{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T16:13:06Z","timestamp":1781107986779,"version":"3.54.1"},"reference-count":50,"publisher":"IGI Global Scientific Publishing","issue":"1","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2019,1]]},"abstract":"<jats:p>The importance of data privacy, information availability and integrity are increasingly recognized. The new EU general data protection regulation 679\/2016 obligates stringent legal requirements with high sanctions for noncompliance. Most organizations worldwide are affected directly or indirectly. It requires overall a risk and evidence-based data privacy management as part of corporate governance. More than 1.6 million organizations worldwide are implementing a standard-based management system, such as ISO 9001 or others. To implement the new data protection regulation in an effective, efficient and sustainable way, the author provides design-oriented guidelines on how to integrate the legal requirements into standard based management systems. The holistic data privacy governance model integrates different information security governance frameworks with standard based management systems in order to comply the regulation. In that way data privacy is part of all strategic, tactical and operational business processes, promotes corporate governance, legal compliance and living data protection.<\/jats:p>","DOI":"10.4018\/ijitbag.2019010105","type":"journal-article","created":{"date-parts":[[2019,7,9]],"date-time":"2019-07-09T14:28:46Z","timestamp":1562682526000},"page":"74-93","source":"Crossref","is-referenced-by-count":0,"title":["A Data Privacy Governance Model"],"prefix":"10.4018","volume":"10","author":[{"given":"Margareth","family":"Stoll","sequence":"first","affiliation":[{"name":"Independent Researcher, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"IJITBAG.2019010105-0","author":"Y.Akao","year":"1990","journal-title":"Quality function deployment, integrating customer requirements into product design"},{"key":"IJITBAG.2019010105-1","doi-asserted-by":"publisher","DOI":"10.25300\/MISQ\/2017\/41.3.10"},{"key":"IJITBAG.2019010105-2","doi-asserted-by":"publisher","DOI":"10.2307\/41409971"},{"key":"IJITBAG.2019010105-3","doi-asserted-by":"publisher","DOI":"10.1057\/s41303-017-0059-9"},{"key":"IJITBAG.2019010105-4","doi-asserted-by":"publisher","DOI":"10.1080\/10580530701586136"},{"key":"IJITBAG.2019010105-5","author":"T. H.Davenport","year":"2005","journal-title":"Thinking for a living, how to get better performance and results from knowledge workers"},{"key":"IJITBAG.2019010105-6","doi-asserted-by":"publisher","DOI":"10.1145\/341852.341877"},{"key":"IJITBAG.2019010105-7","doi-asserted-by":"publisher","DOI":"10.1057\/ejis.2014.1"},{"key":"IJITBAG.2019010105-8","doi-asserted-by":"publisher","DOI":"10.1057\/ejis.2012.23"},{"key":"IJITBAG.2019010105-9","unstructured":"European Union Article 29 Data Protection Working [EU WP29]. (2017). Guidelines on Data Protection Impact Assessment (DPIA) and determining whether processing is \u201clikely to result in a high risk\u201d for the purposes of Regulation 2016\/679. Retrieved from http:\/\/ec.europa.eu\/newsroom\/article29\/item-detail.cfm?item_id=611236"},{"key":"#cr-split#-IJITBAG.2019010105-10.1","unstructured":"European Union [EU]. (2016). Regulation"},{"key":"#cr-split#-IJITBAG.2019010105-10.2","unstructured":"(EU) 2016\/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95\/46\/EC (General Data Protection Regulation). Retrieved from http:\/\/eur-lex.europa.eu\/legal-content\/DE\/TXT\/?uri=CELEX%3A32016R0679"},{"key":"IJITBAG.2019010105-11","unstructured":"Great Britain. Office of Government Commerce [OGC]. (2007). Service design (SD): ITIL. London: TSO The Stationery Office."},{"key":"IJITBAG.2019010105-12","unstructured":"Harvard Business Review Analytic Services. (2017). Digital Dilemma: Turning Data Security and Privacy Concerns Into Opportunities. Retrieved from https:\/\/hbr.org\/sponsored\/2017\/11\/digital-dilemma-turning-data-security-and-privacy-concerns-into-opportunities"},{"key":"IJITBAG.2019010105-13","doi-asserted-by":"publisher","DOI":"10.1080\/10580530903455247"},{"key":"IJITBAG.2019010105-14","unstructured":"International Standard Organization [ISO]. (2011). ISO\/IEC 27034-1:2011 Information technology -- Security techniques -- Application security -- Part 1: Overview and concepts. Geneva, Switzerland: ISO."},{"key":"IJITBAG.2019010105-15","unstructured":"International Standard Organization [ISO]. (2013). ISO\/IEC 27001:2013, Information Technology, Security techniques, Information security management systems requirements. Geneva, Switzerland: ISO."},{"key":"IJITBAG.2019010105-16","unstructured":"International Standard Organization [ISO]. (2013). ISO\/IEC 27002:2013, Information Technology, Security techniques, Code of practice for information security management. Geneva, Switzerland: ISO."},{"key":"IJITBAG.2019010105-17","unstructured":"International Standard Organization [ISO]. (2013). ISO\/IEC Directives, Part 1, Consolidated ISO Supplement, Procedures specific to ISO. Geneva, Switzerland: ISO."},{"key":"IJITBAG.2019010105-18","unstructured":"International Standard Organization [ISO]. (2015). ISO 9001:2015, Quality Management Systems \u2013 requirements. Geneva, Switzerland: ISO."