Open this publication in new window or tab >>2025 (English)In: Proceedings - 10th IEEE European Symposium on Security and Privacy Workshops, IEEE, 2025, p. 251-259Conference paper, Published paper (Refereed)
Abstract [en]
When personal data is processed in a distributed manner by cooperating service providers, privacy risks may emerge solely from the choice of data processors included in the composition. For instance, different data processors may unknowingly rely on the same cloud provider, allowing for unintended linkability of personal data at that very provider. As such compositional risks to privacy are beyond the scope of each individual risk assessment, they are likely to be overseen when performing a data protection impact assessment. In this paper, we propose a novel protocol to detect and manage such compositional risks to privacy. Following an initial problem definition and requirements elicitation, we elaborate how our protocol identifies candidates for compositional risks and how this information may be used to improve the results of a data protection impact assessment over service compositions including multiple data processors.
Place, publisher, year, edition, pages
IEEE, 2025
Keywords
Data privacy, Cloud providers, Compositional risk, Data processors, Data protection impact assessments, DPIA, Privacy, Privacy risks, Risk detections, Risks assessments, Service provider, Risk assessment
National Category
Computer Sciences Software Engineering
Research subject
Computer Science
Identifiers
urn:nbn:se:kau:diva-107431 (URN)10.1109/EuroSPW67616.2025.00035 (DOI)001576286100029 ()2-s2.0-105016554511 (Scopus ID)
Conference
2025 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW), Venice, Italy, June 30- July 4, 2025.
2025-11-032025-11-032026-02-12Bibliographically approved