{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,3,3]],"date-time":"2024-03-03T09:55:33Z","timestamp":1709459733645},"reference-count":24,"publisher":"Association for Computing Machinery (ACM)","issue":"8","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Commun. ACM"],"published-print":{"date-parts":[[2011,8]]},"abstract":"Privacy impact assessments should be integrated into the overall approach to risk management with other strategic planning instruments.<\/jats:p>\n This article considers the issue of whether privacy impact assessments (PIAs) should be mandatory. I will examine the benefits and disadvantages of PIAs, the case for and against mandatory PIAs, and ultimately conclude they should be mandatory. Even if they are made mandatory, however, other factors, such as independent audits, must be taken into account to make them truly effective.<\/jats:p>","DOI":"10.1145\/1978542.1978568","type":"journal-article","created":{"date-parts":[[2011,7,21]],"date-time":"2011-07-21T13:27:09Z","timestamp":1311254829000},"page":"121-131","update-policy":"http:\/\/dx.doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":31,"title":["Should privacy impact assessments be mandatory?"],"prefix":"10.1145","volume":"54","author":[{"given":"David","family":"Wright","sequence":"first","affiliation":[{"name":"Trilateral Research and Consulting LLP, London, U.K."}]}],"member":"320","published-online":{"date-parts":[[2011,8]]},"reference":[{"key":"e_1_2_1_1_1","first-page":"1","article-title":"Privacy decisionmaking in administrative agencies","volume":"75","author":"Bamberger K.A.","year":"2008","unstructured":"Bamberger , K.A. and Mulligan , D.K . Privacy decisionmaking in administrative agencies . University of Chicago Law Review 75 , 1 ( Jan. 2008 ), 75--107. Bamberger, K.A. and Mulligan, D.K. Privacy decisionmaking in administrative agencies. University of Chicago Law Review 75, 1 (Jan. 2008), 75--107.","journal-title":"University of Chicago Law Review"},{"key":"e_1_2_1_2_1","volume-title":"Annex D of Privacy Impact Assessments: International Study of their Application and Effects, study performed for the U.K. Information Commissioner's Office","author":"Bennett C.J.","year":"2007","unstructured":"Bennett , C.J. Privacy Impact Assessments: Jurisdictional Report for the United States of America , Annex D of Privacy Impact Assessments: International Study of their Application and Effects, study performed for the U.K. Information Commissioner's Office , October 2007 ; http:\/\/uat.ico.gov.U.K.\/upload\/documents\/library\/corporate\/research_and_reports\/lbrouni_piastudy_appd_us_2910071.pdf Bennett, C.J. Privacy Impact Assessments: Jurisdictional Report for the United States of America, Annex D of Privacy Impact Assessments: International Study of their Application and Effects, study performed for the U.K. Information Commissioner's Office, October 2007; http:\/\/uat.ico.gov.U.K.\/upload\/documents\/library\/corporate\/research_and_reports\/lbrouni_piastudy_appd_us_2910071.pdf"},{"key":"e_1_2_1_3_1","volume-title":"The Governance of Privacy: Policy Instruments in Global Perspective","author":"Bennett C.J.","year":"2006","unstructured":"Bennett , C.J. and Raab , C.D . The Governance of Privacy: Policy Instruments in Global Perspective , MIT Press , Cambridge, MA , 2006 . Bennett, C.J. and Raab, C.D. The Governance of Privacy: Policy Instruments in Global Perspective, MIT Press, Cambridge, MA, 2006."},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.clsr.2009.02.002"},{"key":"e_1_2_1_5_1","volume-title":"The Times, (Aug. 27","author":"Elliott F.","year":"2007","unstructured":"Elliott , F. Safety fears over new register of all children . The Times, (Aug. 27 , 2007 ); http:\/\/www.timesonline.co.U.K.