School 2017. http://​philip-raschke.​github.​io/​GDPR-privacy-dashboard, last accessed: 01/19/2018.
 
48
Jung von Matt study on typical German Facebook profile. https://​de.​linkedin.​com/​pulse/​das-h%C3%A4ufigste-facebook-profil-deutschlands-raphael-brinkert, last accessed: 11/13/2017.
 
49
GDPR art. 26.
 
50
vis.js - A dynamic, browser based visualization library. http://​visjs.​org/​, last accessed: 11/13/2017.
 
51
GDPR art. 7(3).
 
Literature
1.
go back to reference Angulo, J., Fischer-Hübner, S., Pulls, T., Wästlund, E.: Usable transparency with the data track - a tool for visualizing data disclosures. In: Proceedings of the 33rd Annual ACM Conference Extended Abstracts on Human Factors in Computing Systems - CHI EA 2015, pp. 1803–1808 (2015) Angulo, J., Fischer-Hübner, S., Pulls, T., Wästlund, E.: Usable transparency with the data track - a tool for visualizing data disclosures. In: Proceedings of the 33rd Annual ACM Conference Extended Abstracts on Human Factors in Computing Systems - CHI EA 2015, pp. 1803–1808 (2015)
3.
go back to reference Borgesius, F.Z.: Informed consent: we can do better to defend privacy. IEEE Secur. Priv. 13, 103–107 (2015)CrossRef Borgesius, F.Z.: Informed consent: we can do better to defend privacy. IEEE Secur. Priv. 13, 103–107 (2015)CrossRef
4.
go back to reference Hansen, M., Borcea-Pfitzmann, K., Pfitzmann, A.: PRIME - a European project for privacy-enhancing identity management. IT - Inf. Technol. 47, 352–359 (2005) Hansen, M., Borcea-Pfitzmann, K., Pfitzmann, A.: PRIME - a European project for privacy-enhancing identity management. IT - Inf. Technol. 47, 352–359 (2005)
6.
go back to reference Janic, M., Wijbenga, J.P., Veugen, T.: Transparency enhancing tools (TETs): an overview. In: Workshop on Socio-Technical Aspects in Security and Trust, STAST, pp. 18–25 (2013) Janic, M., Wijbenga, J.P., Veugen, T.: Transparency enhancing tools (TETs): an overview. In: Workshop on Socio-Technical Aspects in Security and Trust, STAST, pp. 18–25 (2013)
7.
go back to reference Jaspers, M.W.M., Steen, T., Van Den Bos, C., Geenen, M.: The think aloud method: a guide to user interface design. Int. J. Med. Inform. 73, 781–795 (2004)CrossRef Jaspers, M.W.M., Steen, T., Van Den Bos, C., Geenen, M.: The think aloud method: a guide to user interface design. Int. J. Med. Inform. 73, 781–795 (2004)CrossRef
9.
go back to reference Lewis, C., Polson, P.G., Wharton, C., Rieman, J.: Testing a walkthrough methodology for theory-based design of walk-up-and-use interfaces. In: Proceedings of the SIGCHI Conference on Human Factors in Computing Systems Empowering People - CHI 1990, pp. 235–242. ACM Press, New York (1990) Lewis, C., Polson, P.G., Wharton, C., Rieman, J.: Testing a walkthrough methodology for theory-based design of walk-up-and-use interfaces. In: Proceedings of the SIGCHI Conference on Human Factors in Computing Systems Empowering People - CHI 1990, pp. 235–242. ACM Press, New York (1990)
11.
go back to reference Nielsen, J.: Usability Engineering. Elsevier, New York (1994)MATH Nielsen, J.: Usability Engineering. Elsevier, New York (1994)MATH
12.
go back to reference Sackmann, S., Strüker, J., Accorsi, R.: Personalization in privacy-aware highly dynamic systems. Commun. ACM 49, 32 (2006)CrossRef Sackmann, S., Strüker, J., Accorsi, R.: Personalization in privacy-aware highly dynamic systems. Commun. ACM 49, 32 (2006)CrossRef
13.
go back to reference Schneier, B.: A taxonomy of social networking data. IEEE Secur. Priv. Mag. 8, 88 (2010) Schneier, B.: A taxonomy of social networking data. IEEE Secur. Priv. Mag. 8, 88 (2010)
14.
go back to reference Siljee, J.: Privacy transparency patterns. In: Proceedings of the 20th European Conference on Pattern Languages of Programs - EuroPLoP 2015, pp. 1–11. ACM Press, New York (2015) Siljee, J.: Privacy transparency patterns. In: Proceedings of the 20th European Conference on Pattern Languages of Programs - EuroPLoP 2015, pp. 1–11. ACM Press, New York (2015)
15.
go back to reference Thatmann, D., Raschke, P., Küpper, A.: “Please, No More GUIs”: a user study, prototype development and evaluation on the integration of attribute-based encryption in a hospital environment. In: Proceedings - International Computer Software and Applications Conference, pp. 496–502. IEEE (2016) Thatmann, D., Raschke, P., Küpper, A.: “Please, No More GUIs”: a user study, prototype development and evaluation on the integration of attribute-based encryption in a hospital environment. In: Proceedings - International Computer Software and Applications Conference, pp. 496–502. IEEE (2016)
16.
go back to reference Weitzner, D.J., Abelson, H., Hanson, C., Hendler, J., Mcguinness, D.L., Jay, G., Waterman, K.K., Berners-lee, T., Kagal, L., Sussman, G.J.: Transparent accountable data mining: new strategies for privacy protection, pp. 1–12 (2006) Weitzner, D.J., Abelson, H., Hanson, C., Hendler, J., Mcguinness, D.L., Jay, G., Waterman, K.K., Berners-lee, T., Kagal, L., Sussman, G.J.: Transparent accountable data mining: new strategies for privacy protection, pp. 1–12 (2006)
17.
go back to reference Zwick, D., Dholakia, N.: Whose identity is it anyway? Consumer representation in the age of database marketing. J. Macromarketing 24, 31–43 (2004)CrossRef Zwick, D., Dholakia, N.: Whose identity is it anyway? Consumer representation in the age of database marketing. J. Macromarketing 24, 31–43 (2004)CrossRef
Metadata
Title
Designing a GDPR-Compliant and Usable Privacy Dashboard
Authors
Philip Raschke
Axel Küpper
Olha Drozd
Sabrina Kirrane
Copyright Year
2018
DOI
https://doi.org/10.1007/978-3-319-92925-5_14

Premium Partner