System and procedure for developing adequate protection and risk management when handling personal data in predefined classes

The PKill Chain® framework provides a structured method for determining when to perform PIA, pseudonymization, and data protection by design and by default, addressing the challenges of vague criteria in current regulations and ensuring adequate protection of personal data rights and freedoms.

WO2025110871A1PCT designated stage Publication Date: 2025-05-30INTEGRA SOLUTION DOO
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
PCT/MK2024/000005
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-11-26
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

Current regulations for protecting personal data, such as GDPR, face challenges in determining the appropriate level of protection and when to perform Privacy Impact Assessments (PIAs), pseudonymization, and data protection by design and by default, due to vague criteria and potential over or under application of these measures.

Method used

The proposed system and method utilize the PKill Chain® framework to develop explicit criteria for when to perform PIA, pseudonymization, and data protection by design and by default, based on risk assessments of harmful activities within defined classes, ensuring adequate protection of personal data rights and freedoms.

Benefits of technology

This approach enables controllers and processors to make informed decisions about when to implement these protective measures, reducing the risk of privacy violations to an acceptable level, while avoiding unnecessary expenses and complexities associated with widespread implementation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IMGF000015_0001
    Figure IMGF000015_0001
  • Figure IMGF000016_0001
    Figure IMGF000016_0001
  • Figure IMGF000017_0001
    Figure IMGF000017_0001
Patent Text Reader

Abstract

The invention provides a system and computer implemented method for managing personal data protection and mitigating risks through predefined classes of harmful activities. It establishes criteria for Privacy Impact Assessments (PIA), pseudonymization, and privacy-by-design and by-default measures, enabling precise risk evaluation and mitigation. The process operates in iterative phases addressing misuse, identification, and root risks, with decisions based on context and processing of personal data. The system includes modules for data processing, risk assessment, and action proposals to ensure effective implementation of protective measures. If standard methods are insufficient, consultation with data protection authorities is included. This innovation streamlines compliance with privacy regulations, offering a clear, scalable, and efficient approach to safeguard data subjects' rights and freedoms.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] TITLE OF THE INVENTION:

[0002] SYSTEM AND PROCEDURE FOR DEVELOPING ADEQUATE PROTECTION AND RISK MANAGEMENT WHEN HANDLING PERSONAL DATA IN PREDEFINED CLASSES

[0003] Field of invention:

[0004] This invention is from the field of physics, specifically in the class of computer processing, i.e. calculation or counting in the subclass of electrical digital data processing in the group of security arrangements for data protection, more specifically it relates to the protection of data by defining of a method for adequate protection and mitigating the risk at an acceptable level that depends on defined rights and freedoms of the subject of personal data.

[0005] The technical problem that the Invention solves

[0006] The invention, covered in the subject specification, offers a solution to the problem that arises when dealing with personal data, more precisely, it provides a procedure for the specific determination of their exposure and suggests ways of acting in order to achieve an adequate level of anonymity to prevent the possibility of privacy violations of the subject.

[0007] At the same time, it reveals a procedure and system for adequate protection and risks mitigation to the privacy rights and freedoms of the Holders (Subjects) of personal data through the development and hierarchical application of criteria that determine when to perform a PIA (Privacy Impact Assessment), pseudonymization and protection of personal data by design and by default based on previously defined classes.

[0008] The invention discloses a method and system for:

[0009] - criteria for when to perform PIA, pseudonymization and protection of personal data by design and by default

[0010] - mastering the risks, based on the risk assessment of the classes of harmful activities of the PKill Chain™ chain

[0011] - adequate protection of the privacy rights and freedoms of the Subjects of personal data. Background of inventson / Prior state of art: in the currently developed regulation for the protection of the privacy of personal data, there is the problem of determining the degree of their exposure and the procedure for harmonizing their protection at an adequate level, three activities / exercises are usually required to be performed, namely: assessment of the impact of privacy (PIA or DPIA in GDPR), pseudonymization, as well ax privacy by design and by default. The problem arises from the vagueness of the criteria when they are mandatory or when they are required to be performed.

[0012] In the GDPR regulation, the decision when to carry out a DPIA is based on an assessment, which represents a high risk to the rights and freedoms of the subject of personal data and on a list. of explicit criteria when it should or should not be carried out, which is published by the respective Authorities for the protection of personal data.

