Skip to main content

2019 | OriginalPaper | Buchkapitel

Implementing GDPR in the Charity Sector: A Case Study

verfasst von : Jane Henriksen-Bulmer, Shamal Faily, Sheridan Jeary

Erschienen in: Privacy and Identity Management. Fairness, Accountability, and Transparency in the Age of Big Data

Verlag: Springer International Publishing

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

Due to their organisational characteristics, many charities are poorly prepared for the General Data Protection Regulation (GDPR). We present an exemplar process for implementing GDPR and the DPIA Data Wheel, a DPIA framework devised as part of the case study, that accounts for these characteristics. We validate this process and framework by conducting a GDPR implementation with a charity that works with vulnerable adults. This charity processes both special category (sensitive) and personally identifiable data. This GDPR implementation was conducted and devised for the charity sector, but can be equally applied in any organisation that need to implement GDPR or conduct DPIAs.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Fußnoten
2
Ibid 1.
 
3
Ibid 1.
 
4
Ibid 1.
 
5
Ibid 1.
 
Literatur
1.
Zurück zum Zitat Bamberger, K.A., Mulligan, D.K.: Privacy on the Ground: Driving Corporate Behaviour in the United States and Europe. The MIT Press/Massachusetts Institute of Technology, London (2015)CrossRef Bamberger, K.A., Mulligan, D.K.: Privacy on the Ground: Driving Corporate Behaviour in the United States and Europe. The MIT Press/Massachusetts Institute of Technology, London (2015)CrossRef
2.
Zurück zum Zitat Barth, A., Anupam, D., Mitchell, J.C., Nissenbaum, H.F.: Privacy and contextual integrity: framework and applications. In: 2006 Symposium on Security and Privacy [Serial Online], vol. 2006, pp. 184–198. IEEE Xplore Digital Library, Ipswich (2006). https://doi.org/10.1109/SP.2006.32. Cited by 0 Barth, A., Anupam, D., Mitchell, J.C., Nissenbaum, H.F.: Privacy and contextual integrity: framework and applications. In: 2006 Symposium on Security and Privacy [Serial Online], vol. 2006, pp. 184–198. IEEE Xplore Digital Library, Ipswich (2006). https://​doi.​org/​10.​1109/​SP.​2006.​32. Cited by 0
3.
Zurück zum Zitat Bruner, J.S.: Actual Minds. Possible Worlds. Harvard University Press, Cambridge (1986). [Electronic resource] Bruner, J.S.: Actual Minds. Possible Worlds. Harvard University Press, Cambridge (1986). [Electronic resource]
4.
Zurück zum Zitat BS ISO 31000:2009: British standards document BS ISO 31000:2009: Risk management. Principles and guidelines. Technical report, British Standard and the International Organization for Standardization (ISO) (2009) BS ISO 31000:2009: British standards document BS ISO 31000:2009: Risk management. Principles and guidelines. Technical report, British Standard and the International Organization for Standardization (ISO) (2009)
6.
Zurück zum Zitat Conley, A., Datta, A., Helen, N., Sharma, D.: Sustaining privacy and open justice in the transition to online court records: a multidisciplinary inquiry. Maryland Law Rev. 71(3), 772–847 (2012) Conley, A., Datta, A., Helen, N., Sharma, D.: Sustaining privacy and open justice in the transition to online court records: a multidisciplinary inquiry. Maryland Law Rev. 71(3), 772–847 (2012)
7.
Zurück zum Zitat Darakhshan, J., Shvartzshnaider, Y., Latonero, M.: It takes a village: a community based participatory framework for privacy design. In: 2018 IEEE European Symposium on Security and Privacy Workshops, EUROSPW, pp. 112–115 (2018) Darakhshan, J., Shvartzshnaider, Y., Latonero, M.: It takes a village: a community based participatory framework for privacy design. In: 2018 IEEE European Symposium on Security and Privacy Workshops, EUROSPW, pp. 112–115 (2018)
