<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Privacy-Enhancing Technologies in the Process of Data Privacy Compliance: An Educational Perspective</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Alexandra Klymenko</string-name>
          <email>alexandra.klymenko@tum.de</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Stephen Meisenbacher</string-name>
          <email>stephen.meisenbacher@tum.de</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Florian Messmer</string-name>
          <email>f.messmer@tum.de</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Florian Matthes</string-name>
          <email>matthes@tum.de</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Technical University of Munich, School of Computation, Information and Technology, Department of Computer Science</institution>
          ,
          <addr-line>Boltzmannstr. 3, Garching, 85748</addr-line>
          ,
          <country country="DE">Germany</country>
        </aff>
      </contrib-group>
      <fpage>62</fpage>
      <lpage>69</lpage>
      <abstract>
        <p>Achieving data privacy compliance presents a unique interdisciplinary challenge for experts from many backgrounds, particularly the technical and legal professions. As a potential solution for the legal mandate handed down by modern privacy regulations, Privacy-Enhancing Technologies (PETs) can serve as promising tools to help data processors demonstrate compliance. The implementation of PETs does not come immediately, however, and challenges in their adoption include their inherent technical complexity, as well as the lack of awareness and understanding of these technologies. In tackling these challenges, we investigate the educational needs of practitioners working in privacy compliance. Guided by Bloom's Revised Taxonomy, we begin the discussion on how the adoption of PETs can become more informed, with the goal of improving the efficiency and privacy consciousness of compliance programs. To accomplish this, we conduct 11 semi-structured interviews, analyze the results following Grounded Theory, and evaluate our findings in a survey with 24 respondents.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;Data privacy</kwd>
        <kwd>privacy compliance</kwd>
        <kwd>privacy-enhancing technologies</kwd>
        <kwd>continuous education1</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        In a world where vast amounts of data are being created and processed on a continual basis, the
need for the responsible handling of such data has starkly risen. Along with increasing concerns
regarding the protection of individuals' privacy, the pressure placed on practitioners to comply
with relevant data privacy regulations such as the GDPR raises the stakes for data processors
[
        <xref ref-type="bibr" rid="ref1">1</xref>
        ][
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. Ultimately, a technical response in the form of privacy preservation must be implemented
in data-intensive systems, a complex task that is accompanied by multiple challenges [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ].
      </p>
      <p>
        Recently, the promise of Privacy-Enhancing Technologies (PETs) has saturated the academic
sphere, engaging researchers to develop innovative technologies for data privacy protection. In
essence, PETs encompass a range of technical approaches designed to protect the data of the
individual, when this data is utilized for some purpose. Such technologies, while falling under the
same class of Privacy-Enhancing Technologies, are highly diverse, particularly in their applicable
use cases. One unifying aspect, though, is their inherent complexity, which has kept their practical
adoption quite limited [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ][
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]. Nevertheless, data processors can benefit from the deployment of
PETs as a means of protecting sensitive information while still allowing meaningful utilization of
the data.
      </p>
      <p>The road to widespread adoption of Privacy-Enhancing Technologies begins with the
transition from PETs as a research topic to the dissemination of such knowledge to practitioners
in the industry. However, essential questions then arise as to who constitutes the target audience,
and what specific knowledge regarding PETs is required by practitioners. To identify the target</p>
      <p>0000-0001-7485-2933 (A. Klymenko); 0000-0001-9230-5001 (S. Meisenbacher);
0000-0002-6667-5452 (F. Matthes)
© 2023 Copyright for this paper by its authors.</p>
      <p>Use permitted under Creative Commons License Attribution 4.0 International (CC BY 4.0).</p>
      <p>
        CEUR Workshop Proceedings (CEUR-WS.org)
audience, we look to the process of privacy compliance, which centers around the
implementation of appropriate technical measures for the safeguarding of personal data being
processed in a system. Gürses and Del Alamo [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ] and Klymenko et al. [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ] have shown that this
process is highly interdisciplinary, involving primarily experts of technical and legal
backgrounds. These two types of roles, therefore, become the focus of our work. We argue that
education on PETs should take into consideration the diversity of roles in the privacy compliance
process, as differing roles have distinct backgrounds, responsibilities, concerns, and, as will be
shown, different interests regarding familiarization with PETs.
      </p>
      <p>
        In this work, we aim to investigate the educational needs of practitioners with respect to PETs,
with the goal of empowering them to be competent users of PETs, as "computer scientists and
particularly IT security experts with knowledge about privacy-enhancing technologies are
increasingly needed" [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]. We define the following research questions:
[RQ1] How can learning goals for Privacy-Enhancing Technologies be defined?
[RQ2] How can these learning goals be mapped to the role-specific needs of practitioners
involved in privacy compliance?
To answer these research questions, we draw upon existing educational frameworks, leveraging
the resulting insights from industry interviews to augment educational thinking on PETs. The
possible learning objectives with regards to Privacy-Enhancing Technologies are segmented
according to the framework of Bloom's Revised Taxonomy [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ] introduced by Krathwohl.