[0013] "Prescribing a pre-defined list as a guideline criterion for risk assessment will lead controllers, dealing with them, to carry out DPIA when it is not necessary. In this case, the controller may overlook other cases of risk that are not covered by the list of criteria, that is, other processing that should be subject to DPIA," (Comments of the European Banking Federation on the Article 29 Data Protection Impact Assessment (DPIA) Working Party Guidelines - wp248)

[0014] The disadvantage of this kind of explicit definition is that such an enumeration may not cover some high risks for the rights and freedoms of the subjects of personal data, that is, there is no implicit definition or criteria when to perform this assessment. It is also not clear when the protection of personal data by design and by default should be enforced.

[0015] Although the decision about these controls should be based on risk analysis, it can be understood that generally by design and by default, controls should always be used as a matter of principle.

[0016] The disadvantage of this kind of general definition is that the generality may dictate that the protection of personal date by design and by implication always be carried out, and there is no implicit definition or criteria when it should be carried out.

[0017] On the other hand, pseudonymisation as a control is potentially needed to:

[0018] - protection of personal data by design and by default

[0019] - reliability of processing and legality, code of conduct and archiving. It is not clear when this control should be used, given that it cart be expensive, complicated and risky to implement, and furthermore represents a control that can limit development and innovation.

[0020] It is well known that modern privacy regulations are risk-based and the common view used on how to perform these tasks is based on paragraphs such as:

[0021] -Assessment of the impact on the protection of personal data: “...taking into account the nature, scope, context and purposes of the processing, it is likely to result in a high risk for the rights and freedoms of the subjects of personal data,..."

[0022] Or, security of processing is always required under the GDPR: “... taking into account the state of current, technology, the costs of implementation, then the nature, scope, context and purposes of the processing, as well as the risk of changing probability and severity according to the rights and the freedoms of natural persons..."

[0023] This shows that the common denominator for defining the purpose of these activities and controls is the rights and freedoms of rhe subjects of personal data, but these are basic human rights and too broad privacy principles to be broken down, and based on this to develop and propose controls / measures in order to reduce the risk.

[0024] This is the reason why the chain of privacy problems PKill Chain®( PKill Chain is a protected trademark of Integra Solutions dooel for EU territory, TM 018632764), based on Daniel Solove’s harmful activities, as a structure and taxonomy for privacy, is used to create a method for developing criteria, when to perform / implement a PIA, protection of personal data by design and by default, and pseudonymization.

[0025] PKill Cain®is based on the taxonomy of privacy defined by Daniel Solove (Solove, D. J, (2006). A taxonomy of privacy. University of Pennsylvania Law Review, 154(3), 477-560), which defines activities that can cause harm of the holder of personal data, according to Solove, divided into several categories, namely:

[0026] · Collection: Surveillance, interrogation

[0027] · Processing: Aggregation, Identification, Insecurity, Secondary Use, Exclusion

[0028] · Dissemination: Breach of Confidentiality, Disclosure, Exposure, Increased Availability, Blackmail, Appropriation, Distortion

[0029] · intrusion: Intrusion, Decisional Interference These privacy concerns are structured in the PKill Cain®model according to the scheme shown in Figure 9 a), where User Behavior Analysis and Profiling are added to the taxonomy by the inventor as more modern privacy concerns.

[0030] For PKill Cain®to work, an attacker needs to obtain some personal data from the Root class, identify the owner of the personal data, and abuse any of the privacy issues from the Abuse class. It can further escalate through any of the malicious activities whereby it can further escalate identification (FEID) or abuses (FEM). Which is appropriately illustrated in Figure 9 b).

[0031] In order to carry out the killing (elimination) of privacy, the attacker needs to carry out at least one harmful activity in the Root, Identifiability and Misusage, Privacy problems of the Further Escalation class are optional but should not be neglected in the analysis because they may escalate the PKill Chain®and thus realize the privacy kill / elimlnation.

[0032] Based on this, the PKill Chain®chain structure is used in the analysis of how to design a method for developing criteria for when and why DPIA, By design and by default and pseudonymization should be performed. This was done on the basis of the risk assessment methodology of the controller / processor to analyze, evaluate and determine the risk to the rights and freedoms of data subject rights and to design adequate protection through implementation of controls / measures that need to be implemented.

