{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,10]],"date-time":"2024-09-10T21:39:55Z","timestamp":1726004395262},"publisher-location":"Cham","reference-count":42,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030025465"},{"type":"electronic","value":"9783030025472"}],"license":[{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018]]},"DOI":"10.1007\/978-3-030-02547-2_2","type":"book-chapter","created":{"date-parts":[[2018,12,29]],"date-time":"2018-12-29T09:22:57Z","timestamp":1546075377000},"page":"24-42","update-policy":"http:\/\/dx.doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["Towards a Roadmap for Privacy Technologies and the General Data Protection Regulation: A Transatlantic Initiative"],"prefix":"10.1007","author":[{"given":"Stefan","family":"Schiffner","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bettina","family":"Berendt","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Triin","family":"Siil","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Martin","family":"Degeling","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Robert","family":"Riemann","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Florian","family":"Schaub","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kim","family":"Wuyts","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Massimo","family":"Attoresi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Seda","family":"G\u00fcrses","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Achim","family":"Klabunde","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jules","family":"Polonetsky","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Norman","family":"Sadeh","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Gabriela","family":"Zanfir-Fortuna","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2018,12,30]]},"reference":[{"key":"2_CR1","series-title":"IFIP Advances in Information and Communication Technology","doi-asserted-by":"publisher","first-page":"446","DOI":"10.1007\/978-3-642-55415-5_38","volume-title":"ICT Systems Security and Privacy Protection","author":"J-H Hoepman","year":"2014","unstructured":"Hoepman, J.-H.: Privacy design strategies. In: Cuppens-Boulahia, N., Cuppens, F., Jajodia, S., Abou El Kalam, A., Sans, T. (eds.) SEC 2014. IAICT, vol. 428, pp. 446\u2013459. Springer, Heidelberg (2014). \nhttps:\/\/doi.org\/10.1007\/978-3-642-55415-5_38"},{"key":"2_CR2","unstructured":"ENISA: Privacy Enhancing Technologies: Evolution and State of the Art A Community Approach to PETs Maturity Assessment (2016). https:\/\/www.enisa.europa.eu\/publications\/pets-evolution-and-state-of-the-art"},{"key":"2_CR3","unstructured":"Schaub, F., Balebako, R., Durity, A.L., Cranor, L.F.: A design space for effective privacy notices. In: Eleventh Symposium on Usable Privacy and Security (SOUPS 2015), Ottawa, pp. 1\u201317. USENIX Association (2015)"},{"key":"2_CR4","unstructured":"President\u2019s Council of Advisors on Science and Technology: Big data and privacy: a technological perspective. Report to the U.S. President, Executive Office of the President, May 2014"},{"key":"2_CR5","first-page":"273","volume":"10","author":"LF Cranor","year":"2012","unstructured":"Cranor, L.F.: Necessary but not sufficient: standard mechanisms for privacy notice and choice. J. Telecommun. High Technol. Law 10, 273 (2012)","journal-title":"J. Telecommun. High Technol. Law"},{"issue":"2","key":"2_CR6","doi-asserted-by":"publisher","first-page":"59","DOI":"10.1109\/MSP.2010.84","volume":"8","author":"FH Cate","year":"2010","unstructured":"Cate, F.H.: The limits of notice and choice. IEEE Secur. Priv. 8(2), 59\u201362 (2010)","journal-title":"IEEE Secur. Priv."},{"issue":"3","key":"2_CR7","doi-asserted-by":"publisher","first-page":"70","DOI":"10.1109\/MIC.2017.75","volume":"21","author":"F Schaub","year":"2017","unstructured":"Schaub, F., Balebako, R., Cranor, L.F.: Designing effective privacy notices and controls. IEEE Internet Comput. 