{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,8]],"date-time":"2026-06-08T21:49:46Z","timestamp":1780955386873,"version":"3.54.1"},"reference-count":58,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2021,10,5]],"date-time":"2021-10-05T00:00:00Z","timestamp":1633392000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Manage. Inf. Syst."],"published-print":{"date-parts":[[2022,3,31]]},"abstract":"<jats:p>Privacy and confidentiality are very important prerequisites for applying process mining to comply with regulations and keep company secrets. This article provides a foundation for future research on privacy-preserving and confidential process mining techniques. Main threats are identified and related to a motivation application scenario in a hospital context as well as to the current body of work on privacy and confidentiality in process mining. A newly developed conceptual model structures the discussion that existing techniques leave room for improvement. This results in a number of important research challenges that should be addressed by future process mining research.<\/jats:p>","DOI":"10.1145\/3468877","type":"journal-article","created":{"date-parts":[[2021,10,5]],"date-time":"2021-10-05T18:37:36Z","timestamp":1633459056000},"page":"1-17","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":43,"title":["Privacy and Confidentiality in Process Mining: Threats and Research Challenges"],"prefix":"10.1145","volume":"13","author":[{"given":"Gamal","family":"Elkoumy","sequence":"first","affiliation":[{"name":"University of Tartu, Tartu, Estonia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Stephan A.","family":"Fahrenkrog-Petersen","sequence":"additional","affiliation":[{"name":"Humboldt-Universit\u00e4t zu Berlin, Berlin, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mohammadreza Fani","family":"Sani","sequence":"additional","affiliation":[{"name":"RWTH-Aachen University, Aachen, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Agnes","family":"Koschmider","sequence":"additional","affiliation":[{"name":"Kiel University, Kiel, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1733-777X","authenticated-orcid":false,"given":"Felix","family":"Mannhardt","sequence":"additional","affiliation":[{"name":"Eindhoven University of Technology, Eindhoven, The Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Saskia Nu\u00f1ez","family":"Von Voigt","sequence":"additional","affiliation":[{"name":"Technische Universit\u00e4t Berlin, Berlin, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Majid","family":"Rafiei","sequence":"additional","affiliation":[{"name":"RWTH-Aachen University, Aachen, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Leopold Von","family":"Waldthausen","sequence":"additional","affiliation":[{"name":"Magdalen College, University of Oxford, Oxford, United Kingdom"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,10,5]]},"reference":[{"key":"e_1_3_2_2_2","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2018.2841877"},{"key":"e_1_3_2_3_2","first-page":"159","volume-title":"BPM (PhD\/Demos)","volume":"2420","author":"Bauer Martin","year":"2019","unstructured":"Martin Bauer, Stephan A. Fahrenkrog-Petersen, Agnes Koschmider, Felix Mannhardt, Han van der Aa, and Matthias Weidlich. 2019. ELPaaS: Event log privacy as a service. In BPM (PhD\/Demos) (CEUR Workshop Proceedings, Vol. 2420). CEUR-WS.org, 159\u2013163."},{"key":"e_1_3_2_4_2","volume-title":"Proceedings of the Joint Workshop on Mobile Web Privacy WAP Forum and World Wide Web Consortium","volume":"7","author":"Bergeron Eric","year":"2000","unstructured":"Eric Bergeron. 2000. The difference between security and privacy. In Proceedings of the Joint Workshop on Mobile Web Privacy WAP Forum and World Wide Web Consortium, Vol. 7."},{"key":"e_1_3_2_5_2","doi-asserted-by":"publisher","DOI":"10.5555\/3312458"},{"key":"e_1_3_2_6_2","first-page":"289","article-title":"The universal declaration of human rights and sodomy laws: A federal common law right to privacy for homosexuals based on customary international law","volume":"31","author":"Catania David A.","year":"1993","unstructured":"David A. Catania. 