Visible to the public CPPL: Compact Privacy Policy Language

TitleCPPL: Compact Privacy Policy Language
Publication TypeConference Paper
Year of Publication2016
AuthorsHenze, Martin, Hiller, Jens, Schmerling, Sascha, Ziegeldorf, Jan Henrik, Wehrle, Klaus
Conference NameProceedings of the 2016 ACM on Workshop on Privacy in the Electronic Society
Date PublishedOctober 2016
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-4569-9
Keywordscloud computing, composability, data handling, Human Behavior, Internet of Things, Metrics, Privacy Policies, pubcrawl, relational database security, Resiliency
Abstract

Recent technology shifts such as cloud computing, the Internet of Things, and big data lead to a significant transfer of sensitive data out of trusted edge networks. To counter resulting privacy concerns, we must ensure that this sensitive data is not inadvertently forwarded to third-parties, used for unintended purposes, or handled and stored in violation of legal requirements. Related work proposes to solve this challenge by annotating data with privacy policies before data leaves the control sphere of its owner. However, we find that existing privacy policy languages are either not flexible enough or require excessive processing, storage, or bandwidth resources which prevents their widespread deployment. To fill this gap, we propose CPPL, a Compact Privacy Policy Language which compresses privacy policies by taking advantage of flexibly specifiable domain knowledge. Our evaluation shows that CPPL reduces policy sizes by two orders of magnitude compared to related work and can check several thousand of policies per second. This allows for individual per-data item policies in the context of cloud computing, the Internet of Things, and big data.

URLhttps://dl.acm.org/doi/10.1145/2994620.2994627
DOI10.1145/2994620.2994627
Citation Keyhenze_cppl:_2016