{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,21]],"date-time":"2026-02-21T00:49:22Z","timestamp":1771634962090,"version":"3.50.1"},"reference-count":57,"publisher":"MDPI AG","issue":"11","license":[{"start":{"date-parts":[[2022,10,31]],"date-time":"2022-10-31T00:00:00Z","timestamp":1667174400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"the H2020-MSCA-RISE-2017 project","award":["778228"],"award-info":[{"award-number":["778228"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Future Internet"],"abstract":"<jats:p>The introduction of Data Protection by Default and Design (DPbDD) brought in as part of the General Data Protection Regulation (GDPR) in 2018, has necessitated that businesses review how best to incorporate privacy into their processes in a transparent manner, so as to build trust and improve decisions around privacy best practice. To address this issue, this paper presents a 7-stage data lifecycle, supported by nine privacy goals that together, will help practitioners manage data holdings throughout data lifecycle. The resulting data lifecycle (7-DL) was created as part of the Ideal-Cities project, a Horizon-2020 Smart-city initiative, that seeks to facilitate data re-use and\/or repurposed. We evaluate 7-DL through peer review and an exemplar worked example that applies the data lifecycle to a real-time life logging fire incident scenario, one of the Ideal-Cities use cases to demonstrate the applicability of the framework.<\/jats:p>","DOI":"10.3390\/fi14110315","type":"journal-article","created":{"date-parts":[[2022,10,31]],"date-time":"2022-10-31T23:26:32Z","timestamp":1667258792000},"page":"315","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["Privacy Goals for the Data Lifecycle"],"prefix":"10.3390","volume":"14","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0807-2661","authenticated-orcid":false,"given":"Jane","family":"Henriksen-Bulmer","sequence":"first","affiliation":[{"name":"Department of Computing and Informatics, Bournemouth University, Fern Barrow, Poole BH12 5BB, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4901-5954","authenticated-orcid":false,"given":"Cagatay","family":"Yucel","sequence":"additional","affiliation":[{"name":"Department of Computing and Informatics, Bournemouth University, Fern Barrow, Poole BH12 5BB, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2859-1143","authenticated-orcid":false,"given":"Shamal","family":"Faily","sequence":"additional","affiliation":[{"name":"Department of Computing and Informatics, Bournemouth University, Fern Barrow, Poole BH12 5BB, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8063-0827","authenticated-orcid":false,"given":"Ioannis","family":"Chalkias","sequence":"additional","affiliation":[{"name":"Department of Computing and Informatics, Bournemouth University, Fern Barrow, Poole BH12 5BB, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2022,10,31]]},"reference":[{"key":"ref_1","unstructured":"EEA (2022, September 25). Circular Economy in Europe: Developing the Knowledge Base. Available online: https:\/\/www.socialistsanddemocrats.eu\/sites\/default\/files\/Circular%20economy%20in%20Europe.pdf."},{"key":"ref_2","unstructured":"EEA (2022, September 25). Circular by Design: Products in the Circular Economy. Available online: https:\/\/circulareconomy.europa.eu\/platform\/sites\/default\/files\/circular_by_design_-_products_in_the_circular_economy.pdf."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Henriksen-Bulmer, J., Faily, S., and Katos, V. (2018, January 3\u20137). Translating Contextual Integrity into Practice using CLIFOD. Proceedings of the 2018 Networked Privacy Workshop at CSCW, Jersey City, NJ, USA.","DOI":"10.14236\/ewic\/HCI2017.95"},{"key":"ref_4","unstructured":"Kosta, E., Pierson, J., Slamanig, D., Fischer-H\u00fcbner, S., and Krenn, S. (2019). Implementing GDPR in the Charity Sector: A Case Study. Privacy and Identity Management. Fairness, Accountability, and Transparency in the Age of Big Data: 13th IFIP WG 9.2, 9.6\/11.7, 11.6\/SIG 9.2.2 International Summer School, Vienna, Austria, August 20\u201324, 2018, Revised Selected Papers, Springer International Publishing."