8.
Zurück zum Zitat Demirci, A.E.: Change-specific cynicism as a determinant of employee resistance to change. Is, Guc: J. Ind. Relat. Hum. Resour. 18(4), 1–20 (2016) Demirci, A.E.: Change-specific cynicism as a determinant of employee resistance to change. Is, Guc: J. Ind. Relat. Hum. Resour. 18(4), 1–20 (2016)
9.
Zurück zum Zitat European Parliament and the Council of Europe: General data protection regulation (GDPR). Regulation (EU) 2016/679 5419/1/16. European Parliament and the Council of Europe, Brussels, April 2016 European Parliament and the Council of Europe: General data protection regulation (GDPR). Regulation (EU) 2016/679 5419/1/16. European Parliament and the Council of Europe, Brussels, April 2016
10.
Zurück zum Zitat Grodzinsky, F.S., Tavani, H.T.: Privacy in “the cloud”: applying Nissenbaum’s theory of contextual integrity. SIGCAS Comput. Soc. 41(1), 38–47 (2011)CrossRef Grodzinsky, F.S., Tavani, H.T.: Privacy in “the cloud”: applying Nissenbaum’s theory of contextual integrity. SIGCAS Comput. Soc. 41(1), 38–47 (2011)CrossRef
11.
Zurück zum Zitat Hall, D.C.: Making risk assessments more comparable and repeatable. Syst. Eng. 14(2), 173–179 (2011)CrossRef Hall, D.C.: Making risk assessments more comparable and repeatable. Syst. Eng. 14(2), 173–179 (2011)CrossRef
12.
Zurück zum Zitat Henriksen-Bulmer, J., Faily, S.: Applying contextual integrity to open data publishing. In: Proceedings of the 31st British HCI Group Annual Conference on People and Computers: Digital Make Believe. British Computer Society (2017) Henriksen-Bulmer, J., Faily, S.: Applying contextual integrity to open data publishing. In: Proceedings of the 31st British HCI Group Annual Conference on People and Computers: Digital Make Believe. British Computer Society (2017)
13.
Zurück zum Zitat ICO: Preparing for the general data protection regulation (GDPR): 12 steps to take now. Technical report, V2.0 20170525, Information Commissioner’s Office, May 2017 ICO: Preparing for the general data protection regulation (GDPR): 12 steps to take now. Technical report, V2.0 20170525, Information Commissioner’s Office, May 2017
14.
Zurück zum Zitat ICO: Data protection impact assessments (DPIAs) (2018) ICO: Data protection impact assessments (DPIAs) (2018)
16.
Zurück zum Zitat ISO/IEC 29100: BS ISO/IEC29100: Information technology – security techniques – privacy framework. Technical report, British Standard and the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) (2011) ISO/IEC 29100: BS ISO/IEC29100: Information technology – security techniques – privacy framework. Technical report, British Standard and the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) (2011)
17.
Zurück zum Zitat Krupa, Y., Vercouter, L.: Handling privacy as contextual integrity in decentralized virtual communities: the privacias framework. Web Intell. Agent Syst. 10(1), 105–116 (2012) Krupa, Y., Vercouter, L.: Handling privacy as contextual integrity in decentralized virtual communities: the privacias framework. Web Intell. Agent Syst. 10(1), 105–116 (2012)
18.
Zurück zum Zitat Mulligan, D.K., Koopman, C., Doty, N.: Privacy is an essentially contested concept: a multi-dimensional analytic for mapping privacy. Philos. Trans. Ser. A Math. Phys. Eng. Sci. 374(2083), 20160118 (2016)CrossRef Mulligan, D.K., Koopman, C., Doty, N.: Privacy is an essentially contested concept: a multi-dimensional analytic for mapping privacy. Philos. Trans. Ser. A Math. Phys. Eng. Sci. 374(2083), 20160118 (2016)CrossRef
19.
Zurück zum Zitat National Drug Evidence Centre: National drug treatment monitoring system (NDTMS) (2018) National Drug Evidence Centre: National drug treatment monitoring system (NDTMS) (2018)
20.