21(3), 70\u201377 (2017)","journal-title":"IEEE Internet Comput."},{"key":"2_CR8","unstructured":"Wenning, R., et al.: The platform for privacy preferences 1.1 (P3P 1.1) specification (2006). https:\/\/www.w3.org\/TR\/2018\/NOTE-P3P11-20180830\/"},{"key":"2_CR9","unstructured":"Fielding, R.T., Singer, D.: Tracking preference expression (DNT) W3C candidate recommendation (2017). https:\/\/www.w3.org\/TR\/2017\/CR-tracking-dnt-20171019\/"},{"key":"2_CR10","unstructured":"Article 29 Working Party. Opinion 05\/2014 on anonymisation techniques (2014). WP216. \nhttp:\/\/ec.europa.eu\/justice\/data-protection\/article-29\/documentation\/opinion-recommendation\/files\/2014\/wp216_en.pdf"},{"key":"2_CR11","doi-asserted-by":"crossref","unstructured":"Narayanan, A., Shmatikov, V.: Robust de-anonymization of large sparse datasets. In: 2008 IEEE Symposium on Security and Privacy, SP 2008 (2008)","DOI":"10.1109\/SP.2008.33"},{"key":"2_CR12","unstructured":"Cavoukian, A., Castro, D.: Big data and innovation, setting the record straight: de-identification does work. In: Information and Privacy Commissioner, p. 18 (2014)"},{"key":"2_CR13","unstructured":"Hu, R., Stalla-Bourdillon, S., Yang, M., Schiavo, V., Sassone, V.: Bridging policy, regulation and practice? A techno-legal analysis of three types of data in the GDPR. In: Data Protection and Privacy: The Age of Intelligent Machines, p. 39 (2017)"},{"issue":"4","key":"2_CR14","doi-asserted-by":"publisher","first-page":"543","DOI":"10.1016\/0957-4174(95)00023-2","volume":"9","author":"LR Ye","year":"1995","unstructured":"Ye, L.R.: The value of explanation in expert systems for auditing: an experimental investigation. Expert Syst. Appl. 9(4), 543\u2013556 (1995)","journal-title":"Expert Syst. Appl."},{"key":"2_CR15","unstructured":"Article 29 Working Party. Guidelines on transparency under regulation 2016\/679 (2016). 17\/EN WP260. \nhttp:\/\/ec.europa.eu\/newsroom\/article29\/item-detail.cfm?item_id\u2009=\u2009615250"},{"key":"2_CR16","doi-asserted-by":"publisher","first-page":"76","DOI":"10.1093\/idpl\/ipx005","volume":"7","author":"S Wachter","year":"2017","unstructured":"Wachter, S., Mittelstadt, B., Floridi, L.: Why a right to explanation of automated decision-making does not exist in the general data protection regulation. Int. Data Priv. Law 7, 76\u201399 (2017)","journal-title":"Int. Data Priv. Law"},{"issue":"4","key":"2_CR17","doi-asserted-by":"publisher","first-page":"233","DOI":"10.1093\/idpl\/ipx022","volume":"7","author":"AD Selbst","year":"2017","unstructured":"Selbst, A.D., Powles, J.: Meaningful information and the right to explanation. Int. Data Priv. Law 7(4), 233\u2013242 (2017)","journal-title":"Int. Data Priv. Law"},{"key":"2_CR18","unstructured":"Biran, O., Cotton, C.: Explanation and justification in machine learning: a survey. In: IJCAI-17 Workshop on Explainable AI (XAI) Proceedings, pp. 8\u201313 (2017). \nhttp:\/\/www.intelligentrobots.org\/files\/IJCAI2017\/IJCAI-17_XAI_WS_Proceedings.pdf#page=8"},{"key":"2_CR19","unstructured":"Lipton, Z.C.: The mythos of model interpretability. In: ICML 2016 Workshop on Human Interpretability in Machine Learning (WHI 2016) (2016). \nhttp:\/\/zacklipton.com\/media\/papers\/mythos_model_interpretability_lipton2016.pdf"},{"key":"2_CR20","first-page":"18","volume":"16","author":"L Edwards","year":"2017","unstructured":"Edwards, L., Veale, M.: Slave to the algorithm? Why a \u2019right to an explanation\u2019 is probably not the remedy you are looking for. Duke Law Technol. Rev. 16, 18 (2017)","journal-title":"Duke Law Technol. Rev."},{"key":"2_CR21","unstructured":"Article 29 Working Party. Guidelines on automated individual decision-making and profiling for the purposes of regulation 2016\/679 (2018). 