[0033] Using the PKill Chain®the risk to the rights and freedoms of personal data subjects through harmful activities is structured into classes and is derived from the components of impact / harm and probabi lity / likelihood as a basic predisposition to perform PIA, data protection by design and by default and risk assessment. The PKill Chain®process has been developed in order to propose a structure that leads to a method for preventing risks to the rights and freedoms of personal data subjects by preventing misuse of personal data by an attacker. Based on the PKill Chain®criteria are developed when to perform PIA, pseudonymization, data protection by design and by default and risk assessment and controls are proposed that will prevent the risks to the rights and freedoms of the subjects of personal data at an acceptable level, Solution of the technical problem

[0034] The procedure presented in this patent specification enables users, i,e. controllers / processors from industries, to use it to make a decision, based on the developed criteria, when to perform the exercises / measures: PIA, pseudonymization, data protection by design and by default, in order to overcome the risk to the rights and freedoms of the subjects of personal data based on the developed controls, while adequate protection will be achieved.

[0035] The procedure for developing criteria for when to perform PIA, pseudonymization, and data protection by design and by default is implicit.

[0036] The risks to the rights and freedoms of the subject of personal data are not performed at a level that could be analyzed through risk management methodologies, but with this innovation and using ths PKill Chain®they are broken down to a lower level, so it becomes dear what contributes to the impact / harm and probabiiity / 'likelihood components as risk is typically decomposed.

[0037] The improvement is that tasks such as PIA, pseudonymisation, and personas data protection are by design and by default expensive, complex, and risky to implement, and developing criteria for when to perform these tasks is critical. Criticality also comes f rom the perspective of regulatory policy and compliance, but the opportunity arising from controller / processor accountability, which is common to all modern privacyregulations, is to use this method in order to justify these decisions on methodological grounds. This will address improving how to prevent harms / impacts and risks to privacy rights and freedoms by developing controls, ie. adequate protection that would reduce the level of risks to an acceptable level for harmful activities within PKill Chain®classes.

[0038] As a result of the risk assessment, the procedure defines how to prevent the risk to the rights and freedoms of the personal data subject by developing criteria when to use PIA controls, pseudonymization, data protection by design and by default, as well as technical and organizational measures. These controls and measures are used for adequate protection, in proportion to the risk they are supposed to reduce in order to prevent the risk to the rights and freedoms of the subject of personal data throughout the structure of the PKill Chain™ process in response to adversary misuse.

[0039] Controllers / processors may use the harmful activity class, misuse, to decide whether a PIA is required. Additionally, they could decide when and what type of pseudonymization, i.e. for which personal data attributes or data subject identification should be used. Finally, they should use data protection by design and by default if the risk cannot be reduced to an acceptable level. They can manage identifiability in order to prevent adversary transitions from the Root class where the initial personal data is acquired to the Misuse class where the ultimate impact / damage is realized on a particular natural person. Taking into account the likely escalation of identifiability and Misuse by acquiring additional personal data, the processor / controller can prevent these events by managing the risk that harmful activities of the Further Escalation class are realized. They could use classical risk assessment to reduce the risk to an acceptable level in the context of malicious activities from the Root class, but also from other classes.

[0040] Brief description of the images: For an easier understanding of the subject of the invention, several graphic representations are provided with the following description:

[0041] Figure 1: Example of system infrastructure;

[0042] Figure 2; View of the entire system with its components and modules;

[0043] Figure 3: Detailed block diagram of the procedure with phases and steps; Figure 4: Table presentation of the course and possible outcomes of the phase of assessment of the risk of Misuse;

[0044] Figure 5: Table representation of the course and possible outcomes of the stage of risk assessment of identification;

[0045] Figure 6: Table presentation of the flow and possible outcomes of the root risk assessment phase; Figure 7: Table representation of the flow and possible outcomes of the results phase;

[0046] Figure 8 is a block diagram showing the process of selecting adequate protection.

[0047] Figure 9a and Figure 9b are an illustration of the structure and stages of the PKill Chain®to illustrate the state of the art,

[0048] Detailed description of the invention The aspects of the described system and the method for developing adequate protection and risk management through PIA performance criteria, pseudonymization, by design and by implication based on the risk assessment of harmful activities in PKill chain®classes are illustratively covered in Figure 1.

