<?xml version="1.0" encoding="UTF-8"?>
<TEI xml:space="preserve" xmlns="http://www.tei-c.org/ns/1.0" 
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" 
xsi:schemaLocation="http://www.tei-c.org/ns/1.0 https://raw.githubusercontent.com/kermitt2/grobid/master/grobid-home/schemas/xsd/Grobid.xsd"
 xmlns:xlink="http://www.w3.org/1999/xlink">
	<teiHeader xml:lang="en">
		<fileDesc>
			<titleStmt>
				<title level="a" type="main">Crafting Privacy: Two Case Studies Integrating Cross-Disciplinary Perspectives on Privacy in Design</title>
			</titleStmt>
			<publicationStmt>
				<publisher/>
				<availability status="unknown"><licence/></availability>
			</publicationStmt>
			<sourceDesc>
				<biblStruct>
					<analytic>
						<author role="corresp">
							<persName><forename type="first">Maaike</forename><surname>Harbers</surname></persName>
							<email>m.harbers@hr.nl</email>
							<affiliation key="aff0">
								<orgName type="institution">Rotterdam University of Applied Sciences</orgName>
								<address>
									<settlement>Rotterdam</settlement>
									<country key="NL">The Netherlands</country>
								</address>
							</affiliation>
						</author>
						<author>
							<persName><forename type="first">Mortaza</forename><forename type="middle">S</forename><surname>Bargh</surname></persName>
							<affiliation key="aff0">
								<orgName type="institution">Rotterdam University of Applied Sciences</orgName>
								<address>
									<settlement>Rotterdam</settlement>
									<country key="NL">The Netherlands</country>
								</address>
							</affiliation>
							<affiliation key="aff1">
								<orgName type="department">Ministry of Justice and Security</orgName>
								<orgName type="institution">The Hague</orgName>
								<address>
									<country key="NL">The Netherlands</country>
								</address>
							</affiliation>
						</author>
						<author>
							<persName><forename type="first">Florian</forename><surname>Cramer</surname></persName>
							<affiliation key="aff0">
								<orgName type="institution">Rotterdam University of Applied Sciences</orgName>
								<address>
									<settlement>Rotterdam</settlement>
									<country key="NL">The Netherlands</country>
								</address>
							</affiliation>
						</author>
						<author>
							<persName><forename type="first">Sunil</forename><surname>Choenni</surname></persName>
							<affiliation key="aff0">
								<orgName type="institution">Rotterdam University of Applied Sciences</orgName>
								<address>
									<settlement>Rotterdam</settlement>
									<country key="NL">The Netherlands</country>
								</address>
							</affiliation>
							<affiliation key="aff1">
								<orgName type="department">Ministry of Justice and Security</orgName>
								<orgName type="institution">The Hague</orgName>
								<address>
									<country key="NL">The Netherlands</country>
								</address>
							</affiliation>
						</author>
						<author>
							<persName><forename type="first">Jeannette</forename><surname>Nijkamp</surname></persName>
							<affiliation key="aff0">
								<orgName type="institution">Rotterdam University of Applied Sciences</orgName>
								<address>
									<settlement>Rotterdam</settlement>
									<country key="NL">The Netherlands</country>
								</address>
							</affiliation>
						</author>
						<author>
							<persName><forename type="first">Anne</forename><surname>Nigten</surname></persName>
							<affiliation key="aff2">
								<orgName type="institution">The Patching Zone</orgName>
								<address>
									<settlement>Rotterdam</settlement>
									<country key="NL">The Netherlands</country>
								</address>
							</affiliation>
						</author>
						<title level="a" type="main">Crafting Privacy: Two Case Studies Integrating Cross-Disciplinary Perspectives on Privacy in Design</title>
					</analytic>
					<monogr>
						<imprint>
							<date/>
						</imprint>
					</monogr>
					<idno type="MD5">57FF0082B14B4E0377B27DC23E511144</idno>
				</biblStruct>
			</sourceDesc>
		</fileDesc>
		<encodingDesc>
			<appInfo>
				<application version="0.7.2" ident="GROBID" when="2023-03-24T19:05+0000">
					<desc>GROBID - A machine learning software for extracting information from scholarly documents</desc>
					<ref target="https://github.com/kermitt2/grobid"/>
				</application>
			</appInfo>
		</encodingDesc>
		<profileDesc>
			<textClass>
				<keywords>
					<term>Privacy by design</term>
					<term>cross-disciplinary</term>
					<term>information technology</term>
					<term>human computer interaction</term>
					<term>IT</term>
					<term>HCI</term>
				</keywords>
			</textClass>
			<abstract>