17\/EN WP251rev.01. \nhttp:\/\/ec.europa.eu\/newsroom\/article29\/item-detail.cfm?item_id=612053"},{"key":"2_CR22","doi-asserted-by":"crossref","unstructured":"Obar, J.A., Oeldorf-Hirsch, A., The biggest lie on the internet: ignoring the privacy policies and terms of service policies of social networking services. In: TPRC 44: The 44th Research Conference on Communication, Information and Internet Policy (2016)","DOI":"10.2139\/ssrn.2757465"},{"key":"2_CR23","unstructured":"Cate, F.H.: Information security breaches: looking back & thinking ahead. Technical report Paper 233, Articles by Maurer Faculty (2008). \nhttp:\/\/www.repository.law.indiana.edu\/facpub\/233"},{"issue":"4","key":"2_CR24","doi-asserted-by":"publisher","first-page":"703","DOI":"10.1007\/s00778-006-0034-x","volume":"17","author":"M Atzori","year":"2008","unstructured":"Atzori, M., Bonchi, F., Giannotti, F., Pedreschi, D.: Anonymity preserving pattern discovery. VLDB J. 17(4), 703\u2013727 (2008)","journal-title":"VLDB J."},{"key":"2_CR25","doi-asserted-by":"crossref","unstructured":"Hansen, M., Jensen, M., Rost, M.: Protection goals for privacy engineering. In: 2015 IEEE Security and Privacy Workshops (SPW), pp. 159\u2013166, May 2015","DOI":"10.1109\/SPW.2015.13"},{"key":"2_CR26","unstructured":"Schmidt , A., Herrmann, T., Degeling, M.: From interaction to intervention: an approach for keeping humans in control in the context of socio-technical systems. In: 4th Workshop on Socio-Technical Perspective in IS development (STPIS 2018) (2018)"},{"key":"2_CR27","doi-asserted-by":"crossref","unstructured":"Ribeiro, M.T., Singh, S., Guestrin, C.: \u201cWhy should I trust you?\u201d: explaining the predictions of any classifier. In: Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, KDD 2016, pp. 1135\u20131144. ACM, New York (2016)","DOI":"10.1145\/2939672.2939778"},{"key":"2_CR28","doi-asserted-by":"publisher","unstructured":"G\u00fcrses, S., van Hoboken, J.: Privacy after the agile turn. In: Selinger, E., Polonetsky, J., Tene, O. (eds.) The Cambridge Handbook of Consumer Privacy (Cambridge Law Handbooks, pp. 579\u2013601). Cambridge University Press, Cambridge (2018). https:\/\/doi.org\/10.1017\/9781316831960.032","DOI":"10.1017\/9781316831960.032"},{"key":"2_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"198","DOI":"10.1007\/978-3-642-17819-1_22","volume-title":"Provenance and Annotation of Data and Processes","author":"L Ding","year":"2010","unstructured":"Ding, L., Bao, J., Michaelis, J.R., Zhao, J., McGuinness, D.L.: Reflections on provenance ontology encodings. In: McGuinness, D.L., Michaelis, J.R., Moreau, L. (eds.) IPAW 2010. LNCS, vol. 6378, pp. 198\u2013205. Springer, Heidelberg (2010). \nhttps:\/\/doi.org\/10.1007\/978-3-642-17819-1_22"},{"key":"2_CR30","unstructured":"Oliver, I.: Privacy Engineering: A Data Flow and Ontological Approach. CreateSpace Independent Publishing, July 2014. 978-1497569713"},{"issue":"3","key":"2_CR31","doi-asserted-by":"publisher","first-page":"169","DOI":"10.1007\/s00766-003-0183-z","volume":"9","author":"AI Anton","year":"2004","unstructured":"Anton, A.I., Earp, J.B.: A requirements taxonomy for reducing web site privacy vulnerabilities. Requirements Eng. 9(3), 169\u2013185 (2004)","journal-title":"Requirements Eng."},{"issue":"3","key":"2_CR32","doi-asserted-by":"publisher","first-page":"477","DOI":"10.2307\/40041279","volume":"154","author":"DJ Solove","year":"2006","unstructured":"Solove, D.J.: A taxonomy of privacy. Univ. Pennsylvania Law Rev. 154(3), 477 (2006). GWU Law School Public Law Research Paper No. 129","journal-title":"Univ. Pennsylvania Law Rev."},{"issue":"4","key":"2_CR33","doi-asserted-by":"publisher","first-page":"1087","DOI":"10.2307\/3481326","volume":"90","author":"J Daniel","year":"2002","unstructured":"Solove, D.J.: Conceptualizing privacy. Calif. Law Rev. 90(4), 1087\u20131155 (2002)","journal-title":"Calif. Law Rev."