Privacy CURE: Consent Comprehension Made Easy

12Citations
Citations of this article
20Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Although the General Data Protection Regulation (GDPR) defines several potential legal bases for personal data processing, in many cases data controllers, even when they are located outside the European Union (EU), will need to obtain consent from EU citizens for the processing of their personal data. Unfortunately, existing approaches for obtaining consent, such as pages of text followed by an agreement/disagreement mechanism, are neither specific nor informed. In order to address this challenge, we introduce our Consent reqUest useR intErface (CURE) prototype, which is based on the GDPR requirements and the interpretation of those requirements by the Article 29 Working Party (i.e., the predecessor of the European Data Protection Board). The CURE prototype provides transparency regarding personal data processing, more control via a customization, and, based on the results of our usability evaluation, improves user comprehension with respect to what data subjects actually consent to. Although the CURE prototype is based on the GDPR requirements, it could potentially be used in other jurisdictions also.

Cite

CITATION STYLE

APA

Drozd, O., & Kirrane, S. (2020). Privacy CURE: Consent Comprehension Made Easy. In IFIP Advances in Information and Communication Technology (Vol. 580 IFIP, pp. 124–139). Springer Science and Business Media Deutschland GmbH. https://doi.org/10.1007/978-3-030-58201-2_9

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free