<div xmlns="http://www.tei-c.org/ns/1.0"><p>Privacy by design is a widely acknowledged necessity, yet its practice is still in its infancy. Many scholars have argued that privacy by design requires a cross-disciplinary approach in which privacy perspectives from different disciplines need to be integrated from the beginning of the design process. This paper investigates the potentials and shortcomings of a workshop format, used in the early stages of a (re)design process, to integrate viewpoints of multiple stakeholders from different disciplines. The workshop is used in two cases involving privacy issues, in the healthcare and in the insurance domain. The results show that different stakeholders, representing social, technological, ethical, legal, domain and user perspectives, identified different problems. Together, they thus provided a more complete view on the issues at stake, forming a better starting point to account for privacy in the design process. Based on the results, the paper suggests a number of research directions for combining diverse views from multiple stakeholders.</p></div>
			</abstract>
		</profileDesc>
	</teiHeader>
	<text xml:lang="en">
		<body>
<div xmlns="http://www.tei-c.org/ns/1.0"><head n="1">Introduction</head><p>The ubiquitous presence of technology creates ever more urgency to account for privacy issues <ref type="bibr" target="#b12">[13]</ref>. Considering and accounting for privacy during the design of information systems is often referred to as 'privacy by design' <ref type="bibr" target="#b0">[1,</ref><ref type="bibr" target="#b9">10,</ref><ref type="bibr" target="#b11">12,</ref><ref type="bibr" target="#b15">16]</ref>. Privacy by design has become particularly prominent due to the European Union's General Data Protection Regulation (GDPR), that has gone into effect in May 2018, which requires meeting the principles of privacy by design when processing personal data <ref type="bibr" target="#b5">[6]</ref>.</p><p>One of the best-known works on privacy by design is by Cavoukian <ref type="bibr" target="#b0">[1]</ref>, introducing seven design principles to enable individuals to gain personal control over their information and to enable organizations to gain a sustainable competitive advantage. Cavoukian's principles are high-level guidelines that still need to be translated to actual system designs and engineering practices <ref type="bibr" target="#b7">[8]</ref>. Currently, there exist no well-established approaches for translating the high-level privacy by design principles to practice <ref type="bibr" target="#b7">[8,</ref><ref type="bibr" target="#b18">19,</ref><ref type="bibr" target="#b22">23]</ref>.</p><p>One of the major challenges in applying privacy by design is that it requires the integration of perspectives from multiple stakeholders (user, designer, developer, etc.) and disciplines (HCI, software engineering, law, etc.) <ref type="bibr" target="#b3">[4,</ref><ref type="bibr" target="#b4">5,</ref><ref type="bibr" target="#b7">8,</ref><ref type="bibr" target="#b14">15]</ref>. In the area of requirement engineering, a number of methods have been proposed that integrate multiple perspectives to elicit privacy-related system requirements, e.g. by using multiple information sources <ref type="bibr" target="#b14">[15]</ref>, questionnaires and scenarios <ref type="bibr" target="#b6">[7]</ref>, and workshops with multiple stakeholders <ref type="bibr" target="#b1">[2,</ref><ref type="bibr" target="#b2">3,</ref><ref type="bibr" target="#b4">5,</ref><ref type="bibr" target="#b16">17]</ref>.</p><p>Although the above works aim at taking into account multiple perspectives in eliciting privacy requirements, they do not elaborate upon how well the applied methods integrate these perspectives in practice. In this paper, we therefore investigate the potentials and shortcomings of using a workshop with multiple stakeholders as a method to surface privacy-related problems from multiple perspectives, by applying it to two design cases.</p></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head n="2">Case studies</head><p>The workshop we use is suitable for the initial phase of a systematic privacy by design approach, aiming to identify privacy issues and trade-offs from multiple perspectives related to the (re-)design of an information system. A diverse participant group is key to the approach, as the participants represent multiple perspectives on privacy. The workshop centers around a timeline, which serves as a boundary object to bridge the participants' domains of expertise <ref type="bibr" target="#b20">[21,</ref><ref type="bibr" target="#b21">22]</ref>. This timeline is used to capture the flow of data in the system to be (re-)designed. The use of a timeline with data is inspired by mappings as known from IT and HCI/UX, such as a customer journey map <ref type="bibr" target="#b10">[11,</ref><ref type="bibr" target="#b13">14]</ref>, threat modelling <ref type="bibr" target="#b17">[18]</ref>, and a typical data lifecycle (e.g., as considered by various spheres in <ref type="bibr" target="#b19">[20]</ref>).