\/tol\/news\/politics\/article2332307.ece Elliott, F. Safety fears over new register of all children. The Times, (Aug. 27, 2007); http:\/\/www.timesonline.co.U.K.\/tol\/news\/politics\/article2332307.ece"},{"key":"e_1_2_1_6_1","volume-title":"Flash Report","author":"Eurobarometer","year":"2008","unstructured":"Eurobarometer , Data Protection in the European Union---Citizen perceptions , Flash Report 225, February 2008 ; http:\/\/ec.europa.eu\/public_opinion\/archives\/flash_arch_en.htm Eurobarometer, Data Protection in the European Union---Citizen perceptions, Flash Report 225, February 2008; http:\/\/ec.europa.eu\/public_opinion\/archives\/flash_arch_en.htm"},{"key":"e_1_2_1_7_1","volume-title":"Recommendation on the implementation of privacy and data protection principles in applications supported by radio-frequency identification","author":"European Commission","year":"2009","unstructured":"European Commission , Recommendation on the implementation of privacy and data protection principles in applications supported by radio-frequency identification , C(2009) 3200 final, Brussels ( May 12, 2009 ). European Commission, Recommendation on the implementation of privacy and data protection principles in applications supported by radio-frequency identification, C(2009) 3200 final, Brussels (May 12, 2009)."},{"key":"e_1_2_1_8_1","unstructured":"European Parliament and Council Regulation (EC) No 45\/2001 on the protection of individuals with regard to the processing of personal data by the Community institutions and bodies and on the free movement of such data (Dec. 18 2000); http:\/\/www.europarl.europa.eu\/tools\/disclaimer\/documents\/l_00820010112en00010022.pdf European Parliament and Council Regulation (EC) No 45\/2001 on the protection of individuals with regard to the processing of personal data by the Community institutions and bodies and on the free movement of such data (Dec. 18 2000); http:\/\/www.europarl.europa.eu\/tools\/disclaimer\/documents\/l_00820010112en00010022.pdf"},{"key":"e_1_2_1_9_1","unstructured":"European Parliament and the Council Directive 95\/46\/EC on the protection of individuals with regard to the processing of personal data and on the free movement of such data Brussels (Oct. 24 1995); http:\/\/ec.europa.eu\/justice_home\/fsj\/privacy\/docs\/95-46-ce\/dir1995-46_part1_en.pdf European Parliament and the Council Directive 95\/46\/EC on the protection of individuals with regard to the processing of personal data and on the free movement of such data Brussels (Oct. 24 1995); http:\/\/ec.europa.eu\/justice_home\/fsj\/privacy\/docs\/95-46-ce\/dir1995-46_part1_en.pdf"},{"key":"e_1_2_1_10_1","volume-title":"Vol I: Report, The Stationery Office Limited","author":"House of Lords Select Committee on the Constitution, Surveillance","year":"2009","unstructured":"House of Lords Select Committee on the Constitution, Surveillance : Citizens and the State , Vol I: Report, The Stationery Office Limited , London ( Feb. 6, 2009 0; http:\/\/www.parliament.the-stationery-office.com\/pa\/ld200809\/ldselect\/ldconst\/18\/1802.htm House of Lords Select Committee on the Constitution, Surveillance: Citizens and the State, Vol I: Report, The Stationery Office Limited, London (Feb. 6, 20090; http:\/\/www.parliament.the-stationery-office.com\/pa\/ld200809\/ldselect\/ldconst\/18\/1802.htm"},{"key":"e_1_2_1_11_1","volume-title":"Version 2.0","author":"Information Commission","year":"2009","unstructured":"Information Commission er's Office (ICO) , Privacy Impact Assessment Handbook , Version 2.0 , June 2009 ; http:\/\/www.ico.gov.U.K.