[0049] The method for developing adequate protection and risk management through PIA performance criteria, pseudonymization and by design by default based on the risk assessment of harmful activities in PKill chain®classes that are presented in this invention can be implemented in various computer systems, environments and configurations. Its application is described in the context of the system shown in Figure 1. The proposed system and method for developing criteria for when to perform PIA, pseudonymization and protection of personal data can be implemented on different computer systems, environments and / or configurations. An example of the system infrastructure is shown in Figure 1, The system shown in the Figure can be implemented in various computer systems, such as a laptop computer, a desktop computer, a mobile device, a workstation, a server, a network server, and the like (1.1). The system can also be implemented in a cloud-based environment. The system can be accessed by multiple users through one or more user devices (1.1). Examples of user devices (1.1) may be; laptop, personal digital assistant, workstation, and others. User devices (1.1) are connected to the system (1.3) via a network (1.2), in an implementation, the network (1.2) may be a wireless network, a wired network or a combination thereof, an intranet, a LAN, a WAN, the internet, and the like. A network may include various protocols, for example, HTTP, TCP / IP, WAP, and so on.

[0050] Also, the network (1.2) may include various network devices, such as routers, servers, computing devices, storage devices, and the like.

[0051] Referring to Figure 2, the order in which the method is described should not be limiting. Any modification of the method such as addition, subtraction or other change in the steps that will produce the same results, that is, there will be no deviation from the context, application and scope is within the scope of the method. Further, ths method may be implemented in any suitable hardware, software, or combination thereof. However, for ease of explanation, in the applications described below, the method may be considered to be implemented within the infrastructure and system of Figure 1.

[0052] Figure 2 is a view of the entire system with its components and modules. The memory (2.3) includes two components: modules (2.4) and data (2.5).

[0053] There are 4 modules (2.4) namely:

[0054] 2.4.1 Module for general processing;

[0055] 2.4.2 Modules for assessments of classes of harmful activities;

[0056] 2.4.3 Module for the protection method; 2.4.4 Proposed Activities Module;

[0057] The general processing module (2.4.1) contains the following operational modules:

[0058] 2.4.1.1 Data collection module;

[0059] 2.4.1.2 Data storage module; 2.4.1.3 Data processing module;

[0060] 2.4.1.4 Analysis module;

[0061] The module for assessments of classes of harmful activities (2.4.2) contains the following modules:

[0062] 2.4.2.1 Module for assessing the class of Misuse;

[0063] 2.4.2.2 Module for assessment of the class of Identifiability;

[0064] 2.4.2.3 Module for assessment of the class Further escalation;

[0065] 2.4.2.4 Module for assessment of the class Roor;

[0066] The protection method module 2.4.3 provides an assessment of the needs for the protection of personal data through the implementation of the modules for proposed activities. The modules for proposed activities are shown in order to indicate the utility value of the invention and they are not part of the initial idea of the solution itself.

[0067] The proposed activities module (2.4.4) consists of the following modules:

[0068] 2.4.4.1 Module for proposal for PIA, that is DPIA in GDPR;

[0069] 2.4.4.2 Module for pseudonymization of identifiers;

[0070] 2.4.4.3 Module for pseudonymization of attributes;

[0071] 2.4.4.4 Processing security module;

[0072] 2.4.4.5 Privacy by Design and Default Module.

[0073] The data component (2.5) includes:

[0074] 2.5.1 Personal data module;

[0075] 2.5.2 Processing Context Data Module.

[0076] The system implementation of Figure 1 may include at least one processor 2.1, input / output interface 2.2, memory 2.3. A processor may be implemented with one or more microprocessors, microcomputers, microcontrollers, central processing units, and / or any devices that process data based on operational instructions. One of the processor 2.1 retrieves and executes computer-readable instructions that are stored or are being stored in the memory 2.3. interface 2.2 allows the system to communicate with other computing devices, such as file structures, web services, APIs, and databases from which personal data information and processing context data are retrieved (as in Figure 2). The input / output interface 2.2 enables communications within multiple networks and protocols such as wired / wireless, cable, mobile or satellite networks, through one or more ports to connect the required number of devices from which personal data is read.

[0077] Any computer-readable media such as temporary memory, persistent memory, hard disks, dynamic memory, read-only memory, optical disks, programmable memory, flash memories, and magnetic tapes are examples of Memory 2.3. It. includes modules component 2.4 and data component 2.5.

[0078] 2.4 Modules can be implemented through programs, data structures, objects, components, etc, that perform certain tasks, functions or create certain data structures, in one implementation, modules 2.4,1 include the general modules namely 2.4.1.1 Data collection module;

[0079] 2.4.1.2 Data storage module; 2.4.13 Data processing module, 2,4.14 Data analysis module; then the Harmful Activity Class Assessment Module includes 2.4.2.1 Misuse Class Assessment Module, 2.4.2.2 identification Class Assessment Module, 2.4.2.3 Further Escalation Assessment Module and

[0080] 2.4.2.4 The root estimation module; 2.4.3 The module for the personal data protection method does not contain modules; and finally 2.4,4 the Proposed Actions Module which includes 2.4.4.1 the Privacy impact Assessment Module (PIA i.e. DPIA in GDPR), 2.4.4.2 the Identifier Pseudonymization Module, 2.4.4.3 the Attributes Pseudonymization Module,

[0081] 2.4.4.4 The Security Processing Module and 2.4.4.5 The Privacy by design and by default Module. The solution in question defines when and under what conditions the modules from group 2.4.4, which refers to proposed activities, are executed.