Subsequently, we evaluate the identified objectives via the administration of surveys. From this,
we propose a new way of thinking about education on PETs, particularly considering the
background of the person in question.
      </p>
    </sec>
    <sec id="sec-2">
      <title>2. Background</title>
      <p>A key step towards ensuring compliance with the data privacy regulations comes with the
requirement to implement technical measures to protect the privacy of individuals. In this respect
becomes important the concept of Privacy-Enhancing Technologies (PETs), a class of
technologies that "protect privacy by eliminating or reducing personal data or by preventing
unnecessary and/or undesired processing of personal data, all without losing the functionality of
the information system" [9]. The recent guidance by the Information Commissioner’s Office (ICO)
provides a detailed discussion on some of the prominent PETs, such as Differential Privacy,
ZeroKnowledge Proofs, and Secure Multi-Party Computation, and outlines how they can help
organizations to achieve data privacy compliance [10].</p>
      <p>
        Although such advanced PETs present concrete solutions for personal data protection and
multiple real-world use case examples have been reported [11][12], they still remain
predominantly in the academic sphere and are not widely adopted in practice [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ][
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]. Among the
main reasons for this, is the complexity of these technologies, as well as the lack of awareness,
knowledge, and education on them [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]. Therefore, the promotion of continuing education on
topics related to data privacy and PETs can be considered crucial to the development of successful
privacy compliance programs. While the presented recent reports [10][11][12] highlight the
significance of PETs and play an important role in promoting their implementation in the
industry, these works offer a rather broader overview and do not focus on providing tailored and
comprehensive educational content.
      </p>
      <p>
        In this work, we consider the inherently interdisciplinary nature of privacy compliance and
investigate the educational needs of practitioners based on the different roles involved in the
process of privacy compliance, as proposed by Klymenko et al. [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]. Namely, the roles are divided
into three categories: 1) Legal – practicing lawyers, specializing in the fields of privacy and data
protection, 2) Technical – roles involved in the implementation of the product, such as software
developers, engineers, and architects, as well as the appropriate management roles, and 3)
GoBetweens – practitioners working at the intersection of technical and legal fields, including roles
such as Data Protection Officer (DPO), and Privacy Engineer.
      </p>
    </sec>
    <sec id="sec-3">
      <title>3. Methodology</title>
      <p>To assess the educational needs of practitioners in learning about PETs, we designed the
interview and survey studies to focus on extracting the learning goals of the questioned experts.
In the interview, this was done in a semi-structured way, with two categories of questions:
background questions, including the interviewee’s baseline knowledge of PETs, and questions
aimed at identifying what kind of information about PETs is most relevant to the interviewee's
role and responsibilities. A thematic content analysis according to Braun and Clarke [13] was
conducted on the interview transcripts. The main goal of this analysis was to identify overarching
themes expressed in the interviews, particularly relating to the learning needs and goals of
practitioners with respect to PETs. Guided by following Grounded Theory (GT) Methodology [14],
we analyzed interview transcripts concurrently to data collection and highlighted key themes,
which were categorized into learning goals and educational needs. Axial coding was applied to
identify relationships between these themes, supported by Bloom’s Revised Taxonomy.</p>
      <p>Based on the resulting learning goals identified by our analysis and introduced in Table 3, the
survey statements were designed to map learning goals to role-specific educational needs, where
each statement corresponded to a cognitive process in Bloom’s Revised Taxonomy. The survey
participants were then prompted to select the statement which best reflects their personal
learning goals, allowing for the mapping of roles to levels in Bloom’s Revised Taxonomy.</p>
      <p>Table 1 and Table 2 present relevant information on the interviewees and survey participants.
Area identifies whether the survey respondents are working in a technical (T), legal (L), or
GoBetween (G) role. Exp. represents years of relevant experience. To mitigate bias, no survey
respondents also took part in the interview study.</p>
    </sec>
    <sec id="sec-4">
      <title>4. PETs and Bloom's Revised Taxonomy</title>
      <p>
        To formulate and categorize the learning goals of practitioners regarding PETs, we employ
Bloom's Revised Taxonomy [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ]. This taxonomy provides an organizational structure of
educational objectives, consisting of the Knowledge Dimension and the Cognitive Process
Dimension. The types of knowledge are structured into four categories: Factual, Conceptual,
Procedural, and Metacognitive. These knowledge levels are mapped back to the six cognitive
processes: Remember, Understand, Apply, Analyze, Evaluate, and Create. The knowledge levels are
introduced below in light of PETs, and the resulting learning goal statements are presented in
Table 3, which maps statements to their corresponding knowledge level and cognitive process.
This mapping becomes relevant to understanding the role-specific learning goals of practitioners
on the topic of PETs.
