data privacy

Designs, implements, and evaluates systems, processes, and policies that prevent unauthorized access, disclosure, or misuse of data and that control how data is collected, stored, shared, and deleted. Builds and analyzes technical and organizational controls—such as access control, encryption, anonymization and de-identification, auditing and logging, consent mechanisms, and privacy-preserving algorithms—and assesses privacy risk, privacy–utility trade-offs, and compliance with relevant legal or regulatory requirements.

dataprivacy

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
-0.5
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$207K/year
Oct 01, 2026Oct 01, 2026

Must-Read Papers

Most classic and influential ideas
View more

This study addresses the escalating threat of unauthorized data access confronting enterprises and proposes an integrated defense framework that synergistically combines technological, human, and organizational dimensions. The framework establishes a robust security foundation through technical measures such as firewalls, intrusion detection systems, and encryption, while simultaneously reinforcing this infrastructure with employee security awareness training and rigorous enforcement of data access policies. By integrating these layers into a cohesive, defense-in-depth architecture, the approach not only substantially mitigates the risk of data breaches but also enhances organizational compliance and overall cyber resilience. This work thus offers a practical, holistic solution for effective data governance in complex enterprise environments.

data breach preventiondata securityregulatory compliance

Two Types of Data Privacy Controls

Mar 24, 2025
EA
Eman Alashwali
🏛️ King Abdulaziz University

Users widely perceive a loss of data control, stemming from existing privacy mechanisms that conflate two distinct types of control: interpersonal privacy (e.g., social sharing settings) and user-institutional privacy (e.g., platform-level data processing rights). This paper introduces and rigorously substantiates the “dichotomy of control objects,” arguing that current privacy design overemphasizes the former while systematically neglecting the latter. Through an interdisciplinary investigation—including controlled human-computer interaction experiments, comparative analysis of privacy policy texts, and critical information ethics inquiry—the study exposes the structural inadequacies of prevailing “one-size-fits-all” privacy interfaces. Findings inform the redesign of privacy interfaces, strengthen regulatory enforcement (e.g., GDPR compliance), and advance institutional innovations such as data trusts. Collectively, this work shifts the paradigm from procedural consent toward substantive user empowerment in data governance.

Address lack of user control over shared dataAnalyze overlooked privacy control type differencesDistinguish user-user vs user-institution privacy controls

Conformidade com os Requisitos Legais de Privacidade de Dados: Um Estudo sobre Técnicas de Anonimização

Jul 24, 2025
AM
André Menolli
🏛️ Universidade Estadual do Norte do Paraná | Universidade Estadual de Londrina

This study addresses the core challenge of balancing regulatory compliance—specifically with LGPD and GDPR—with data utility in privacy-preserving data anonymization. We systematically evaluate the privacy protection strength and utility loss of mainstream techniques—including aggregation, generalization, perturbation, and k-anonymity—on real-world sensitive datasets. Through quantitative comparative experiments, we characterize their distinct trade-offs along the privacy–utility spectrum and propose a context-aware technical selection framework guided by application-specific features (e.g., data dimensionality, analytical task type, and regulatory emphasis). Our key contributions are threefold: (1) the first unified empirical validation of the interplay between multi-regulatory compliance and utility preservation; (2) identification of mechanistic links between anonymization method choice and cross-jurisdictional compliance feasibility; and (3) a practical, evidence-based decision guide for privacy engineers to select optimal anonymization strategies under legal and operational constraints. (149 words)

Assessing effectiveness of methods like k-anonymity and perturbationBalancing privacy protection with data utility in anonymizationEvaluating data anonymization techniques for legal compliance

Understanding issues related to personal data and data protection in open source projects on GitHub

Apr 13, 2023
AH
Anne Hennig
🏛️ Karlsruhe Institute of Technology | University of Passau | IT University of Copenhagen | University of Southern Denmark

This study investigates how data protection regulations (e.g., GDPR, CCPA) impact open-source software (OSS) development practices, focusing on the reporting, discussion, and resolution of personal-data-related issues in GitHub projects. Using an exploratory empirical approach—combining inductive thematic coding, annotating reporter roles and issue states, and conducting relevance-based statistical analysis—the authors systematically identify six recurrent categories of data protection issues. Results show that such issues are predominantly reported by non-core contributors; resolution rates are low and rely heavily on non-technical negotiation rather than code-level fixes; and a structural tension exists between regulatory compliance requirements and OSS development culture. This work is the first to empirically demonstrate how data protection obligations are substantively embedded within OSS development workflows, thereby bridging regulatory compliance and OSS engineering practice. It provides foundational evidence and design insights for developing compliance-aware open-source governance mechanisms.

