How to make privacy policies both GDPR-compliant and usable

Research output: Chapter in Book/Report/Conference proceedingConference contribution

5 Citations (Scopus)
188 Downloads (Pure)

Abstract

It is important for organisations to ensure that their privacy policies are General Data Protection Regulation (GDPR) compliant, and this has to be done by the May 2018 deadline. However, it is also important for these policies to be designed with the needs of the human recipient in mind. We carried out an investigation to find out how best to achieve this.
We commenced by synthesising the GDPR requirements into a checklist-type format. We then derived a list of usability design guidelines for privacy notifications from the research literature. We augmented the recommendations with other findings reported in the research literature, in order to confirm the guidelines. We conclude by providing a usable and GDPR-compliant privacy policy template for the benefit of policy writers.
Original languageEnglish
Title of host publication2018 International Conference on Cyber Situational Awareness, Data Analytics and Assessment (CyberSA)
PublisherIEEE
Number of pages8
DOIs
Publication statusPublished - 29 Nov 2018
EventCyber Science 2018: Security, Safety and Survivability in an era of constant, contemporary and complex Physical and Cyber Attacks - Grand Central Hotel, Glasgow, United Kingdom
Duration: 11 Jun 201812 Jun 2018

Conference

ConferenceCyber Science 2018
Abbreviated titleCyber SA
CountryUnited Kingdom
CityGlasgow
Period11/06/1812/06/18

Fingerprint Dive into the research topics of 'How to make privacy policies both GDPR-compliant and usable'. Together they form a unique fingerprint.

  • Cite this

    Renaud, K., & Shepherd, L. (2018). How to make privacy policies both GDPR-compliant and usable. In 2018 International Conference on Cyber Situational Awareness, Data Analytics and Assessment (CyberSA) IEEE . https://doi.org/10.1109/CyberSA.2018.8551442