Since GDPR went into effect in 2018, many other data protection and privacy regulations have been released. With the new regulation, there has been an associated increase in industry professionals focused on data protection and privacy. Building on related work showing the potential benefits of knowledge management in organisational compliance and privacy engineering, this paper presents the findings of an exploratory qualitative study with data protection officers and other privacy professionals. We found issues with knowledge management to be the underlying challenge of our participants' feedback. Our participants noted four categories of feedback: (1) a perceived disconnect between regulation and practice, (2) a general lack of clear job description, (3) the need for data protection and privacy to be involved at every level of an organisation, (4) knowledge management tools exist but are not used effectively. This paper questions what knowledge management or automation solutions may prove to be effective in establishing better computer-supported work environments.
翻译:自《通用数据保护条例》(GDPR)于2018年生效以来,众多其他数据保护与隐私法规相继出台。伴随新规实施,专注于数据保护与隐私领域的行业专业人士数量相应增长。基于相关研究揭示的知识管理在组织合规与隐私工程中的潜在效益,本文呈现了一项探索性定性研究的结果,研究对象为数据保护官及其他隐私专业人士。研究发现,知识管理问题是参与者反馈的核心挑战。参与者反馈涵盖四类问题:(1) 法规与实践之间感知到的脱节;(2) 普遍缺乏明确的岗位职责描述;(3) 数据保护与隐私需渗透组织各层级;(4) 知识管理工具虽已存在但未得到有效应用。本文进一步探讨何种知识管理或自动化解决方案能有效构建更完善的计算机辅助工作环境。