Analyzing developer reactions and resolutions to data protection issuesExamining data protection regulations' impact on software development processesIdentifying who reports and discusses personal data issues in GitHub projects

DePLOI: Applying NL2SQL to Synthesize and Audit Database Access Control

Feb 11, 2024
PS
Pranav Subramaniam
🏛️ University of Chicago

In enterprise databases, access control policy specification and enforcement are often decoupled, leading to cumbersome, non-systematic manual auditing. To address this, we propose Intent-Based Access Control for Databases (IBAC-DB), a novel model supporting semantic policy modeling and bidirectional traceability between policies and their implementations. We introduce IBACBench—the first benchmark tailored for database access control—and DePLOI, an LLM-based system featuring a task-decomposition paradigm for NL2SQL translation. DePLOI integrates domain-customized NL2SQL, role-hierarchy-aware modeling, and hybrid synthetic data generation for evaluation. Experiments on IBACBench demonstrate that DePLOI achieves significantly higher synthesis accuracy and auditing F1-score (+10 F1) than state-of-the-art baselines, validating the feasibility and robustness of automating secure access control policy deployment.

Automating database access control policy synthesis and auditingBridging policy principles with database-level implementation processesEvaluating NL2SQL systems for access control compliance accuracy

Latest Papers

What's happening recently
View more

This study addresses the challenges posed by divergent and conflicting data protection regulations across jurisdictions, which hinder the early identification of compliance requirements in software development and often lead to costly rework and legal risks. Drawing on interviews with 70 legal experts from G20 and other countries, the research employs systematic content analysis and deductive qualitative methods to distill, for the first time from a legal expert perspective, both commonalities—such as consent—and key divergences—such as the right to be forgotten—across global data protection laws. These insights are innovatively operationalized into a comprehensive set of Data Protection Officer (DPO) user stories mapped to each phase of the software development lifecycle and enterprise architecture layers, significantly enhancing the actionable integration of compliance requirements into early-stage software engineering practices.

data protection regulationsprivacy complianceregulatory data protection requirements

This work addresses the challenge of efficiently verifying whether corporate privacy policies comply with data protection laws. It proposes APLiance, a novel framework that formalizes legal compliance as an attribute-based access control (ABAC) authorization decision: by semantically mapping privacy policy clauses into implicit access requests and checking whether they are permitted under an ABAC policy modeled from legal provisions. Integrating natural language processing with access control mechanisms, the approach enables automated compliance verification. Empirical evaluation in the context of India’s Digital Personal Data Protection Act demonstrates its effectiveness, and the authors release an open-source browser extension that allows users to assess the legal compliance of website privacy policies in real time.

ABACdata protectionlaw compliance

This study addresses the long-standing lack of a unified software engineering perspective on privacy documents throughout their lifecycle, which has led to fragmented approaches in generation, analysis, compliance verification, and usability evaluation. Through a systematic literature review (SoK) of 290 studies published between 2010 and 2025, this work proposes the first comprehensive lifecycle framework encompassing definition, generation, analysis, compliance validation, and usability assessment. The research identifies 15 key trends, 21 open challenges, and four major future directions, with particular emphasis on leveraging large language models for analyzing consistency between privacy policies and code implementations. By establishing a structured knowledge base and introducing a novel paradigm that balances usability for both end users and developers, this work lays a shared foundation for privacy documentation research in the AI era.

lifecycleprivacy documentsprivacy policies

This study addresses the challenges of assessing compliance between organizational cybersecurity policies and abstract security control frameworks such as NIST SP 800-53, which are often time-consuming, difficult to standardize, and lack traceability. To overcome these limitations, the authors propose PROPAGATE, a novel framework that leverages large language models (LLMs) to automate control-level compliance evaluation for the first time. By integrating both open-source and closed-source LLMs, the framework automatically retrieves relevant policy text, evaluates coverage across 1,007 security controls, and generates interpretable gap analyses with actionable improvement recommendations. Experimental results on two real-world organizational policy corpora demonstrate high effectiveness, achieving F1 scores of 88.54 and 82.31, respectively, thereby enabling traceable and explainable compliance enhancement.

compliance assessmentcybersecurity policyNIST SP 800-53

Hot Scholars

JD

Jinho D. Choi

Associate Professor, Emory University
Natural Language ProcessingComputational LinguisticsConversational AI
VM

Victor Morel

Chalmers University of Technology
privacyinterplay law/technology
LH

Lei Hou

RMIT University
Building Information Modeling (BIM) - Project Management - Construction IT - Productivity Research - Lean Construction
DK

Dongyeop Kang

University of Minnesota
Natural Language Processing