[0082] The data component 2.5 serves to store data either generated or received through one of the modules 2.4. These may include personal data 2.5,1 and processing context data 2.5.2.

[0083] The disclosed invention relates to a method for developing criteria when to perform PIA, pseudonymization and protection of personal data by design and by implication and prevention of risks to privacy rights and freedoms based on the PKill Chain®process.

[0084] Figure 3 represents a block diagram on which the steps for the implementation of the procedure are indicated Starting at this point, assuming that the PKill Chain®classes are clear, a method will be presented to develop criteria for when to perform a PIA, aliasing both by design and by default. The method consists of four stages as presented in the block diagram, namely:

[0085] 3.1 Misuse assessment phase where it is decided whether to perform PIA and attribute pseudonymization; 3.2 Phase of identification assessment where it is decided whether to perform pseudonymization of the identifiers;

[0086] 3.3 Root class assessment phase where it is decided whether to implement protection with controls by design and by default;

[0087] 3.4 Phase of results, where as a result of all previous phases and steps, the method will end with a satisfactory mitigation of the risks (END) or with Consultations with the competent authority for data protection if the risk is not mitigated in the block diagram, the meaning of dashed lines is conditional execution, that is, they are executed if some of the actions are not effective or AND.1 or AND.2 are 1 (True) which means that all input flags are 1 (True). So the sectors are conventionally divided inter.

[0088] Sector A) “Activities to be performed" on the right side of the diagram, and the same are not mandatory, while on the contrary all parts in

[0089] Sector B) "Phases and steps of the method" on the left side of the diagram are mandatory, that is, the method should be implemented by performing all of them in a certain sequence of phases and steps. All stages are further explained including tables describing the steps and possible outcomes.

[0090] Note: All input flags of AND.1 and AND.2 are set to 0 (False) and they can conditionally be set. to 1 (True) if the dashed lines are realized, ie. PIA and PsA (pseudo-anonymization of attributes) or PsID (pseudoanonymization of identifiers) are not effective. Only If it is by design and by default (byD&D) Is not effective, it will lead to consultation with the data protection authority. 3.1. Misuse risk assessment phase

[0091] Starting from the abuse class, the controller / processor should perform a Harmful Activity Risk Assessment (3.1.1), ie the Abuse Assessment block, based on the current risk assessment methodology it uses. This risk assessment. should be extended by performing an assessment of potential further escalation of harmful activities from the class of further escalation (3.1.2) and if an escalation of harmful activities from the class of abuse Is possible (3.1.3: Yes) the assessment of the class of abuse should be carried out again, more specifically it returns to (3.1.1).

[0092] If escalation Is no longer possible (3.1.3: No), then a risk acceptability decision (3.1.4) should be made based on the risk acceptance criteria defined by the current controller. If there is at least one harmful activity of the risk misuse class that is not acceptable (3.1.4: No), then a Privacy Impact Assessment (PIA)(3.1.5) should be performed.

[0093] Defining risk mitigation controls through the Privacy Impact Assessment (PSA) method will again lead to repeating steps (3.1.1, 3.1.2, 3.1.3...). If the risk for all harmful activities during misuse is acceptable (3.1.4: Yes), the method will lead to the identification assessment phase and its first step 3.2.1. Identification assessment.

[0094] A detailed table presentation of the process and possible results is given and presented In Figure 4.

[0095] Otherwise, the cycle of the first four steps (3.1.1, 3.1.2, 3.1.3, 3.1.4) could be repeated until it is determined that the privacy impact assessment (PIA) procedure is not effective (3.1 .5: No) and consequently to perform the activity 3,1.6 Pseudonymization of attributes. After implementing the Pseudonymization of Attributes control, a Re-Assessment (PR) will be performed by repeating steps 3,1.1 to 1.3.5 and it will be concluded whether the risk is acceptable. If the risk is not acceptable and the final conclusion is that the results of the privacy impact assessment (PIA) and Attribute aliasing (PsA) are not effective, ie. in the Misuse Class still have harmful activities whose risk is not acceptable (3.6: No), it will produce the value (the flag) to have a value of 1 (True) which indicates ineffectiveness (NO) and is passed in the AND connection.1 and AND.2. It continues to Phase 3,2 and its first step 3.2,1. Identification assessment.

