Saved in:
Bibliographic Details
Main Author: Enriquez, Luis
Format: Preprint
Published: 2024
Subjects:
Online Access:https://arxiv.org/abs/2411.03217
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866929716634583040
author Enriquez, Luis
author_facet Enriquez, Luis
contents What if the main data protection vulnerability is risk management? Data Protection merges three disciplines: data protection law, information security, and risk management. Nonetheless, very little research has been made on the field of data protection risk management, where subjectivity and superficiality are the dominant state of the art. Since the GDPR tells you what to do, but not how to do it, the solution for approaching GDPR compliance is still a gray zone, where the trend is using the rule of thumb. Considering that the most important goal of risk management is to reduce uncertainty in order to take informed decisions, risk management for the protection of the rights and freedoms of the data subjects cannot be disconnected from the impact materialization that data controllers and processors need to assess. This paper proposes a quantitative approach to data protection risk-based compliance from a data controllers perspective, with the aim of proposing a mindset change, where data protection impact assessments can be improved by using data protection analytics, quantitative risk analysis, and calibrating expert opinions.
format Preprint
id arxiv_https___arxiv_org_abs_2411_03217
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle A Personal data Value at Risk Approach
Enriquez, Luis
Risk Management
Machine Learning
What if the main data protection vulnerability is risk management? Data Protection merges three disciplines: data protection law, information security, and risk management. Nonetheless, very little research has been made on the field of data protection risk management, where subjectivity and superficiality are the dominant state of the art. Since the GDPR tells you what to do, but not how to do it, the solution for approaching GDPR compliance is still a gray zone, where the trend is using the rule of thumb. Considering that the most important goal of risk management is to reduce uncertainty in order to take informed decisions, risk management for the protection of the rights and freedoms of the data subjects cannot be disconnected from the impact materialization that data controllers and processors need to assess. This paper proposes a quantitative approach to data protection risk-based compliance from a data controllers perspective, with the aim of proposing a mindset change, where data protection impact assessments can be improved by using data protection analytics, quantitative risk analysis, and calibrating expert opinions.
title A Personal data Value at Risk Approach
topic Risk Management
Machine Learning
url https://arxiv.org/abs/2411.03217