</p><p>To gain practical experience with the workshop format, we organized two sessions with 6 stakeholders: a problem owner (domain expert), an end-user, and four privacy experts with a social, ethical, technical and legal perspective, respectively. The workshops were led by a moderator (a designer). The roles of moderator and privacy experts were fulfilled by researchers at Rotterdam University of Applied Sciences (RUAS), and those of problem owner and end-user by people outside of RUAS, associated to the respective domains. In an iterative design fashion, the results of the first session were used to inform the second.</p></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head n="2.1">Case 1: The OT black box</head><p>The first case deals with the design of recording surgeries in the Operation Theater (OT) in a so-called OT Black Box. Data stored in this OT Black Box contain video and audio recordings of the OT, featuring the patient and the OT team, typically consisting of surgeons, anesthesiologists, nurse anesthetists and OT nurses. These recordings are later used by the OT-team to analyze and evaluate their performance, and by a quality and safety manager to detect potential safety issues and improve the OT procedure if possible. After two days, the recordings are anonymized (patient and OT-team are no longer identifiable) and used for medical training purposes. Recordings are then no longer available for the patient who underwent the surgery. Before the workshop, the moderator and problem owner prepared a timeline consisting of five steps (see Figure <ref type="figure" target="#fig_0">1</ref>). For each step, a large (A0-sized) paper was put on the wall, on which the other workshop participants could write and add sticky notes. Each participant was provided with markers and sticky notes of a unique color, so that the contributions on the poster could be traced back to the different perspectives.</p><p>The four-hour workshop session consisted of five activities. First, the design case was introduced by the problem owner, explaining what happens in each timeline step. Second, data assets per timeline step were identified by the workshop participants (first individually, then in a group discussion), and added to the posters. Third, privacy violation risks per timeline step were identified (first individually, then in a group discussion), and added to the posters. Fourth, opportunities and risks of the information system as a whole were determined and trade-offs were identified (in a group discussion). Fifth, the workshop participants agreed on a set of design constraints, based on the identified trade-offs (in a group discussion).</p><p>Figure <ref type="figure" target="#fig_0">1</ref> shows some of the 'data' and 'privacy risks' that were identified per timeline step. The overview is not exhaustive but intends to provide a gist of the contributions from different participants. The results show that they bring in different perspectives. For instance, the social privacy expert mentions that the patient's dignity may be at stake, whereas the legal privacy expert points at the application of a privacy impact assessment. After identifying privacy risks, participants agreed that the most important trade-off was improved healthcare versus deteriorated privacy, i.e., recordings by the OT Black Box can enhance the quality of healthcare, but they introduce privacy violation risks for both the patient and the OT team. There was little time left to perform the last activity, identifying design constraints. Participants stressed that data should only be used for the purpose they were collected for.</p></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head n="2.2">Case 2: WhatsApp damage claims</head><p>The second design case involves the use of the mobile application WhatsApp for damage claims to an insurance company. The insurance company offers its customers the possibility to send text and pictures of car damage (including pictures of the location) via WhatsApp, when claiming the damage to the insurance company. These messages and pictures are encrypted by WhatsApp.</p><p>Although detailing the 'data' of all timeline steps in the first workshop brought forward deeply engaged participants, it also led to discussions in which domain-specific details were explored by non-experts. Moreover, it led to time shortage later on in the session. We therefore asked the problem owner in the second workshop to detail the data in each timeline step beforehand (Figure <ref type="figure" target="#fig_1">2</ref>, 3rd column). The other workshop activities remained the same.