},{"key":"ref_5","first-page":"1967","article-title":"Towards a modern approach to privacy-aware government data releases","volume":"30","author":"Altman","year":"2015","journal-title":"Berkeley Technol. Law J."},{"key":"ref_6","unstructured":"Oxford University Press (2022, September 25). Oxford English Dictionary. Available online: https:\/\/www.oed.com\/."},{"key":"ref_7","first-page":"1","article-title":"Understanding Data, Information, Knowledge And Their Inter-Relationships","volume":"7","author":"Liew","year":"2007","journal-title":"J. Knowl. Manag. Pract."},{"key":"ref_8","first-page":"49","article-title":"DIKIW: Data, Information, Knowledge, Intelligence, Wisdom and their Interrelationships","volume":"2","author":"Liew","year":"2013","journal-title":"Bus. Manag. Dyn."},{"key":"ref_9","first-page":"3","article-title":"From data to wisdom","volume":"16","author":"Ackoff","year":"1989","journal-title":"J. Appl. Syst. Anal."},{"key":"ref_10","first-page":"60","article-title":"Big data: The management revolution","volume":"90","author":"McAfee","year":"2012","journal-title":"Harv. Bus. Rev."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"565","DOI":"10.1016\/j.bushor.2014.06.001","article-title":"Business analytics: Why now and what next?","volume":"57","author":"Acito","year":"2014","journal-title":"Bus. Horizons"},{"key":"ref_12","first-page":"1","article-title":"Evaluating Privacy-Determining User Privacy Expectations on the Web","volume":"105","author":"Pilton","year":"2021","journal-title":"Comput. Secur. J."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3364223","article-title":"Confident privacy decision-making in IoT environments","volume":"27","author":"Lee","year":"2020","journal-title":"ACM Trans. -Comput.-Hum. Interact."},{"key":"ref_14","unstructured":"Solove, D.J. (2011). Nothing to Hide: The False Tradeoff between Privacy and Security, Yale University Press."},{"key":"ref_15","first-page":"1701","article-title":"Broken Promises of Privacy: Responding to the surprising failure of anonymization","volume":"57","author":"Ohm","year":"2010","journal-title":"UCLA Law Rev."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Yucel, C., Chalkias, I., Mallis, D., Cetinkaya, D., Henriksen-Bulmer, J., and Cooper, A. (2021, January 26\u201328). Data Sanitisation and Redaction for Cyber Threat Intelligence Sharing Platforms. Proceedings of the 2021 IEEE International Conference on Cyber Security and Resilience (CSR), Cyber Security and Resilience (CSR), Virtual.","DOI":"10.1109\/CSR51186.2021.9527916"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1186\/s12911-014-0123-5","article-title":"A RESTful interface to pseudonymization services in modern web applications","volume":"15","author":"Lablans","year":"2015","journal-title":"BMC Med. Inform. Decis. Mak."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"1010","DOI":"10.1109\/69.971193","article-title":"Protecting respondents\u2019 identities in microdata release","volume":"13","author":"Samarati","year":"2001","journal-title":"IEEE Trans. Knowl. Data Eng."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Cynthia, D., Nitin, K., and Deirdre, M. (2019). Differential Privacy in Practice: Expose your Epsilons!. J. Priv. Confidentiality, 9, Available online: https:\/\/journalprivacyconfidentiality.org\/index.php\/jpc\/article\/view\/689.","DOI":"10.29012\/jpc.689"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"122","DOI":"10.1023\/A:1011902718709","article-title":"Transforming the \u2019Weakest Link\u2019 a Human\/Computer Interaction Approach to Usable and Effective Security","volume":"19","author":"Sasse","year":"2001","journal-title":"BT Technol. J."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Faily, S. (2018). Designing Usable and Secure Software with IRIS and CAIRIS, Springer International Publishing. [1st ed.].","DOI":"10.1007\/978-3-319-75493-2"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"1003","DOI":"10.2307\/1120997","article-title":"Science, Privacy, and Freedom: Issues and Proposals for the 1970\u2019s. Part I\u2013The Current Impact of Surveillance on Privacy","volume":"66","author":"Westin","year":"1966","journal-title":"Columbia Law Rev."