\/for_organisations\/topic_specific_guides\/pia_handbook.aspx Information Commissioner's Office (ICO), Privacy Impact Assessment Handbook, Version 2.0, June 2009; http:\/\/www.ico.gov.U.K.\/for_organisations\/topic_specific_guides\/pia_handbook.aspx"},{"key":"e_1_2_1_12_1","volume-title":"Geneva (Apr. 16","author":"International Organization for Standardization, ISO 22307","year":"2008","unstructured":"International Organization for Standardization, ISO 22307 : 2008: Financial services---Privacy impact assessment , Geneva (Apr. 16 , 2008 ); http:\/\/www.iso.org\/iso\/iso_catalogue\/catalogue_tc\/catalogue_detail.htm?csnumber=40897 International Organization for Standardization, ISO 22307:2008: Financial services---Privacy impact assessment, Geneva (Apr. 16, 2008); http:\/\/www.iso.org\/iso\/iso_catalogue\/catalogue_tc\/catalogue_detail.htm?csnumber=40897"},{"key":"e_1_2_1_13_1","series-title":"July 2009","volume-title":"data breach incidents on the rise. The Register","author":"Leyden J. U.K.","year":"2009","unstructured":"Leyden , J. U.K. data breach incidents on the rise. The Register ( July 2009 ); http:\/\/www.theregister.co.U.K.\/ 2009 \/07\/09\/data_breach_survey\/ Leyden, J. U.K. data breach incidents on the rise. The Register (July 2009); http:\/\/www.theregister.co.U.K.\/2009\/07\/09\/data_breach_survey\/"},{"key":"e_1_2_1_14_1","volume-title":"Privacy Impact Assessment Handbook","author":"New Zealand","unstructured":"New Zealand Office of the Privacy Commissioner , Privacy Impact Assessment Handbook , June 2007; http:\/\/www.privacy.org.nz\/privacy-impact-assessment-handbook New Zealand Office of the Privacy Commissioner, Privacy Impact Assessment Handbook, June 2007; http:\/\/www.privacy.org.nz\/privacy-impact-assessment-handbook"},{"key":"e_1_2_1_15_1","volume-title":"Assessing the Privacy Impacts of Programs, Plans, and Policies","author":"Office of the Privacy Commission","year":"2007","unstructured":"Office of the Privacy Commission er of Canada (OPC). Assessing the Privacy Impacts of Programs, Plans, and Policies , Ottawa, October 2007 ; www.privcom.gc.ca Office of the Privacy Commissioner of Canada (OPC). Assessing the Privacy Impacts of Programs, Plans, and Policies, Ottawa, October 2007; www.privcom.gc.ca"},{"key":"e_1_2_1_16_1","volume-title":"No Place to Hide","author":"O'Harrow Jr., R.","year":"2005","unstructured":"O'Harrow , Jr., R. No Place to Hide , Free Press , New York , 2005 . O'Harrow, Jr., R. No Place to Hide, Free Press, New York, 2005."},{"key":"e_1_2_1_17_1","volume-title":"The Telegraph, (Jan. 26","author":"Paton G.","year":"2009","unstructured":"Paton , G. Children's database ContactPoint launched despite security fears . The Telegraph, (Jan. 26 , 2009 ); http:\/\/www.telegraph.co.U.K.\/news\/newstopics\/politics\/4338712\/Childrens-database-ContactPoint-launched-despite-security-fears.html Paton, G. Children's database ContactPoint launched despite security fears. The Telegraph, (Jan. 26, 2009); http:\/\/www.telegraph.co.U.K.\/news\/newstopics\/politics\/4338712\/Childrens-database-ContactPoint-launched-despite-security-fears.html"},{"key":"e_1_2_1_18_1","volume-title":"The New York Times, (Nov. 22, 2007","author":"Pfanner E.","year":"2007","unstructured":"Pfanner , E. Data leak in Britain affects 25 million . The New York Times, (Nov. 22, 2007 ); http:\/\/www.nytimes.com\/ 2007 \/11\/22\/world\/europe\/22data.html?hp Pfanner, E. Data leak in Britain affects 25 million. The New York Times, (Nov. 22, 2007); http:\/\/www.nytimes.com\/2007\/11\/22\/world\/europe\/22data.html?hp"},{"key":"e_1_2_1_19_1","volume-title":"Information Commissioner's Office, (Oct. 29","author":"Thomas R.","year":"2008","unstructured":"Thomas , R. Speech to RSA Conference Europe on data breaches , Information Commissioner's Office, (Oct. 29 , 2008 ); http:\/\/www.ico.gov.U.K.