</p><p>Figure <ref type="figure" target="#fig_1">2</ref> shows the results of the second workshop session. Again, these results are not exhaustive, yet indicative. Similar to case 1, privacy issues related to ownership, faulty data and function creeps were identified. In the discussions, a lot of attention was paid to the trustworthiness of the photos sent for a damage claim via WhatsApp, as they could easily be manipulated or uploaded from the internet. Thanks to the new setup of the workshop, it was possible to complete all workshop activities this time.</p><p>Participants identified a trade-off between ease of use and privacy. Using WhatsApp for reporting damage increases ease of use for customers but introduces privacy risks due to relying on a 3rd party service provider. Other trade-offs identified were knowledge versus privacy (collecting and storing information increases insurers' knowledge, but introduces privacy risks), costs versus privacy (building an in-house application protects customers' privacy, but increases costs), ease of use versus security (as the ease of using WhatsApp creates security risks due to relying on a 3rd party service provider).</p><p>The workshop participants identified the following design constraints and recommendations: 1) insurance companies should develop their own application rather than relying on 3rd parties such as WhatsApp, this should be done according to privacy by design principles, 2) customers should always be able to choose whether they want to make use of WhatsApp, 3) customers should be informed about their options and the implications of their choices, 4) as least data as possible should be collected, data should not be collected if they will not be used, 5) customers should be able to access their personal data stored by the insurance company, and 6) authorization of data access should be implemented carefully in the insurance company in order to avoid function creeps.</p></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head n="3">Discussion and conclusion</head><p>In both design sessions, stakeholders from different disciplines identified different (privacy) problems and high-level requirements. For instance, the technical expert focused on issues related to the processing of data, such as data leaks and de-anonymization of data, whereas the social expert brought up the issue of human dignity and the legal expert identified issues related to authorization of access. The number of identified issues of all stakeholders was larger than any of the individual stakeholders' contributions. Having multiple perspectives represented thus provided a richer view on the design case at hand. Besides helping the privacy by design of IT systems, the workshops were increasing awareness about privacy and its complexity among the participants, i.e., they learned from each other and gained more insight in the complexity of privacy by design.</p><p>A number of issues should be considered when combining perspectives of multiple stakeholders in a workshop in general, and in this workshop in particular. First, in a multiple stakeholder workshop, there is a risk that some perspectives are more dominant in the discussion than others. This could be countered by stricter time management by the moderator, making sure that all participants receive an equal amount of speaking time. Second, different perspectives, objectives and/or identified risks may not be of equal importance. In future work, guiding principles for weighing different perspectives should be developed. Third, the boundary object of a multi-stakeholder workshop, in our case the timeline, steers the discussion in the workshop. In future research, developing guidelines for preparing the timeline could help avoiding too directive descriptions. Fourth, in our workshops, a number of well-known tradeoffs did not surface (e.g., data-subject/user control versus central/system control, prevention versus mitigation, and technical versus procedural). This could be explained by a lack of expertise of the participants. Yet, the likelihood of overseeing important trade-offs can be lowered by providing more structure for discussing design trade-offs and providing design recommendations, for example by systematically holding design tradeoffs along various dimensions (e.g., data usage vs data privacy, data-subject control vs central control, prevention vs mitigation, and technical vs procedural).