Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Privacy

ENISA Calls For Privacy by Design

The European Union Agency for Network and Information Security (ENISA) has published a new report on online privacy and data protection.

The agency believes the key to protecting privacy, which has been declared a fundamental right, is to focus on privacy and data protection from the beginning of the design process.

The European Union Agency for Network and Information Security (ENISA) has published a new report on online privacy and data protection.

The agency believes the key to protecting privacy, which has been declared a fundamental right, is to focus on privacy and data protection from the beginning of the design process.

The problem is that existing policy doesn’t offer any incentives for adopting privacy by design. In addition to new policies, ENISA says new electronic communication standards should also focus more on privacy and data protection.

The study points out that encryption, anonymous communications protocols, private database searches, attribute-based credentials, and other privacy-enhancing technologies have been demonstrated to be effective.

Encryption is becoming widely used, especially because of the recent revelations about the advanced capabilities of spy agencies. However, other technologies have not become a standard and they’re not utilized as much as they should be in system design, ENISA noted.

“The term ‘Privacy by Design’, or its variation ‘Data Protection by Design’, has been coined as a development method for privacy-friendly systems and services, thereby going beyond mere technical solutions and addressing organisational procedures and business models as well,” the report reads. “Although the concept has found its way into legislation as the proposed European General Data Protection Regulation, its concrete implementation remains unclear at the present moment.”

Advertisement. Scroll to continue reading.

The report is addressed to policy makers, data protection authorities, researchers, engineers, and regulators. It details approaches, strategies, and technical aspects, and provides recommendations on how to implement privacy by design with the aid of engineering methods.

ENISA says legislators need to promote data protection and privacy in their norms, and policy makers should come up with incentives for privacy-friendly services. Standardization bodies are advised to include privacy considerations into the standardization process, and provide standards for the interoperability of privacy features.

The agency also believes data protection authorities should play an important part in providing independent guidance and tools for privacy engineering. The research community should focus its efforts on privacy engineering and, in collaboration with software development tool providers, offer solutions enabling intuitive implementation of privacy properties.

The EU agency published its report just as British Prime Minister David Cameron announced his intention to introduce a new law banning encrypted communications that cannot be accessed by authorities. Experts believe this approach will not do much good. On the contrary, it will put consumers and organizations at risk.

ENISA’s report, Privacy and Data Protection by Design, is available online.

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

ServiceNow has appointed Simon Mouyal as Chief Marketing Officer.

James Wilkinson has been named Chief Information Security Officer for the City of Dallas.

PNC Financial Services Group has appointed Christian Winward as CISO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.