\/about_us\/news_and_views\/press_releases.aspx?year=2008 Thomas, R. Speech to RSA Conference Europe on data breaches, Information Commissioner's Office, (Oct. 29, 2008); http:\/\/www.ico.gov.U.K.\/about_us\/news_and_views\/press_releases.aspx?year=2008"},{"key":"e_1_2_1_20_1","volume-title":"Data Sharing Review Report, (July 11","author":"Thomas R.","year":"2008","unstructured":"Thomas , R. and Walport , M . Data Sharing Review Report, (July 11 , 2008 ); www.justice.gov.U.K.\/docs\/data-sharing-review-report.pdf Thomas, R. and Walport, M. Data Sharing Review Report, (July 11, 2008); www.justice.gov.U.K.\/docs\/data-sharing-review-report.pdf"},{"key":"e_1_2_1_21_1","volume-title":"Privacy Impact Assessment Guidelines: A framework to Manage Privacy Risks","author":"Treasury Board Secretariat","year":"2002","unstructured":"Treasury Board Secretariat of Canada , Privacy Impact Assessment Guidelines: A framework to Manage Privacy Risks , Ottawa , ( Aug. 31, 2002 ); http:\/\/www.tbs-sct.gc.ca\/pubs_pol\/ciopubs\/pia-pefr\/paipg-pefrld1-eng.asp Treasury Board Secretariat of Canada, Privacy Impact Assessment Guidelines: A framework to Manage Privacy Risks, Ottawa, (Aug. 31, 2002); http:\/\/www.tbs-sct.gc.ca\/pubs_pol\/ciopubs\/pia-pefr\/paipg-pefrld1-eng.asp"},{"key":"e_1_2_1_22_1","volume-title":"London","author":"Cabinet Office","year":"2008","unstructured":"U.K. Cabinet Office . Data Handling Procedures in Government: Final Report , London , June 2008 . http:\/\/www.cabinetoffice.gov.U.K.\/reports\/data_handling.aspx U.K. Cabinet Office. Data Handling Procedures in Government: Final Report, London, June 2008. http:\/\/www.cabinetoffice.gov.U.K.\/reports\/data_handling.aspx"},{"key":"e_1_2_1_23_1","volume-title":"Cabinet Office","author":"Performance","year":"2002","unstructured":"U.K. Performance and Innovation Unit, Privacy and Data-Sharing : The Way Forward For Public Services , Cabinet Office , London , April 2002 ; http:\/\/www.cabinetoffice.gov.U.K.\/strategy\/work_areas\/privacy.aspx U.K. Performance and Innovation Unit, Privacy and Data-Sharing: The Way Forward For Public Services, Cabinet Office, London, April 2002; http:\/\/www.cabinetoffice.gov.U.K.\/strategy\/work_areas\/privacy.aspx"},{"key":"e_1_2_1_25_1","volume-title":"Atheneum","author":"Westin A.F.","year":"1967","unstructured":"Westin , A.F. Privacy and Freedom , Atheneum , New York , 1967 . Westin, A.F. Privacy and Freedom, Atheneum, New York, 1967."}],"container-title":["Communications of the ACM"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1978542.1978568","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,12,29]],"date-time":"2022-12-29T18:53:19Z","timestamp":1672339999000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1978542.1978568"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011,8]]},"references-count":24,"journal-issue":{"issue":"8","published-print":{"date-parts":[[2011,8]]}},"alternative-id":["10.1145\/1978542.1978568"],"URL":"https:\/\/doi.org\/10.1145\/1978542.1978568","relation":{},"ISSN":["0001-0782","1557-7317"],"issn-type":[{"value":"0001-0782","type":"print"},{"value":"1557-7317","type":"electronic"}],"subject":[],"published":{"date-parts":[[2011,8]]},"assertion":[{"value":"2011-08-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}