[0096] Otherwise, flags AND.1 and AND.2 will remain with the initial values 0 (False) which will make the Pseudoanonymization of identifiers and by Design by Implicit unnecessary from the stages of Risk Assessment Identification and Root, i.e, in this case the risk of the class of harmful activities Abuse is overcome by the currently implemented and designed controls.

[0097] 3.2 Identification risk assessment phase In the identification assessment phase, the first step is (3.2.1) Identification assessment followed by 3.2.2 identification assessment with further escalation which is repeated if further identification escalation is possible (3.2.3: Yes).

[0098] After the completion of this cycle, the evaluation is carried out on whether the risk for the harmful activities of the identification class is acceptable; in case of answer Yes (3.2.4: Yes), then the method can continue in the phase 3.3.1. Estimation of the root.

[0099] Otherwise, if the risk is not acceptable, the method should proceed to AND.1 setting the input flag to 1 (True) from where depending on the method input flag the Abuse Assessment Phase will proceed with Pseudonymization of Identifiers (PsID) if the output flag is 1 (True) or stage 3.3.1 of the root evaluation stage if the output flag is 0 (False).

[0100] A detailed tabular representation of the process and possible results is given and presented in Figure 5.

[0101] If the output flag of AND.1 is 1 (True) aliasing of identifiers will be performed, and then the method will continue with Re-Evaluation ll.1 Identification Evaluation, This cycle of steps (3.2.1, 3.2.2, 3.2.3, 3.2.4, 3.2,3) is repeated until the Risk of identification assessment is not acceptable or conditionally, we conclude that. pseudonymbation of identifiers (PsID) is not effective which will set the input flag leading to AND.2 to 1 (True

[0102] ) and continue with Processing Security.

[0103] The effect of the above is that processing security or ths so-called implementation of technical and organizational measures cannot be skipped if it comes from ineffective Privacy Impact Assessment (PIA), Pseudonymization of Attributes (PsA) and Pseudonymization of identifiers (PsID), and it should be taken into account how to compensate for their ineffectiveness.

[0104] 3.3. Root risk assessment phase

[0105] At this stage, if the assessment of the risk of harmful activities of the Root class is carried out and if the determined risk is not acceptable, in that case the activity of processing security is carried out in order to reduce the risk of this class of harmful activities to an acceptable level. This cycle of steps 3.3.1 and 3.3.2 is repeated until the risk of harmful activities from the Root class is not overcome, or it is concluded that the security of the processing is ineffective in which case the procedure continues with data protection by design and by default. This means that Privacy impact Assessment (PIA), .Attribute Pseudonymization (PsA) and identifier Pseudonymization (PsID) are not effective and the controller should redesign the processing of personal data, because the risks of harmful activities from the PKill Chain classes) are not overcome or there is an unacceptable risk and harmful activities from the Chain (PKill Chain®. The protection process by design and by defauist is the most demanding and requires a complete rethinking of the processing of the processing of personal data that, should ultimately Include the concept, of sovereignty of personal data under the control of the subject of personal data.

[0106] A detailed tabular presentation of the process and possible results is given and presented in Figure 6.

[0107] Consequently, after the implementation of data protection by design and by default, it goes to the stage of assessing the harmful activities of the class of Misusage and step 3.1.1, This means that through the assessment of the class of abuse the method will be performed once again from the beginning and stages 3.1, 3.2, 3.3 will be repeated. If it is determined that data protection by design and by default Is not effective, then the Controller should proceed with the DPA consultation arid await their feedback.

[0108] 3,4. Results phase

[0109] Results phase 3.4. there are two results: either the risk is successfully mitigated by performing the previous stages and activities determined on the basis of the criteria determined by the method, or if data protection by design and by implication is ineffective, the competent Agency for Personal Data Protection is consulted.

