Designing Notice and Consent for the Internet of Things

No ratings

Presented at GlobalPrivacySummit 2019 by

Privacy notices are often long, difficult to understand and don’t appear at opportune times. Constrained interfaces on mobile devices, wearables and smart home devices exacerbate the issue. In this session, Professor Cranor will present a taxonomy of notice options based on her research at Carnegie Mellon University, including various forms of visual, audio and haptic notices. She will guide participants through hands-on design exercises and offer guidelines on how to evaluate the effectiveness of notice and consent mechanisms for a given system or device.What you’ll take away:Understand the range of privacy notice optionsPractice designing appropriate notices for a variety of internet of things scenariosLearn techniques for evaluating the effectiveness of privacy notice and consent mechanisms Pseudonymization and Anonymization Under the GDPRKhaled El Emam and Mike Hintze N/AN/AThe GDPR explicitly recognizes pseudonymization as a means of protecting personal data. Pseudonymization has certain benefits under the GDPR. At the same time, the GDPR, along with guidance from the Article 29 Working Party and some DPAs, sets the bar for strong anonymization quite high. These two approaches provide controllers and processors with powerful mechanisms to use and disclose data, including sensitive health information, for secondary purposes and big data projects while complying with the GDPR and without having to obtain explicit consent from every data subject. In this Active Learning session, we will explore the two approaches and practice how to apply them using example scenarios.What you’ll take away:Understand what strong pseudonymization and strong anonymization meanIdentify the benefits of each approachHow to apply them under different data acquisition and sharing scenarios taken from the health sector