1993. The universal declaration of human rights and sodomy laws: A federal common law right to privacy for homosexuals based on customary international law. American Criminal Law Review 31 (1993), 289.","journal-title":"American Criminal Law Review"},{"key":"e_1_3_2_7_2","doi-asserted-by":"publisher","DOI":"10.1073\/pnas.1914598117"},{"key":"e_1_3_2_8_2","article-title":"APEC privacy framework","volume":"81","author":"Cooperation Asia-Pacific Economic","year":"2005","unstructured":"Asia-Pacific Economic Cooperation. 2005. APEC privacy framework. Asia Pacific Economic Cooperation Secretariat 81 (2005).","journal-title":"Asia Pacific Economic Cooperation Secretariat"},{"key":"e_1_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.1145\/773153.773173"},{"key":"e_1_3_2_10_2","first-page":"1","article-title":"A knowledge-based approach to security requirements for e-health applications","author":"Dritsas S.","year":"2006","unstructured":"S. Dritsas, L. Gymnopoulos, M. Karyda, T. Balopoulos, S. Kokolakis, C. Lambrinoudakis, and S. Katsikas. 2006. A knowledge-based approach to security requirements for e-health applications. Electronic Journal for E-Commerce Tools and Applications 2006 (2006), 1\u201324.","journal-title":"Electronic Journal for E-Commerce Tools and Applications"},{"key":"e_1_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.5555\/1791834.1791836"},{"key":"e_1_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1146\/annurev-statistics-060116-054123"},{"key":"e_1_3_2_13_2","series-title":"Lecture Notes in Business Information Processing","doi-asserted-by":"crossref","first-page":"166","DOI":"10.1007\/978-3-030-49418-6_11","volume-title":"Enterprise, Business-Process and Information Systems Modeling","author":"Elkoumy Gamal","year":"2020","unstructured":"Gamal Elkoumy, Stephan A. Fahrenkrog-Petersen, Marlon Dumas, Peeter Laud, Alisa Pankova, and Matthias Weidlich. 2020. Secure multi-party computation for inter-organizational process mining. In Enterprise, Business-Process and Information Systems Modeling. Lecture Notes in Business Information Processing, Vol. 387. Springer, 166\u2013181."},{"key":"e_1_3_2_14_2","first-page":"72","volume-title":"BPM (PhD\/Demos)","volume":"2673","author":"Elkoumy Gamal","year":"2020","unstructured":"Gamal Elkoumy, Stephan A. Fahrenkrog-Petersen, Marlon Dumas, Peeter Laud, Alisa Pankova, and Matthias Weidlich. 2020. Shareprom: A tool for privacy-preserving inter-organizational process mining. In BPM (PhD\/Demos) (CEUR Workshop Proceedings, Vol. 2673). CEUR-WS.org, 72\u201376."},{"key":"e_1_3_2_15_2","first-page":"23","volume-title":"Proceedings of the Doctoral Consortium Papers Presented at the 31st International Conference on Advanced Information Systems Engineering (CAiSE 2019), Rome, Italy, June 3-7, 2019","volume":"2370","author":"Fahrenkrog-Petersen Stephan A.","year":"2019","unstructured":"Stephan A. Fahrenkrog-Petersen. 2019. Providing privacy guarantees in process mining. In Proceedings of the Doctoral Consortium Papers Presented at the 31st International Conference on Advanced Information Systems Engineering (CAiSE 2019), Rome, Italy, June 3-7, 2019 (CEUR Workshop Proceedings, Vol. 2370). CEUR-WS.org, 23\u201330. http:\/\/ceur-ws.org\/Vol-2370\/paper-03.pdf."},{"key":"e_1_3_2_16_2","unstructured":"Stephan A. Fahrenkrog-Petersen Niek Tax Irene Teinemaa Marlon Dumas Massimiliano de Leoni Fabrizio Maria Maggi and Matthias Weidlich. 2019. Fire now fire later: Alarm-based systems for prescriptive process monitoring. arXiv:1905.09568."},{"key":"e_1_3_2_17_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICPM.2019.00012"},{"key":"e_1_3_2_18_2","doi-asserted-by":"crossref","first-page":"111","DOI":"10.1007\/978-3-030-58666-9_7","volume-title":"Business Process Management","author":"Fahrenkrog-Petersen Stephan A.","year":"2020","unstructured":"Stephan A. Fahrenkrog-Petersen, Han van der Aa, and Matthias Weidlich. 2020. PRIPEL: Privacy-preserving event log publishing including contextual information. In Business Process Management. Lecture Notes in Computer Science, Vol. 12168. Springer, 111\u2013128."