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Nissenbaum, H.F. (2010). Privacy in Context: Technology, Policy, and the Integrity of Social Life, Stanford Law Books.","DOI":"10.1515\/9780804772891"},{"key":"ref_24","unstructured":"(2009). British Standards Document BS ISO 31000:2009: Risk Management. Principles and Guidelines (Standard No. BS ISO 31000). Technical report."},{"key":"ref_25","unstructured":"(2020). BS ISO\/IEC29100: Information Technology-Security Techniques-Privacy Framework (Standard No. ISO\/IEC 29100). Technical report."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"421","DOI":"10.2307\/795891","article-title":"Privacy and the limits of the law","volume":"89","author":"Gavison","year":"1980","journal-title":"Yale Law J."},{"key":"ref_27","first-page":"3301","article-title":"Unintentional and Involuntary Personal Information Leakage on Facebook from User Interactions","volume":"10","author":"Lin","year":"2016","journal-title":"KSII Trans. Internet Inf. Syst."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"109","DOI":"10.1093\/ijlit\/eat001","article-title":"Online Data Processing Consent under EU Law: A Theoretical Framework and Empirical Evidence from the UK [article]","volume":"21","author":"Borghi","year":"2013","journal-title":"Int. J. Law Inf. Technol."},{"key":"ref_29","unstructured":"Ungoed-Thomas, J., Hookham, M., Belfield, R., and Ramzan, I. (2021). British Airways hack was \u2018a disaster waiting to happen\u2019. Times, Available online: https:\/\/sourceforge.net\/projects\/openccg\/."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1016\/0167-6423(93)90021-G","article-title":"Goal-directed requirements acquisition","volume":"20","author":"Dardenne","year":"1993","journal-title":"Sci. Comput. Program."},{"key":"ref_31","first-page":"49","article-title":"From System Goals to Intruder Anti-Goals: Attack Generation and Resolution for Security Requirements Engineering","volume":"3","author":"Lamsweerde","year":"2003","journal-title":"Proc. RHAS"},{"key":"ref_32","unstructured":"Howard, M., and Lipner, S. (2006). The Secuirty Development Lifecycle, Microsoft Press. Number 9780735622742."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1007\/s00766-010-0115-7","article-title":"A privacy threat analysis framework: Supporting the elicitation and fulfillment of privacy requirements","volume":"16","author":"Deng","year":"2011","journal-title":"Requir. Eng."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"122","DOI":"10.1016\/j.jss.2014.05.075","article-title":"Empirical evaluation of a privacy-focused threat modeling methodology","volume":"96","author":"Wuyts","year":"2014","journal-title":"J. Syst. Softw."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"56","DOI":"10.4018\/jsse.2010070104","article-title":"Towards tool-support for Usable Secure Requirements Engineering with CAIRIS","volume":"1","author":"Faily","year":"2010","journal-title":"Int. J. Secur. Softw. Eng."},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"140","DOI":"10.1108\/10662240610656483","article-title":"Incorporating privacy requirements into the system design process: The PriS conceptual framework","volume":"16","author":"Kavakli","year":"2006","journal-title":"Internet Res."},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"241","DOI":"10.1007\/s00766-008-0067-3","article-title":"Addressing privacy requirements in system design: The PriS method","volume":"13","author":"Kalloniatis","year":"2008","journal-title":"Requir. Eng."},{"key":"ref_38","unstructured":"European Commission (2022, September 25). Types of Legislation, Available online: https:\/\/www.legislation.gov.uk\/draft\/2022."},{"key":"#cr-split#-ref_39.1","unstructured":"European Parliament and the Council of Europe (2016). General Data Protection Regulation (GDPR), Regulation (EU) 2016\/679 5419\/1\/16"},{"key":"#cr-split#-ref_39.2","unstructured":"European Parliament and the Council of Europe (2016). General Data Protection Regulation (GDPR), Regulation"},{"key":"#cr-split#-ref_39.3","unstructured":"(EU) 2016\/679 5419\/1\/16; European Parliament and the Council of Europe."