Growing recognition of the potential for exploitation of personal data and of the shortcomings of prior privacy regimes has led to the passage of a multitude of new online privacy regulations. Some of these laws -- notably the European Union's General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA) -- have been the focus of large bodies of research by the computer science community, while others have received less attention. In this work, we analyze a set of Internet privacy and data protection regulations drawn from around the world -- both those that have frequently been studied by computer scientists and those that have not -- and develop a taxonomy of rights granted and obligations imposed by these laws. We then leverage this taxonomy to systematize 270 technical research papers published in computer science venues that investigate the impact of these laws and explore how technical solutions can complement legal protections. Finally, we analyze the results in this space through an interdisciplinary lens and make recommendations for future work at the intersection of computer science and legal privacy.
翻译:随着对个人数据滥用风险以及先前隐私制度缺陷的认识日益加深,多项新型在线隐私法规相继出台。部分法律——尤其是欧盟《通用数据保护条例》(GDPR)与《加州消费者隐私法案》(CCPA)——已成为计算机科学界大量研究的焦点,而其他法规得到的关注相对较少。本研究系统分析了一套源自全球的互联网隐私与数据保护法规(既包括计算机科学家频繁研究的对象,也涵盖尚未被深入研究的法规),并构建了这些法律所赋予权利与施加义务的分类体系。我们借此分类体系,系统梳理了计算机科学领域发表的270篇探讨这些法律影响及技术解决方案如何补充法律保护机制的学术论文。最后,我们通过跨学科视角分析相关成果,并为未来计算机科学与法律隐私交叉领域的研究提出建议。