Organizations use privacy policies to communicate their data collection practices to their clients. A privacy policy is a set of statements that specifies how an organization gathers, uses, discloses, and maintains a client's data. However, most privacy policies lack a clear, complete explanation of how data providers' information is used. We propose a modeling methodology, called the Privacy Policy Permission Model (PPPM), that provides a uniform, easy-to-understand representation of privacy policies, which can accurately and clearly show how data is used within an organization's practice. Using this methodology, a privacy policy is captured as a diagram. The diagram is capable of highlighting inconsistencies and inaccuracies in the privacy policy. The methodology supports privacy officers in properly and clearly articulating an organization's privacy policy.
翻译:组织通过隐私政策向客户传达其数据收集实践。隐私政策是一组规定组织如何收集、使用、披露和维护客户数据的陈述。然而,大多数隐私政策缺乏对数据提供者信息使用方式的清晰、完整解释。我们提出了一种名为隐私政策权限模型(PPPM)的建模方法,该方法能够为隐私政策提供统一且易于理解的表示,从而准确清晰地展示数据在组织实践中的使用方式。利用该方法,隐私政策被捕捉为一种图表形式。该图表能够揭示隐私政策中的不一致性和不准确性。该方法支持隐私官员恰当且清晰地阐述组织的隐私政策。