},{"key":"e_1_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"e_1_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-69904-2_16"},{"key":"e_1_3_2_21_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-50316-1_28"},{"key":"e_1_3_2_22_2","doi-asserted-by":"publisher","DOI":"10.1001\/virtualmentor.2012.14.9.stas1-1209"},{"key":"e_1_3_2_23_2","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2014.35"},{"key":"e_1_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.1145\/3329717"},{"key":"e_1_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.1145\/1065167.1065183"},{"key":"e_1_3_2_26_2","doi-asserted-by":"publisher","DOI":"10.5555\/2051002.2051032"},{"key":"e_1_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE.2007.367856"},{"key":"e_1_3_2_28_2","doi-asserted-by":"publisher","DOI":"10.1145\/1217299.1217302"},{"key":"e_1_3_2_29_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-07881-6_31"},{"key":"e_1_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.1007\/s12599-019-00613-3"},{"key":"e_1_3_2_31_2","first-page":"Article 8, 4 pa","article-title":"Trust and privacy in process analytics","volume":"15","author":"Mannhardt Felix","year":"2020","unstructured":"Felix Mannhardt, Agnes Koschmider, Lars Biermann, Jana Lange, Florian Tschorsch, and Moe Thandar Wynn. 2020. Trust and privacy in process analytics. Enterprise Modelling and Information Systems Architectures: International Journal of Conceptual Modeling 15 (2020), Article 8, 4 pages.","journal-title":"Enterprise Modelling and Information Systems Architectures: International Journal of Conceptual Modeling"},{"key":"e_1_3_2_32_2","doi-asserted-by":"publisher","DOI":"10.1109\/IE.2018.00017"},{"key":"e_1_3_2_33_2","doi-asserted-by":"publisher","DOI":"10.1145\/1055558.1055591"},{"key":"e_1_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.1145\/2629446"},{"key":"e_1_3_2_35_2","first-page":"1","volume-title":"Designing Privacy Enhancing Technologies","author":"Pfitzmann Andreas","year":"2000","unstructured":"Andreas Pfitzmann and Marit K\u00f6hntopp. 2000. Anonymity, unobservability, and pseudonymity\u2014A proposal for terminology. In Designing Privacy Enhancing Technologies. Lecture Notes in Computer Science, Vol. 2009. Springer, 1\u20139."},{"key":"e_1_3_2_36_2","doi-asserted-by":"publisher","DOI":"10.1145\/3041218"},{"key":"e_1_3_2_37_2","doi-asserted-by":"publisher","DOI":"10.3390\/ijerph17051612"},{"key":"e_1_3_2_38_2","doi-asserted-by":"crossref","first-page":"676","DOI":"10.1007\/978-3-030-37453-2_54","volume-title":"Business Process Management Workshops\u2014BPM 2019 International Workshops, Vienna, Austria, September 1-6, 2019, Revised Selected Papers","author":"Rafiei Majid","year":"2019","unstructured":"Majid Rafiei and Wil M. P. van der Aalst. 2019. Mining roles from event logs while preserving privacy. In Business Process Management Workshops\u2014BPM 2019 International Workshops, Vienna, Austria, September 1-6, 2019, Revised Selected Papers. Springer, 676\u2013689."},{"key":"e_1_3_2_39_2","first-page":"92","volume-title":"BPM (PhD\/Demos)","volume":"2673","author":"Rafiei Majid","year":"2020","unstructured":"Majid Rafiei and Wil M. P. van der Aalst. 2020. Practical aspect of privacy-preserving data publishing in process mining. In BPM (PhD\/Demos) (CEUR Workshop Proceedings, Vol. 2673). CEUR-WS.org, 92\u201396."},{"key":"e_1_3_2_40_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58638-6_8"},{"key":"e_1_3_2_41_2","first-page":"385","volume-title":"Process Mining Workshops","author":"Rafiei Majid","year":"2020","unstructured":"Majid Rafiei and Wil M. P. van der Aalst. 2020. Towards quantifying privacy in process mining. In Process Mining Workshops. Lecture Notes in Business Information Processing, Vol. 406. Springer, 385\u2013397. https:\/\/doi.org\/10.1007\/978-3-030-72693-5_29"},{"key":"e_1_3_2_42_2","first-page":"3","volume-title":"SIMPDA","volume":"2270","author":"Rafiei Majid","year":"2018","unstructured":"Majid Rafiei, Leopold von Waldthausen, and Wil M. P. van der Aalst. 2018. Ensuring confidentiality in process mining. In SIMPDA (CEUR Workshop Proceedings, Vol. 2270). CEUR-WS.org, 3\u201317."},{"key":"e_1_3_2_43_2","first-page":"101","volume-title":"Data-Driven Process Discovery and Analysis","author":"Rafiei Majid","year":"2019","unstructured":"Majid Rafiei, Leopold von Waldthausen, and Wil M. P. van der Aalst. 