[0110] Figure 8 is a block diagram showing the process of adequate protection. The steps in the process of adequate protection of personal data have the following meaning:

[0111] 8.1 The first step of the process is understanding and analyzing the context of personal data and their processing. At the same time, the context of personal data derives to the greatest extent from the class of Misuse and identification, and contributes to the greatest extent to the damage component in the risk to ths rights and freedoms of the holders of personal data. The context of how the data is processed derives from the classes of Further Escalation, Root and identification and contributes to the greatest extent to the probability component in the risk to the rights and freedoms of the holders of personal data:

[0112] 8.2 The second step consists of assessing the risk of harmful activities in the classes based on the previously analyzed context from step 8,1 and the risk analysis method used by the controller / processor;

[0113] 8.3 The third step is the method described in detail in the section Detailed description of the invention and the block diagram of Figure 3 which defines based on the criteria that. It sets which protective activities such as PIA, pseudonymization, by design and by implication are needed to overcome the risk by rights and the freedoms of the holders of personal data; 8.4 The fourth step is their actual performance, in which all risk assessments of harmful activities will be used in the classes that will produce protective controls to overcome the risk to the rights and freedoms of the holders of personal data;

[0114] 8.5 The fifth step is checking whether that protection is adequate, which is a set of checks in each phase of the method that mean the evaluation of the assessed risk against the acceptable risk and leads to the repetition of this in the process shown in Figure 4 if the protection is not adequate, that is, the risk is not mitigated;

[0115] 8.6 The sixth step occurs under the condition that there is a residual risk that is not acceptable and that does not provide adequate protection of the rights arid freedoms of the holders of personal data. In this case we say that this process is not effective and it. is necessary to consult the appropriate Authority for the protection of personal data

[0116] 8.7 The seventh step occurs if the protection is adequate, that is, by performing all the determined actions, the risk to the rights and freedoms of the holders of personal data is overcome.

[0117] Following this process and performing the method within the same controller supported by the results of the analyzes and based on the criteria decides on the PIA request, pseudonymization and by design and by default to he carried out when necessary and the protection of the rights and freedoms of the holders of personal data to be adequate, i.e. the risk is mitigated to an acceptable level

[0118] EXAMPLE OF APPLICATION OF THE INVENTION

[0119] For a detailed illustration of the procedure and sequence of the various actions to be performed depending on ths acceptability of the risk of harmful activities in the PKill Chain®classes.

[0120]

[0121] In the diagram view, further escalation should always be performed, in order to produce an Escalation of identification and Misuse to challenge the likelihood of escalation. This activity is again a type of risk assessment that will be performed on the class of harmful activities further escalation at any significant change during the design, implementation and operation.

[0122] Table 2: Sequence of steps depending on the acceptable level of risk within the classes of the PKill Chain®with a graphical display.

[0123] Legend: Is Effective Note: All other abbreviations apply from Table 1. All controls that will be designed when the final solution is reached should be documented in a Risk Treatment Plan based on the methodology used by the controller / processor and the resources dedicated to implementation and operation in order to demonstrate accountability.

[0124] White an adversary will attack from the Root class from left to right to the Misuse class, assessments and controls evolve from right to left in order to break the multi-point kill chain and develop a defense in depth from a privacy perspective. Through assessments such as PSA, risk assessment and data protection by design and by default, the controls to be designed and implemented are decided upon, with pseudonymisatio.n being one of them. But since these assessments, as well as pseudonymizations. are expensive, complex and risky, this method introduces criteria when they should be carried out in proportion to the appropriate level of risk they should reduce. if the Impact component is above the acceptable level represented by the Misuse and Identification classes, then PIA and pseudcmymization should be performed in order to reduce the impact on the rights and freedoms of the personal data subject, and if this is not possible, then through protection by design and by default and doing risk assessment mainly on the Root classes, Further escalation and to some extent Identification, which should reduce the level of probability of occurrence.

Claims

PATENT CLAIMS1. A system intended to implement a procedure for adequate protection of personal data, where the System (1.3) can include at least one processor, an input / output (I / O) interface, a memory in which modules are located, namely a module for general processing. Modules for evaluations on classes of harmful activities, module on the method of protection, Module on Proposed Activities; and ths data (2.8) is designated by including in the harmful activity class assessment module the following subordinate modules Misuse class assessment module, identification class assessment module, Further escalation assessment module and Root class assessment module;2. The system intended for adequate protection of personal data according to claim 1, is further characterized by the fact that the module for proposed activities includes the sub-modules privacy impact assessment (PIA i.e, DPIA in GDPR), for pseudonymization of identifiers, for pseudonymization of attributes, for processing security and for privacy by design and by default which are executed in accordance with the phases and need of a computer implemented procedure.

