数据保护的有效执行:使用响应式监管工具的基于风险的监管模型

M. Raghavan, Beni Chugh, Nishanth Kumar
{"title":"数据保护的有效执行:使用响应式监管工具的基于风险的监管模型","authors":"M. Raghavan, Beni Chugh, Nishanth Kumar","doi":"10.2139/ssrn.3552665","DOIUrl":null,"url":null,"abstract":"This paper presents ideas for a new approach to enforcement of a data protection regime, based on risk-based supervision and the use of a range of responsive enforcement tools that could be deployed in advance of a breach to prevent it, or after a breach to mitigate the effects. Building on the risk-based approach to supervision, the model proposes a methodology to identify those entities that potentially pose more risk (to individuals and the system) when the personal data they hold is compromised.<br><br>Part 2 of this paper proposes a risk-based framework to identify and classify entities based on the risk they pose when the personal data they hold is compromised, using both qualitative and quantitative components. Part 3 sets out an enforcement toolkit for data protection, guided by the paradigm of responsive regulation (that also employs ex ante tools) to prevent and mitigate the effects of a compromise of personal data. This approach is a departure from the post-data breach sanctions that currently dominate data protection regimes worldwide. Part 4 sets out the features of institutional design and inter-sectoral coordination required for effective implementation of such a model approach for risk-based supervision and enforcement of data protection rights.","PeriodicalId":128369,"journal":{"name":"CompSciRN: Other Cybersecurity","volume":"34 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Effective Enforcement of a Data Protection: A Model for Risk-Based Supervision Using Responsive Regulatory Tools\",\"authors\":\"M. Raghavan, Beni Chugh, Nishanth Kumar\",\"doi\":\"10.2139/ssrn.3552665\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"This paper presents ideas for a new approach to enforcement of a data protection regime, based on risk-based supervision and the use of a range of responsive enforcement tools that could be deployed in advance of a breach to prevent it, or after a breach to mitigate the effects. Building on the risk-based approach to supervision, the model proposes a methodology to identify those entities that potentially pose more risk (to individuals and the system) when the personal data they hold is compromised.<br><br>Part 2 of this paper proposes a risk-based framework to identify and classify entities based on the risk they pose when the personal data they hold is compromised, using both qualitative and quantitative components. Part 3 sets out an enforcement toolkit for data protection, guided by the paradigm of responsive regulation (that also employs ex ante tools) to prevent and mitigate the effects of a compromise of personal data. This approach is a departure from the post-data breach sanctions that currently dominate data protection regimes worldwide. Part 4 sets out the features of institutional design and inter-sectoral coordination required for effective implementation of such a model approach for risk-based supervision and enforcement of data protection rights.\",\"PeriodicalId\":128369,\"journal\":{\"name\":\"CompSciRN: Other Cybersecurity\",\"volume\":\"34 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2019-11-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"CompSciRN: Other Cybersecurity\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.2139/ssrn.3552665\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"CompSciRN: Other Cybersecurity","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.2139/ssrn.3552665","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

本文提出了一种执行数据保护制度的新方法的想法,该方法基于基于风险的监督和使用一系列响应性执法工具,这些工具可以在违规之前部署以防止违规,也可以在违规之后部署以减轻影响。在基于风险的监管方法的基础上,该模型提出了一种方法,用于识别那些在其持有的个人数据受到损害时可能对个人和系统构成更大风险的实体。本文的第2部分提出了一个基于风险的框架,该框架使用定性和定量组件,根据实体在其持有的个人数据被泄露时构成的风险对实体进行识别和分类。第3部分列出了数据保护的执行工具包,以响应式监管范式(也使用事前工具)为指导,以防止和减轻个人数据泄露的影响。这种方法与目前在全球数据保护制度中占主导地位的数据泄露后制裁不同。第4部分列出了有效实施这种基于风险的监督和执行数据保护权利的模式方法所需的制度设计和部门间协调的特点。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Effective Enforcement of a Data Protection: A Model for Risk-Based Supervision Using Responsive Regulatory Tools
This paper presents ideas for a new approach to enforcement of a data protection regime, based on risk-based supervision and the use of a range of responsive enforcement tools that could be deployed in advance of a breach to prevent it, or after a breach to mitigate the effects. Building on the risk-based approach to supervision, the model proposes a methodology to identify those entities that potentially pose more risk (to individuals and the system) when the personal data they hold is compromised.

Part 2 of this paper proposes a risk-based framework to identify and classify entities based on the risk they pose when the personal data they hold is compromised, using both qualitative and quantitative components. Part 3 sets out an enforcement toolkit for data protection, guided by the paradigm of responsive regulation (that also employs ex ante tools) to prevent and mitigate the effects of a compromise of personal data. This approach is a departure from the post-data breach sanctions that currently dominate data protection regimes worldwide. Part 4 sets out the features of institutional design and inter-sectoral coordination required for effective implementation of such a model approach for risk-based supervision and enforcement of data protection rights.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信