Zurück zum Zitat Nissenbaum, H.: Privacy as contextual integrity. Wash. Law Rev. 79(1), 119–158 (2004) Nissenbaum, H.: Privacy as contextual integrity. Wash. Law Rev. 79(1), 119–158 (2004)
21.
Zurück zum Zitat Nissenbaum, H.F.: Privacy in Context: Technology, Policy, and the Integrity of Social Life. Stanford Law Books, Stanford (2010) Nissenbaum, H.F.: Privacy in Context: Technology, Policy, and the Integrity of Social Life. Stanford Law Books, Stanford (2010)
22.
Zurück zum Zitat NIST: Guide to protecting the confidentiality of personally identifiable information (PII). Technical Report, National Institute of Standards and Technology (NIST), U.S. Department of Commerce, pp. 800–122 (2010) NIST: Guide to protecting the confidentiality of personally identifiable information (PII). Technical Report, National Institute of Standards and Technology (NIST), U.S. Department of Commerce, pp. 800–122 (2010)
23.
Zurück zum Zitat NIST: Guide for conducting risk assessments. Technical Report SP 800-30, National Institute of Standards and Technology (NIST), U.S. Department of Commerce, Gaithersburg, September 2012 NIST: Guide for conducting risk assessments. Technical Report SP 800-30, National Institute of Standards and Technology (NIST), U.S. Department of Commerce, Gaithersburg, September 2012
24.
Zurück zum Zitat Palen, L., Dourish, P.: Unpacking ‘privacy’ for a networked world. In: CHI-CONFERENCE, pp. 129–136 (2003) Palen, L., Dourish, P.: Unpacking ‘privacy’ for a networked world. In: CHI-CONFERENCE, pp. 129–136 (2003)
25.
Zurück zum Zitat Rooney, T., Lawlor, K., Rohan, E.: Telling tales: storytelling as a methodological approach in research. Electron. J. Bus. Res. Methods 14(2), 147–156 (2016) Rooney, T., Lawlor, K., Rohan, E.: Telling tales: storytelling as a methodological approach in research. Electron. J. Bus. Res. Methods 14(2), 147–156 (2016)
26.
Zurück zum Zitat Sanchez Abril, P., Levin, A., Del Riego, A.: Blurred boundaries: social media privacy and the twenty-first-century employee. Am. Bus. Law J. 49(1), 63–124 (2012)CrossRef Sanchez Abril, P., Levin, A., Del Riego, A.: Blurred boundaries: social media privacy and the twenty-first-century employee. Am. Bus. Law J. 49(1), 63–124 (2012)CrossRef
27.
Zurück zum Zitat Sar, R.K., Al-Saggaf, Y.: Contextual integrity’s decision heuristic and the tracking by social network sites. Ethics Inf. Technol. 16(1), 15–26 (2013)CrossRef Sar, R.K., Al-Saggaf, Y.: Contextual integrity’s decision heuristic and the tracking by social network sites. Ethics Inf. Technol. 16(1), 15–26 (2013)CrossRef
28.
Zurück zum Zitat Solove, D.J.: A taxonomy of privacy. Univ. Pennsylvania Law Rev. 154(3), 477–564 (2006)CrossRef Solove, D.J.: A taxonomy of privacy. Univ. Pennsylvania Law Rev. 154(3), 477–564 (2006)CrossRef
29.
Zurück zum Zitat Warren, S.D., Brandeis, L.D.: The right to privacy. Harvard Law Rev. IV(5), 193–220 (1890)CrossRef Warren, S.D., Brandeis, L.D.: The right to privacy. Harvard Law Rev. IV(5), 193–220 (1890)CrossRef
30.
Zurück zum Zitat Westin, A.F.: Science, privacy, and freedom: issues and proposals for the 1970’s. Part I-the current impact of surveillance on privacy. Columbia Law Rev. 66(6), 1003–1050 (1966)CrossRef Westin, A.F.: Science, privacy, and freedom: issues and proposals for the 1970’s. Part I-the current impact of surveillance on privacy. Columbia Law Rev. 66(6), 1003–1050 (1966)CrossRef
32.
Zurück zum Zitat Yin, R.K.: Case Study Research : Design and Methods. SAGE, Los Angeles (2013) Yin, R.K.: Case Study Research : Design and Methods. SAGE, Los Angeles (2013)
Metadaten
Titel
Implementing GDPR in the Charity Sector: A Case Study
verfasst von
Jane Henriksen-Bulmer
Shamal Faily
Sheridan Jeary
Copyright-Jahr
2019
DOI
https://doi.org/10.1007/978-3-030-16744-8_12