3. A computer-implemented procedure for adequate protection of personal data that contains the steps:(8.1) understanding and analysis of the context of personal data and their processing;(8.2) assessment of the risk of harmful activities in classes;(8.3) determinlrig the criteria that sets which protective actions are needed to overcome the risk to the rights and freedoms of the holders of personal data;(8.4) actual performance of appropriate measures based on risk assessments of harmful activities in the classes that will produce protective controls;(8.5) checking whether the protection is adequate; as well as(8.6) checking the impact on the rights and freedoms of the holders of personal data; and(8.7) an appropriate outcome at the end or additional consultation is characterized by the fact that risk management when dealing with collections of personal data consists of four phases: Misuse assessment phase, where it is decided whether to perform PIA sod attribute pseudonymization, identification assessment phase, where it is decided whether to perform pseudonymization of identifiers, root class evaluation phase, where it is decided whether to performprotection with controls by design and by default, results phase, where as a result, a satisfactory level of risk management is determined from all previous phases.

4. The computer-implemented method according to patent claim 3 is distinguished by that the stage of abuse assessment, based on the current risk assessment methodology it uses, is extended by making an assessment of a potential further escalation of harmful activities, from the class of further escalation, so if escalation is possible the harmful activities of the class of Misuse a re-assessment of the Misuse class is carried out, in cases where there is at least one harmful activity of the abuse class, with a risk that is not acceptable, then a privacy impact assessment (PIA) is carried out and the steps are repeated until the risk for all harmful activities during abuse is not acceptable, the procedure will lead to the next phase of identification assessment.

5. The computer- implemented method according to claim 3 and 4, is characterized by the fact that in the first stage of misuse assessment the cycle of the first steps (3.1.1, 3.1.2, 3.1.3, 3.1.4) is repeated until it is determined that the procedure for the privacy impact assessment (PIA) it is ineffective to perform the activity 3.1.6 pseudonymization of the attributes, and after the implementation of the control pseudonymization of the attributes, a re-assessment will be carried out by repeating the steps from 3.1.1 to 1.3.3 and it will be concluded whether ths risk is acceptable and after receiving a positive assessment, it will continue to the identification assessment phase.

6. The computer- implemented method according to patent claim 3, is characterized in that the identihcation assessment phase consists of a first identification assessment step (3.2.1), followed by an identification assessment with further escalation (3.2.2), which is repeated , if further escalation of the identification is possible (3.2.3;yes), and after the end of this cycle, the evaluation is carried out as to whether the risk for the harmful activities of the identification class is acceptable, whereby in case of a positive answer (3.2.4: Yes), the procedure goes to the next stage 3.3.1, otherwise, if the risk is not acceptable, the method should continue to AND.1 setting the input flag to 1 (True) e where depending on the input flag from the method the Abuse Assessment Phase will proceed with pseudonymization of the identifiers (PsID) and then the procedure will proceed with re-evaluation of the identification whereby the steps (3.2.1, 3.2.2, 3.2.3 , 3.2.4, 3.2.5) are repeated until the identification assessment risk is acceptable.

7. The computer-implemented method according to claim 3 and 4, is characterized by that in the phase of identification assessment, the security of the processing, i.e. the implementation of technical and organizational measures, cannot be skipped if it comes from an ineffective privacy impact assessment(PIA). pseudonymization of attributes (PsA) and pseudonymizstion of identifiers (PsID), taking into account to compensate their ineffectiveness.

8. The computer-implemented method according to patent ciaim 3, is characterized by that in ths phase of assessment of ths root class in the case of a determined risk that is not acceptable, the activity for processing security is carried out. whereby the cycle of steps 3,3.1 and 3,3.2 is repeated every until the risk of harmful activities from the root class is overcome.

9. The computer-implemented method according to patent claims 3 and 8. is characterized by the fact that if in the root class assessment phase it is concluded that processing security is ineffective, ths procedure continues with data protection by design and by default, after which the procedure returns to the phase of assessment of harmful activities of the class of Misuse and the method will be executed once again from the beginning and the abuse assessment, identification assessment, root class assessment phases will be repeated.

10. The computer-implemented method according to patent claim 3 is characterized by the fact that the results phase as an outcome has two results: the risk is successfully overcome by performing the previous phases and activities or a recommendation for consultation with the competent Personal Data Protection Agency,

Citation Information

Cited By

  • Data privacy protection method and device, storage medium and computer equipment

    CN121859353A

  • Data privacy protection method and device, storage medium and computer device

    CN121859353B