},{"key":"IJITBAG.2019010105-19","unstructured":"International Standard Organization [ISO]. (2016). ISO\/IEC 27004:2016, Information technology, Security techniques, information security management measurement. Geneva, Switzerland: ISO."},{"key":"IJITBAG.2019010105-20","unstructured":"International Standard Organization [ISO]. (2017). ISO Survey of Survey of Management System Standard Certifications 2016. Retrieved from https:\/\/www.iso.org\/the-iso-survey.html"},{"key":"IJITBAG.2019010105-21","unstructured":"International Standard Organization [ISO]. (2017). ISO\/IEC 29134:2017, Information technology -- Security techniques -- Guidelines for privacy impact assessment. Geneva, Switzerland: ISO."},{"key":"IJITBAG.2019010105-22","unstructured":"International Standard Organization [ISO]. (2018). ISO 31000:2018, Risk management -- Guidelines. Geneva, Switzerland: ISO."},{"key":"IJITBAG.2019010105-23","year":"2006","journal-title":"Information security governance: Guidance for boards of directors and executive management."},{"key":"IJITBAG.2019010105-24","year":"2007","journal-title":"COBIT 4.1: Framework, control objectives, management guidelines, maturity models"},{"key":"IJITBAG.2019010105-25","author":"R. S.Kaplan","year":"1996","journal-title":"The balanced scorecard: Translating strategy into action"},{"key":"IJITBAG.2019010105-26","doi-asserted-by":"publisher","DOI":"10.25300\/MISQ\/2014\/38.2.06"},{"key":"IJITBAG.2019010105-27","doi-asserted-by":"publisher","DOI":"10.1509\/jm.15.0497"},{"key":"IJITBAG.2019010105-28","doi-asserted-by":"publisher","DOI":"10.25300\/MISQ\/2018\/13853"},{"key":"IJITBAG.2019010105-29","unstructured":"National Institute of Standards and Technology [NIST]. (2008). Performance Measurement Guide for Information Security, NIST Special Publication 800-55 Revision 1. Retrieved from http:\/\/csrc.nist.gov\/publications\/nistpubs\/800-55-Rev1\/SP800-55-rev1.pdf"},{"key":"IJITBAG.2019010105-30","unstructured":"Organization for Economic Co-operation and Development [OECD]. (2004). Principles of Corporate Governance. Retrieved from http:\/\/www.oecd.org\/dataoecd\/32\/18\/31557724.pdf"},{"key":"IJITBAG.2019010105-31","doi-asserted-by":"publisher","DOI":"10.2307\/41409969"},{"key":"IJITBAG.2019010105-32","unstructured":"Ponemon. (2017). 2017 Cost of Data Breach Study. Retrieved from https:\/\/www.ibm.com\/security\/infographics\/data-breach\/"},{"key":"IJITBAG.2019010105-33","doi-asserted-by":"publisher","DOI":"10.2307\/25750704"},{"key":"IJITBAG.2019010105-34","doi-asserted-by":"crossref","unstructured":"Reinmann-Rothmeier, G. (2002). Mediendidaktik und Wissensmanagement. MedienP\u00e4dagogik, 2(2), 1-27. Retrieved from www.medienpaed.com\/02-2\/reinmann1.pdf","DOI":"10.21240\/mpaed\/06\/2002.10.30.X"},{"key":"IJITBAG.2019010105-35","author":"M. J.Rosenberg","year":"2001","journal-title":"E-learning: Strategies for delivering knowledge in the digital age"},{"issue":"2","key":"IJITBAG.2019010105-36","first-page":"47","article-title":"Taking personal change seriously: The impact of Organizational Learning on management practice.","volume":"17","author":"P.Senge","year":"2003","journal-title":"The Academy of Management Executive"},{"key":"IJITBAG.2019010105-37","doi-asserted-by":"publisher","DOI":"10.1057\/ejis.2012.59"},{"key":"IJITBAG.2019010105-38","doi-asserted-by":"publisher","DOI":"10.2307\/41409970"},{"key":"IJITBAG.2019010105-39","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-09762-6_4"},{"key":"IJITBAG.2019010105-40","doi-asserted-by":"publisher","DOI":"10.2307\/25750689"},{"key":"IJITBAG.2019010105-41","unstructured":"Stoll, M. (2007). Managementsysteme und Prozessorientiertes Wissensmanagement. In N. Gronau (Ed.), Proc. 4th Conference on Professional Knowledge Management \u2013 Experiences and Visions: Vol. 1. (pp. 433-434). Berlin: Gito Verlag."},{"key":"IJITBAG.2019010105-42","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4020-8739-4_54"},{"key":"IJITBAG.2019010105-43","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4614-3535-8_20"},{"key":"IJITBAG.2019010105-44","doi-asserted-by":"publisher","DOI":"10.4018\/978-1-4666-0197-0.ch015"},{"key":"IJITBAG.2019010105-45","author":"H.Takeuchi","year":"2004","journal-title":"Hitotsubashi on knowledge management"},{"key":"IJITBAG.2019010105-46","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-79984-1"},{"key":"IJITBAG.2019010105-47","doi-asserted-by":"publisher","DOI":"10.1057\/ejis.2009.12"},{"key":"IJITBAG.2019010105-48","doi-asserted-by":"publisher","DOI":"10.25300\/MISQ\/2013\/37.1.01"}],"container-title":["International Journal of IT\/Business Alignment and Governance"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=233157","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,9,23]],"date-time":"2022-09-23T07:12:46Z","timestamp":1663917166000},"score":1,"resource":{"primary":{"URL":"http:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/IJITBAG.2019010105"}},"subtitle":["The Integration of the General Data Protection Regulation Into Standard Based Management Systems"],"short-title":[],"issued":{"date-parts":[[2019,1]]},"references-count":50,"journal-issue":{"issue":"1"},"URL":"https:\/\/doi.org\/10.4018\/ijitbag.2019010105","relation":{},"ISSN":["1947-9611","1947-962X"],"issn-type":[{"value":"1947-9611","type":"print"},{"value":"1947-962X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,1]]}}}