</p><p>In future work, we will take up the issues mentioned in this discussion and work on the subsequent steps of a privacy by (re)design approach. We foresee the need of developing a method that systematically translates the current workshop outcomes (i.e., design recommendations and constraints) into software requirements, e.g. by using bridging concepts such as value stories <ref type="bibr" target="#b8">[9]</ref>, turning privacy by design into privacy engineering. For giving more structure to the design thinking process, we foresee organizing the design discussions along three directions of security related aspects, usersbeing-in-control related aspects and data-minimalization related aspects. The outcome of these sessions should deliver a number of promising design options, which can be prototyped and improved in a number of iterations.</p></div><figure xmlns="http://www.tei-c.org/ns/1.0" xml:id="fig_0"><head>Fig. 1 .</head><label>1</label><figDesc>Fig. 1. Data and privacy risks identified by workshop participants for case 1 (OT Black Box).</figDesc><graphic coords="3,46.45,448.20,503.95,198.30" type="bitmap" /></figure>
<figure xmlns="http://www.tei-c.org/ns/1.0" xml:id="fig_1"><head>Fig. 2 .</head><label>2</label><figDesc>Fig. 2. Data and privacy risks identified by workshop participants for case 2 (WhatsApp for damage claims).</figDesc><graphic coords="4,47.80,510.55,503.40,155.50" type="bitmap" /></figure>
		</body>
		<back>

			<div type="acknowledgement">
<div xmlns="http://www.tei-c.org/ns/1.0"><head>Acknowledgements</head><p>The authors thank all the workshop participants for sharing their expertise and for their valuable contributions.</p></div>
			</div>

			<div type="references">

				<listBibl>

<biblStruct xml:id="b0">
	<monogr>
		<author>
			<persName><forename type="first">A</forename><surname>Cavoukian</surname></persName>
		</author>
		<ptr target="http://www.Priva-cybydesign.Ca/index.Php/about-pbd/7-foundamental-principles" />
		<title level="m">Foundational Principles-Privacy by design</title>
				<imprint>
			<date type="published" when="2009">2009</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b1">
	<analytic>
		<title level="a" type="main">Public safety mashups to support policy makers</title>
		<author>
			<persName><forename type="first">S</forename><surname>Choenni</surname></persName>
		</author>
		<author>
			<persName><forename type="first">E</forename><surname>Leertouwer</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">Proceedings of Int. Conf. on Electronic Government and the Information Systems Perspective (EGOVIS)</title>
				<meeting>Int. Conf. on Electronic Government and the Information Systems Perspective (EGOVIS)<address><addrLine>Germany</addrLine></address></meeting>
		<imprint>
			<publisher>Springer-Verlag</publisher>
			<date type="published" when="2010">2010</date>
			<biblScope unit="page" from="234" to="248" />
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b2">
	<analytic>
		<title level="a" type="main">Preserving privacy whilst integrating data: applied to criminal justice. Information Polity</title>
		<author>
			<persName><forename type="first">S</forename><surname>Choenni</surname></persName>
		</author>
		<author>
			<persName><forename type="first">J</forename><surname>Van Dijk</surname></persName>
		</author>
		<author>
			<persName><forename type="first">F</forename><surname>Leeuw</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="j">Int. J. of Government &amp; Democracy in the Information Age</title>
		<imprint>
			<biblScope unit="volume">15</biblScope>
			<biblScope unit="issue">1-2</biblScope>
			<biblScope unit="page" from="125" to="138" />
			<date type="published" when="2010">2010</date>
			<publisher>IOS Press</publisher>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b3">
	<monogr>
		<title level="m" type="main">Privacy and Data Protection by Design-from policy to engineering</title>
		<author>
			<persName><forename type="first">G</forename><surname>Danezis</surname></persName>
		</author>
		<author>
			<persName><forename type="first">J</forename><surname>Domingo-Ferrer</surname></persName>
		</author>
		<author>
			<persName><forename type="first">M</forename><surname>Hansen</surname></persName>
		</author>
		<author>
			<persName><forename type="first">J</forename><forename type="middle">H</forename><surname>Hoepman</surname></persName>
		</author>
		<author>
			<persName><forename type="first">D</forename><forename type="middle">L</forename><surname>Metayer</surname></persName>
		</author>
		<author>
			<persName><forename type="first">R</forename><surname>Tirtea</surname></persName>
		</author>
		<author>
			<persName><forename type="first">S</forename><surname>Schiffner</surname></persName>
		</author>
		<imprint>
