Risk Optimization Paper

 


A Pragmatic Approach to Privacy Risk Optimization-Privacy by Design for Business Practices, is a paper which introduces Nymity's Privacy Risk Optimization Process (PROP); a process that enables the implementation of privacy into operational policies and procedures, which embodies in Privacy by Design for business practices.

Download Risk Optimization Paper (registration required)

Background

In 2004, Nymity, a global privacy and data protection research firm, recognized that traditional approaches to implementing privacy often placed constraints on organizations’ business practices. Nymity initiated a research project with the objective of creating an approach to privacy compliance which would enable business to prosper while advancing privacy. Multiple approaches were developed and tested1 and ultimately, a process was developed which enabled organizations to effectively build privacy into their business practices.
 
Aware of how Nymity’s research helped organizations build privacy into business practices, Dr. Ann Cavoukian, the Information and Privacy Commissioner of Ontario, Canada, asked Nymity to make the process publicly available and to present it at the first, “Privacy by Design: The Definitive Workshop,” in Madrid, Spain, on November 2nd, 2009.

This jointly developed paper, Nymity and Dr. Ann Cavoukian, introduces Nymity’s Privacy Risk Optimization Process (PROP), a process that enables the implementation of privacy into operational policies and procedures, which results in Privacy by Design for business practices.


Table of Contents

Executive Summary. 4
Section 1: Prevailing Privacy Management Myths 7
“Privacy constrains business operations.” 7
“Privacy is nothing more than compliance.” 7
“Implementing privacy controls must be expensive.” 7
Section 2: Understanding the Components of the Privacy Risk Optimization Process (PROP) 8
Risk Optimization. 8
Business Activities 9
Privacy Risk. 10
Privacy Controls 12
Compliance. 13
Section 3: Application of the PbD Risk Optimization Methodology. 14
Step 1: Create a Project Plan. 15
Step 2: Create Risk and Positive Control Checklists 15
Step 3: Create a Risk Optimization Plan. 17
Step 4: Implement the Risk Optimization Plan. 18
Section 4: Dispelling the Myths 19
Appendix A: Nymity’s PbD Risk and Control Checklists 20
Appendix B: Privacy by Design Principles 21
Appendix C: Example of PROP Positive Privacy Controls 23
Appendix D: About the Authors 25

Privacy Statement · Legal notice