},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"99","DOI":"10.2307\/1884852","article-title":"A Behavioral Model of Rational Choice","volume":"69","author":"Simon","year":"1955","journal-title":"Q. J. Econ."},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"380","DOI":"10.1037\/h0053870","article-title":"The theory of decision making","volume":"51","author":"Edwards","year":"1954","journal-title":"Psychol. Bull."},{"key":"ref_42","first-page":"493","article-title":"Rational Decision Making in Business Organizations","volume":"69","author":"Simon","year":"1979","journal-title":"Am. Econ. Rev."},{"key":"ref_43","doi-asserted-by":"crossref","first-page":"51","DOI":"10.2307\/41165723","article-title":"Study of a Business Decision","volume":"9","author":"Fleming","year":"1966","journal-title":"Calif. Manag. Rev."},{"key":"ref_44","doi-asserted-by":"crossref","first-page":"59","DOI":"10.1111\/1467-9957.00089","article-title":"The essence of the modern corporation: Markets, strategic decision-making and the theory of the firm","volume":"66","author":"Cowling","year":"1998","journal-title":"Manch. Sch."},{"key":"ref_45","doi-asserted-by":"crossref","first-page":"462","DOI":"10.1108\/00251740010373476","article-title":"The essence of management decision","volume":"38","author":"Harrison","year":"2000","journal-title":"Manag. Decis."},{"key":"ref_46","first-page":"21","article-title":"Logic and risk as qualitative and quantitative dimensions of decision-making process","volume":"26","author":"Galanc","year":"2016","journal-title":"Oper. Res. Decis."},{"key":"ref_47","unstructured":"Yin, R.K. (2013). Case Study Research: Design and Methods, SAGE."},{"key":"ref_48","unstructured":"Pfitzmann, A., and Hansen, M. (2022, September 25). A terminology for talking about privacy by data minimization: Anonymity, Unlinkability, Undetectability, Unobservability, Pseudonymity, and Identity Management. Available online: https:\/\/dud.inf.tu-dresden.de\/literatur\/Anon_Terminology_v0.34.pdf."},{"key":"ref_49","doi-asserted-by":"crossref","first-page":"14","DOI":"10.1007\/978-3-642-31668-5_2","article-title":"Top 10 mistakes in system design from a privacy perspective and privacy protection goals","volume":"Volume 375","author":"Hansen","year":"2012","journal-title":"Privacy and Identity for Life"},{"key":"ref_50","doi-asserted-by":"crossref","unstructured":"Hansen, M., Jensen, M., and Rost, M. (2015, January 21\u201322). Protection Goals for Privacy Engineering. Proceedings of the 2015 IEEE Security and Privacy Workshops. Unabh\u00e4ngiges Landeszentrum f\u00fcr Datenschutz Schleswig-Holstein (ULD), San Jose, CA, USA.","DOI":"10.1109\/SPW.2015.13"},{"key":"ref_51","unstructured":"ENISA (2014). Privacy and Data Protection by Design Privacy and Data Protection by Design\u2014From Policy to Engineering, European Union Agency for Network and Information Security (ENISA). Technical Report."},{"key":"ref_52","unstructured":"(2017). British Standards Document BS ISO 27000:2017: Information Technology. Security Techniques. Information Security Management Systems. Overview and Vocabulary (Standard No. BS ISO 27000:2017). Technical Report."},{"key":"ref_53","unstructured":"Forth and NodalPoint and Bluesoft and Bournemouth University and Ecole des Ponts Business School and DGS. Ideal-Cities. 2022."},{"key":"ref_54","first-page":"1","article-title":"DPIA in Context: Applying DPIA to Assess Privacy Risks of Cyber Physical Systems","volume":"12","author":"Faily","year":"2020","journal-title":"Future Internet"},{"key":"ref_55","unstructured":"Bishop, M. (2002). Computer Security: Art and Science. [Electronic Resource], Addison-Wesley Professional."}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/14\/11\/315\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T01:06:50Z","timestamp":1760144810000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/14\/11\/315"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,10,31]]},"references-count":57,"journal-issue":{"issue":"11","published-online":{"date-parts":[[2022,11]]}},"alternative-id":["fi14110315"],"URL":"https:\/\/doi.org\/10.3390\/fi14110315","relation":{},"ISSN":["1999-5903"],"issn-type":[{"value":"1999-5903","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,10,31]]}}}