			<date type="published" when="2015">2015</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b4">
	<analytic>
		<title level="a" type="main">Privacy by Socio-Technical Design: A Collaborative Approach for Privacy Friendly System Design</title>
		<author>
			<persName><forename type="first">M</forename><surname>Degeling</surname></persName>
		</author>
		<author>
			<persName><forename type="first">C</forename><surname>Lentzsch</surname></persName>
		</author>
		<author>
			<persName><forename type="first">A</forename><surname>Nolte</surname></persName>
		</author>
		<author>
			<persName><forename type="first">T</forename><surname>Herrmann</surname></persName>
		</author>
		<author>
			<persName><forename type="first">K</forename><forename type="middle">U</forename><surname>Loser</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">Proc. of Collaboration and Internet Computing (CIC)</title>
				<meeting>of Collaboration and Internet Computing (CIC)</meeting>
		<imprint>
			<publisher>IEEE</publisher>
			<date type="published" when="2016">2016</date>
			<biblScope unit="page" from="502" to="505" />
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b5">
	<monogr>
		<ptr target="http://ec.eu-ropa.eu/justice/data-protection/reform/index_en.htm" />
		<title level="m">Reform of EU data protection rules</title>
				<imprint>
			<publisher>European Commission</publisher>
			<date type="published" when="2016">2016</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b6">
	<analytic>
		<title level="a" type="main">Privacy requirements: Findings and lessons learned in developing a privacy platform</title>
		<author>
			<persName><forename type="first">M</forename><surname>Gharib</surname></persName>
		</author>
		<author>
			<persName><forename type="first">M</forename><surname>Salnitri</surname></persName>
		</author>
		<author>
			<persName><forename type="first">E</forename><surname>Paja</surname></persName>
		</author>
		<author>
			<persName><forename type="first">P</forename><surname>Giorgini</surname></persName>
		</author>
		<author>
			<persName><forename type="first">H</forename><surname>Mouratidis</surname></persName>
		</author>
		<author>
			<persName><forename type="first">M</forename><surname>Pavlidis</surname></persName>
		</author>
		<author>
			<persName><forename type="first">A</forename><surname>Della Siria</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">Proc. International Requirements Engineering Conference</title>
				<meeting>International Requirements Engineering Conference</meeting>
		<imprint>
			<date type="published" when="2016">2016</date>
			<biblScope unit="page" from="256" to="265" />
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b7">
	<analytic>
		<title level="a" type="main">Privacy Engineering: Shaping an Emerging Field of Research and Practice</title>
		<author>
			<persName><forename type="first">S</forename><surname>Gürses</surname></persName>
		</author>
		<author>
			<persName><forename type="first">J</forename><forename type="middle">M</forename><surname>Del Alamo</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">Proceedings of IEEE Security &amp; Privacy</title>
				<meeting>IEEE Security &amp; Privacy</meeting>
		<imprint>
			<date type="published" when="2016">2016</date>
			<biblScope unit="volume">14</biblScope>
			<biblScope unit="page" from="40" to="46" />
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b8">
	<analytic>
		<title level="a" type="main">Embedding stakeholder values in the requirements engineering process</title>
		<author>
			<persName><forename type="first">M</forename><surname>Harbers</surname></persName>
		</author>
		<author>
			<persName><forename type="first">C</forename><surname>Detweiler</surname></persName>
		</author>
		<author>
			<persName><forename type="first">M</forename><forename type="middle">A</forename><surname>Neerincx</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">Proc. of Conference on Requirements Engineering: Foundation for Software Quality</title>
				<meeting>of Conference on Requirements Engineering: Foundation for Software Quality</meeting>
		<imprint>
			<publisher>Springer</publisher>
			<date type="published" when="2015">2015</date>
			<biblScope unit="page" from="318" to="332" />
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b9">
	<analytic>
		<title level="a" type="main">Privacy design strategies</title>
		<author>
			<persName><forename type="first">J</forename><forename type="middle">H</forename><surname>Hoepman</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">IFIP International Information Security Conference</title>
				<meeting><address><addrLine>Berlin Heidelberg</addrLine></address></meeting>
		<imprint>
