Data protection and privacy

a model for evidence management

Authors

DOI:

https://doi.org/10.1590/1808-5245.29.128009

Keywords:

data protection; data privacy; evidence management; information security

Abstract

The legislation and regulations related to data protection and privacy present the requirements that organizations, processes, products, and environments need to meet to be considered secure. Among the recommended requirements, the “Accountability” and “Privacy Compliance” requirements stand out, which define that organizations must be responsible and able to demonstrate compliance with current laws and regulations. In addition to the challenge of implementing such requirements, it is necessary to adopt systematized processes that prove how and on what evidence these requirements are validated. This article presents a model called COM.PRIVACY to manage evidence of data protection and privacy to demonstrate diligence and compliance with good practice regulations. Design Science Research (DSR) was used as a research method for proposing the model. For its validation, COM.PRIVACY was applied in an organization that made it possible to observe and identify improvements during its use, in addition to submitting a questionnaire to specialists to evaluate the model. It was concluded that the model supports the validation and proof of compliance with data protection and privacy requirements in all data processing operations, and can be adopted both in the activity of adequacy and implementation of regulations, in the process of measurement and verification compliance with them, as well as to promote transparency in the processing of data to their holders.

Downloads

Download data is not yet available.

Author Biographies

Gislaine Parra Freund, Universidade Federal de Santa Catarina

Doutoranda em Ciência da Informação pelo Programa de Pós-Graduação em Ciência da Informação (PGCIN) da Universidade Federal de Santa Catarina (UFSC).

Douglas Dyllon Jeronimo de Macedo, Universidade Federal de Santa Catarina

Doutor em Engenharia e Gestão do Conhecimento. Professor do Departamento de Ciência da Informação da Universidade Federal de Santa Catarina (UFSC).

Priscila Basto Fagundes, Universidade Federal de Santa Catarina

Doutora em Ciência da Informação pelo Programa de Pós-Graduação em Ciência da Informação (PGCIN) da Universidade Federal de Santa Catarina (UFSC).

References

ASSOCIAÇÃO BRASILEIRA DE NORMAS TÉCNICAS. NBR ISO/IEC 29100: tecnologia da informação: técnicas de segurança: estrutura de privacidade. Rio de Janeiro, ABNT, 2020.

BRASIL. Lei n. 13.709, de 14 de agosto de 2018. Lei Geral de Proteção de Dados Pessoais (LGPD). Diário Oficial da União: seção 1, Brasília, n. 157, p. 59, 15 ago. 2018.

CAVOUKIAN, Ann. Privacy by design: the 7 foundational principles. Information and Privacy Commissioner of Ontario, Toronto, 2009.

EUROPEAN UNION. General data protection regulation. EUR-Lex, Luxemburgo, 2016.

FACCHINI NETO, Eugênio; DEMOLINER, Karina Silva. Direito à privacidade e novas tecnologias: breves considerações acerca da proteção de dados pessoais no Brasil e na Europa. Revista Internacional Consinter de Direito, Porto, ano 6, n. 7, p. 19-40, 2018. Disponível em: https://doi.org/10.19135/revista.consinter.0007.01. Acesso em: 7 maio 2023.

HEVNER, Alan; CHATTERJEE, Samir. Design research in information systems: theory and practice. Berlin: Springer, 2010.

ISAAK, Jim; HANNA, Mina J. User data privacy: Facebook, Cambridge analytica, and privacy protection. Computer, New York, v. 51, n. 8, p. 56-59, 2018. Disponível em: http://doi.org/ 10.1109/MC.2018.3191268. Acesso em: 10 mar. 2022.

KOKALY, Sahar. Managing assurance cases in model based software systems. In: INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING COMPANION, 39., 2017, Buenos Aires. Anais […]. Buenos Aires: IEE, 2017. p. 453-456.

LIMA, Paulo Ricardo Silva; PRESSER, Nadi Helena. A Lei Geral de Proteção de Dados e os desafios para a gestão nas organizações brasileiras na era do big data. Revista P2P & Inovação, Brasília, v. 8, n. 2, p. 109-120, 2022. Disponível em: https://doi.org/10.21721/p2p.2022v8n2.p109-120. Acesso em: 2 maio 2023.

MENDES, Laura Schertel. Privacidade, proteção de dados e defesa do consumidor: linhas gerais de um novo direito fundamental. São Paulo: Saraiva, 2014.

OBJECT MANAGEMENT GROUP (OMG). Structured Assurance Case Metamodel (SACM): version 2.1., Milford, Apr. 2020.

ROCHA, Junia M.; HONORATO, Mauro Jacob; COSTA, Eduardo. Assessment of expert panels. IEEE Latin America Transactions, New York, v. 14, n. 1, p. 303-308, 2016. Disponível em: http://doi.org/10.1109/TLA.2016.7430093. Acesso em: 30 ago. 2022.

SCHAAR, Peter. Privacy by Design. Identity in the Information Society, Estados Unidos, v. 3, n. 2, p. 267-274, 2010. Disponível em: http://doi.org/ 10.1007/s12394-010-0055-x. Acesso em: 5 maio 2022.

SOUSA, Rosilene Paiva Marinho de; BARRANCOS, Jacqueline Echeverría; MAIA, Manuela Eugênio. Acesso à informação e ao tratamento de dados pessoais pelo poder público. Informação & Sociedade: Estudos, João Pessoa, v. 29, n. 1, p. 237-251, 2019.

Published

2023-11-20

How to Cite

FREUND, Gislaine Parra; DYLLON JERONIMO DE MACEDO, Douglas; BASTO FAGUNDES, Priscila. Data protection and privacy: a model for evidence management. Em Questão, Porto Alegre, v. 29, 2023. DOI: 10.1590/1808-5245.29.128009. Disponível em: https://seer.ufrgs.br/index.php/EmQuestao/article/view/128009. Acesso em: 22 aug. 2026.

Issue

Section

Article

Most read articles by the same author(s)

Similar Articles

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 > >> 

You may also start an advanced similarity search for this article.