2019. Supporting condentiality in process mining using abstraction and encryption. In Data-Driven Process Discovery and Analysis. Lecture Notes in Business Information Processing, Vol. 379. Springer, 101\u2013123."},{"key":"e_1_3_2_44_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-50316-1_24"},{"issue":"1","key":"e_1_3_2_45_2","article-title":"Regulation (EU) 2016\/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95\/46\/ec (general data protection regulation) 2016","volume":"119","author":"Regulation EU General Data Protection","year":"2016","unstructured":"EU General Data Protection Regulation. 2016. Regulation (EU) 2016\/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95\/46\/ec (general data protection regulation) 2016. International Journal of the European Union 119, 1 (2016).","journal-title":"International Journal of the European Union"},{"key":"e_1_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jbi.2016.04.007"},{"key":"e_1_3_2_47_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.datak.2004.03.008"},{"key":"e_1_3_2_48_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"e_1_3_2_49_2","doi-asserted-by":"publisher","DOI":"10.1142\/S0218488502001648"},{"key":"e_1_3_2_50_2","doi-asserted-by":"publisher","DOI":"10.1145\/3301300"},{"key":"e_1_3_2_51_2","first-page":"267","volume-title":"SECRYPT","author":"Tillem Gamze","year":"2017","unstructured":"Gamze Tillem, Zekeriya Erkin, and Reginald L. Lagendijk. 2017. Mining encrypted software logs using alpha algorithm. In SECRYPT. SciTePress, 267\u2013274."},{"key":"e_1_3_2_52_2","doi-asserted-by":"publisher","DOI":"10.5555\/2948762"},{"key":"e_1_3_2_53_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-49435-3_16"},{"key":"e_1_3_2_54_2","doi-asserted-by":"publisher","DOI":"10.1145\/3168389"},{"issue":"1","key":"e_1_3_2_55_2","first-page":"166","article-title":"Privacy and freedom","volume":"25","author":"Westin Alan F.","year":"1968","unstructured":"Alan F. Westin. 1968. Privacy and freedom. Washington and Lee Law Review 25, 1 (1968), 166.","journal-title":"Washington and Lee Law Review"},{"key":"e_1_3_2_56_2","first-page":"39","volume-title":"Proceedings of the Network and Distributed System Security Symposium","volume":"2","author":"Wright Matthew K.","year":"2002","unstructured":"Matthew K. Wright, Micah Adler, Brian Neil Levine, and Clay Shields. 2002. An analysis of the degradation of anonymous protocols. In Proceedings of the Network and Distributed System Security Symposium (NDSS'02), Vol. 2. The Internet Society, 39\u201350."},{"key":"e_1_3_2_57_2","first-page":"1","volume-title":"Proceedings of the 2019 International Conference on Process Mining Doctoral Consortium","author":"Zaman Rashid","year":"2019","unstructured":"Rashid Zaman and Marwan Hassani. 2019. Process mining meets GDPR compliance: The right to be forgotten as a use case. In Proceedings of the 2019 International Conference on Process Mining Doctoral Consortium (ICPM-DC'19). 1\u20139."},{"key":"e_1_3_2_58_2","doi-asserted-by":"publisher","DOI":"10.1007\/s42979-020-00215-x"},{"key":"e_1_3_2_59_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.dss.2012.12.001"}],"container-title":["ACM Transactions on Management Information Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3468877","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3468877","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T20:17:22Z","timestamp":1750191442000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3468877"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,10,5]]},"references-count":58,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2022,3,31]]}},"alternative-id":["10.1145\/3468877"],"URL":"https:\/\/doi.org\/10.1145\/3468877","relation":{},"ISSN":["2158-656X","2158-6578"],"issn-type":[{"value":"2158-656X","type":"print"},{"value":"2158-6578","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,10,5]]},"assertion":[{"value":"2020-12-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2021-05-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2021-10-05","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}