			<publisher>Springer</publisher>
			<date type="published" when="2014">2014</date>
			<biblScope unit="page" from="446" to="459" />
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b10">
	<monogr>
		<title level="m" type="main">A Study Customer Journey Map for User Experience Analysis of Information and Communications Technology Service</title>
		<author>
			<persName><forename type="first">J</forename><forename type="middle">H</forename><surname>Lee</surname></persName>
		</author>
		<author>
			<persName><forename type="first">M</forename><forename type="middle">J</forename><surname>Kim</surname></persName>
		</author>
		<author>
			<persName><forename type="first">S</forename><forename type="middle">W</forename><surname>Kim</surname></persName>
		</author>
		<imprint>
			<date type="published" when="2015">2015</date>
			<publisher>Springer International Publishing</publisher>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b11">
	<analytic>
		<title level="a" type="main">Privacy by design-principles of privacy-aware ubiquitous systems</title>
		<author>
			<persName><forename type="first">M</forename><surname>Langheinrich</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">International conference on Ubiquitous Computing</title>
				<imprint>
			<publisher>Springer Berlin Heidelberg</publisher>
			<date type="published" when="2001">2001</date>
			<biblScope unit="page" from="273" to="291" />
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b12">
	<monogr>
		<author>
			<persName><forename type="first">H</forename><surname>Nissenbaum</surname></persName>
		</author>
		<title level="m">Privacy in context: Technology, policy, and the integrity of social life</title>
				<imprint>
			<publisher>Stanford University Press</publisher>
			<date type="published" when="2009">2009</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b13">
	<analytic>
		<title level="a" type="main">Using the customer journey to road test and refine the business model</title>
		<author>
			<persName><forename type="first">D</forename><forename type="middle">W</forename><surname>Norton</surname></persName>
		</author>
		<author>
			<persName><forename type="first">B</forename><forename type="middle">J</forename><surname>Pine</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="j">Strategy &amp; Leadership</title>
		<imprint>
			<biblScope unit="volume">41</biblScope>
			<biblScope unit="issue">2</biblScope>
			<biblScope unit="page" from="12" to="17" />
			<date type="published" when="2013">2013</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b14">
	<analytic>
		<title level="a" type="main">PRIPARE: Integrating Privacy Best Practices into a Privacy Engineering Methodology</title>
		<author>
			<persName><forename type="first">N</forename><surname>Notario</surname></persName>
		</author>
		<author>
			<persName><forename type="first">A</forename><surname>Crespo</surname></persName>
		</author>
		<author>
			<persName><forename type="first">Y</forename><forename type="middle">S</forename><surname>Martín</surname></persName>
		</author>
		<author>
			<persName><forename type="first">J</forename><forename type="middle">M</forename><surname>Del Alamo</surname></persName>
		</author>
		<author>
			<persName><forename type="first">D</forename><surname>Le Métayer</surname></persName>
		</author>
		<author>
			<persName><forename type="first">T</forename><surname>Antignac</surname></persName>
		</author>
		<author>
			<persName><forename type="first">A</forename><surname>Kung</surname></persName>
		</author>
		<author>
			<persName><forename type="first">I</forename><surname>Kroener</surname></persName>
		</author>
		<author>
			<persName><forename type="first">D</forename><surname>Wright</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">Proc. of Security and Privacy Workshops (SPW)</title>
				<meeting>of Security and Privacy Workshops (SPW)</meeting>
		<imprint>
			<publisher>IEEE</publisher>
			<date type="published" when="2015">2015</date>
			<biblScope unit="page" from="151" to="158" />
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b15">
	<analytic>
		<title level="a" type="main">Privacy by design</title>
		<author>
			<persName><forename type="first">P</forename><surname>Schaar</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="j">Identity in the Information Society</title>
		<imprint>
			<biblScope unit="volume">3</biblScope>
			<biblScope unit="issue">2</biblScope>
			<biblScope unit="page" from="267" to="274" />
			<date type="published" when="2010">2010</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b16">
	<analytic>
		<title level="a" type="main">Who will watch (over) me? Humane monitoring in dementia care</title>
		<author>