},{"key":"2_CR34","doi-asserted-by":"crossref","unstructured":"Kost, M., Freytag, J.C., Kargl, F., Kung, A.: Privacy verification using ontologies. In: ARES, pp. 627\u2013632. IEEE (2011)","DOI":"10.1109\/ARES.2011.97"},{"key":"2_CR35","volume-title":"Flight Discipline","author":"T Kern","year":"1998","unstructured":"Kern, T.: Flight Discipline. McGraw-Hill Education, New York (1998)"},{"key":"2_CR36","doi-asserted-by":"publisher","first-page":"23","DOI":"10.1002\/jhrm.20101","volume":"31","author":"AJ Card","year":"2012","unstructured":"Card, A.J., Ward, J.R., Clarkson, P.J.: Beyond FMEA: the structured what-if technique (SWIFT). J. Healthc. Risk Manag. 31, 23\u201329 (2012)","journal-title":"J. Healthc. Risk Manag."},{"issue":"2","key":"2_CR37","doi-asserted-by":"publisher","first-page":"163","DOI":"10.1007\/s00766-013-0195-2","volume":"20","author":"R Scandariato","year":"2015","unstructured":"Scandariato, R., Wuyts, K., Joosen, W.: A descriptive study of Microsoft\u2019s threat modeling technique. Requirements Eng. 20(2), 163\u2013180 (2015)","journal-title":"Requirements Eng."},{"key":"2_CR38","unstructured":"Gawande, A.: The Checklist Manifesto. Profile Books (2011)"},{"key":"2_CR39","volume-title":"Managing the Risks of Organizational Accidents","author":"JT Reason","year":"1997","unstructured":"Reason, J.T.: Managing the Risks of Organizational Accidents. Ashgate, Farnham (1997)"},{"issue":"3","key":"2_CR40","doi-asserted-by":"publisher","first-page":"265","DOI":"10.1016\/S0164-1212(00)00017-0","volume":"53","author":"SL Pfleeger","year":"2000","unstructured":"Pfleeger, S.L.: Risky business: what we have yet to learn about risk management. J. Syst. Softw. 53(3), 265\u2013273 (2000)","journal-title":"J. Syst. Softw."},{"key":"2_CR41","doi-asserted-by":"crossref","unstructured":"Oliver, I.: Experiences in the development and usage of a privacy requirements framework. In: 24th IEEE International Requirements Engineering Conference, RE 2016, Beijing, China, 12\u201316 September 2016, pp. 293\u2013302. IEEE Computer Society (2016)","DOI":"10.1109\/RE.2016.59"},{"key":"2_CR42","doi-asserted-by":"publisher","first-page":"58","DOI":"10.1108\/eb023001","volume":"5","author":"M Power","year":"2004","unstructured":"Power, M.: The risk management of everything. J. Risk Finance 5, 58\u201365 (2004)","journal-title":"J. Risk Finance"}],"container-title":["Lecture Notes in Computer Science","Privacy Technologies and Policy"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-02547-2_2","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2018,12,29]],"date-time":"2018-12-29T09:23:43Z","timestamp":1546075423000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-030-02547-2_2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018]]},"ISBN":["9783030025465","9783030025472"],"references-count":42,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-02547-2_2","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2018]]},"assertion":[{"value":"APF","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Annual Privacy Forum","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Barcelona","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Spain","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2018","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"13 June 2018","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14 June 2018","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"6","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"apf2018","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/privacyforum.eu\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"49","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"11","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"22% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"3.16","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"3.0","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}}]}}