A Framework for Supporting PET Selection Based on GDPR Principles
摘要
The General Data Protection Regulation (GDPR) lists seven privacy principles relating to the processing of personal data and requires the processor to implement appropriate technical and organizational measures (TOMs). In practice, TOMs are often addressed by organizational measures, but technical measures, i. e. Privacy-Enhancing Technologies (PETs), are rarely used to address them. One reason for that might be the challenge to find an appropriate PET. The contribution of our paper is a framework to support the selection of PETs based on GDPR principles. For that purpose, we provide mappings between the trust model and GDPR principles, and between PET types and GDPR principles. Furthermore, we provide an assessment of the different maturity levels of PETs. We evaluated our framework by applying it to three different use cases in the automotive domain and it proved to be highly effective in guiding the identification and selection of candidate PETs.