			<persName><forename type="first">Y</forename><surname>Schikhof</surname></persName>
		</author>
		<author>
			<persName><forename type="first">I</forename><surname>Mulder</surname></persName>
		</author>
		<author>
			<persName><forename type="first">S</forename><surname>Choenni</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="j">Int. J. of Human-Computer Studies</title>
		<imprint>
			<biblScope unit="volume">68</biblScope>
			<biblScope unit="issue">6</biblScope>
			<biblScope unit="page" from="410" to="422" />
			<date type="published" when="2010">2010</date>
			<publisher>Elsevier</publisher>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b17">
	<monogr>
		<title level="m" type="main">Threat modeling: Designing for security</title>
		<author>
			<persName><forename type="first">A</forename><surname>Shostack</surname></persName>
		</author>
		<imprint>
			<date type="published" when="2014">2014</date>
			<publisher>John Wiley &amp; Sons</publisher>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b18">
	<analytic>
		<title level="a" type="main">The challenges of privacy by design</title>
		<author>
			<persName><forename type="first">S</forename><surname>Spiekermann</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="j">Communications of the ACM</title>
		<imprint>
			<biblScope unit="volume">55</biblScope>
			<biblScope unit="issue">7</biblScope>
			<biblScope unit="page" from="38" to="40" />
			<date type="published" when="2012">2012</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b19">
	<analytic>
		<title level="a" type="main">Engineering privacy</title>
		<author>
			<persName><forename type="first">S</forename><surname>Spiekermann</surname></persName>
		</author>
		<author>
			<persName><forename type="first">L</forename><forename type="middle">F</forename><surname>Cranor</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="j">IEEE Transactions on software engineering</title>
		<imprint>
			<biblScope unit="volume">35</biblScope>
			<biblScope unit="issue">1</biblScope>
			<biblScope unit="page" from="67" to="82" />
			<date type="published" when="2009">2009</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b20">
	<analytic>
		<title level="a" type="main">This is not a boundary object: Reflections on the origin of a concept</title>
		<author>
			<persName><forename type="first">S</forename><forename type="middle">L</forename><surname>Star</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="j">Science, Technology, &amp; Human Values</title>
		<imprint>
			<biblScope unit="volume">35</biblScope>
			<biblScope unit="page" from="601" to="617" />
			<date type="published" when="2010">2010</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b21">
	<analytic>
		<title level="a" type="main">Institutional ecology, &quot;translations&quot; and boundary objects: Amateurs and professionals in Berkeley&apos;s Museum of Vertebrate Zoology, 1907-39</title>
		<author>
			<persName><forename type="first">S</forename><forename type="middle">L</forename><surname>Star</surname></persName>
		</author>
		<author>
			<persName><forename type="first">J</forename><forename type="middle">R</forename><surname>Griesemer</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="j">Social Studies of Science</title>
		<imprint>
			<biblScope unit="volume">19</biblScope>
			<biblScope unit="page" from="387" to="420" />
			<date type="published" when="1989">1989</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b22">
	<analytic>
		<title level="a" type="main">Bridging the gap between privacy by design and privacy in practice</title>
		<author>
			<persName><forename type="first">L</forename><surname>Stark</surname></persName>
		</author>
		<author>
			<persName><forename type="first">J</forename><surname>King</surname></persName>
		</author>
		<author>
			<persName><forename type="first">X</forename><surname>Page</surname></persName>
		</author>
		<author>
			<persName><forename type="first">A</forename><surname>Lampinen</surname></persName>
		</author>
		<author>
			<persName><forename type="first">J</forename><surname>Vitak</surname></persName>
		</author>
		<author>
			<persName><forename type="first">P</forename><surname>Wisniewski</surname></persName>
		</author>
		<author>
			<persName><forename type="first">N</forename><surname>Good</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">Proc. of the CHI Conference on Human Factors in Computing Systems</title>
				<meeting>of the CHI Conference on Human Factors in Computing Systems</meeting>
		<imprint>
			<publisher>ACM</publisher>
			<date type="published" when="2016">2016</date>
			<biblScope unit="page" from="3415" to="3422" />
		</imprint>
	</monogr>
</biblStruct>

				</listBibl>
			</div>
		</back>
	</text>
</TEI>