      </p>
      <sec id="sec-4-1">
        <title>4.1. Factual Knowledge</title>
        <p>Factual knowledge includes terminology, characteristics, and features of PETs. The simplest
learning goals are to list different PETs, as well as to know about the use cases of PETs, a topic
most directly corresponding to Remember. Analyzing PETs on a factual level can be conceived as
comparing different PETs and accordingly selecting technologies. It thus becomes clear that the
tasks build up on each other, i.e., that Remember, Understand, and Apply are required to perform
the subsequent Analyze tasks.</p>
      </sec>
      <sec id="sec-4-2">
        <title>4.2. Conceptual Knowledge</title>
        <p>Conceptual knowledge is closely related to theoretical topics, such as introducing models,
approaches, and interrelations of PETs. As opposed to factual knowledge, conceptual knowledge
includes the principles behind the functionality of PETs. Based on the study results, statements
are focused on system architecture, as interview participants reported a need to understand this
topic better. The idea of integrating newly learned information into existing knowledge domains
characterizes conceptual knowledge. However, it encapsulates the decision over which
technology would be applicable; the implementation itself belongs strictly to the following
category.</p>
      </sec>
      <sec id="sec-4-3">
        <title>4.3. Procedural Knowledge</title>
        <p>Here, the focus is placed on the implementation of PETs. Although the statements presented are
expected to be universally applicable to all privacy roles, there is now a shift towards more
technical content. Applying Procedural Knowledge marks the point where the learning content
becomes rather technical, implying that a higher level of technical literacy is required.
Furthermore, it shows how many learning goals can be identified before implementation. The
next modification of the cognitive category is directed at the implementation action itself. The
intent is not just to implement PETs in any fashion but to know parameters and quality measures,
and thereby build an implementation strategy. Ultimately, the goal of procedural knowledge is
not only to find the most suitable PET, but also to contribute to the development of new PETs.</p>
      </sec>
      <sec id="sec-4-4">
        <title>4.4. Metacognitive Knowledge</title>
        <p>Privacy-Enhancing Technologies are under constant pressure to evolve, as are any technologies
employed to minimize risks or mitigate threats. The question of maturity is of great interest with
Privacy-Enhancing Technologies. Achieving such knowledge requires a deep knowledge of the
PETs in question, the environment in which PETs are implemented, and awareness of the
limitations of the technologies. Therefore, learning goals in this knowledge category convey this
critical approach, while also focusing on finding strategies to address these limitations. The
highest learning goal would be to transfer knowledge to formerly unknown domains, identifying
new purposes for PETs.</p>
      </sec>
      <sec id="sec-4-5">
        <title>4.5. Learning Goal Statements</title>
        <p>Table 3 presents the set of learning goal statements for PETs, which is based on Bloom’s Revised
Taxonomy and supported by the interview findings. Using the guidelines provided by the original
taxonomy and augmenting these with goals expressed by interviewees, we build the statements
in Table 3 to align with the knowledge levels and cognitive processes of Bloom’s Revised
Taxonomy. This mapping process is aided by Anderson and Krathwohl [15] and inspired by
Servin et al. [16], the latter of which extends existing verb sets to include the technical domain.</p>
        <p>Evaluate Create
I want to verify I want to be
statements about able to
the features of classify a</p>
        <p>PETs. new PET.</p>
        <p>I want to decide I want to
on which PET create
metawould be most models for
suitable in a given PETs.</p>
        <p>system
environment.</p>
        <p>I want to decide I want to
on the best way to contribute to
implement a PET the
in a given development
situation. of new PETs.</p>
        <p>I want to evaluate</p>
        <p>PET
implementations</p>
        <p>and develop
recommendations.</p>
        <p>I want to
find new use</p>
        <p>cases to
which PETs
could be
applied.</p>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>5. Role-Specific Educational Needs</title>
      <p>To evaluate the relevance of the presented in Table 3 learning goals for different roles, we
conducted a survey with practitioners. In designing the survey, we first ensured that the role of
each respondent was captured. Next, the statements of each separate knowledge level were
presented, and the respondent was prompted to select which statement was most relevant to the
task of their specific privacy role. In addition, the respondent was informed that the statements
followed a hierarchical order, meaning that selecting a more advanced cognitive process included
all the previous ones as relevant. For example, in the Factual Knowledge category, choosing "I
want to know the various use cases for PETs" implies that "I want to know what different PETs
exist" also applies.</p>
      <p>The role-specific insights are presented in Table 4 which separates the results based on the
reported role. Table 4 utilizes a heat map to illustrate the frequency by which a particular option
was chosen. Thus, the number displayed in each cell represents the aggregated number of
responses that the corresponding option received, considering the previously introduced
hierarchical setup.</p>
      <p>As can be seen from Table 4, roles from the three different privacy role categories possess
different learning goals, which is made particularly salient by our utilization of Bloom's Revised
Taxonomy. Table 4b suggests that legal experts in the privacy compliance process would be most
concerned with obtaining factual knowledge about PETs. This is plausible, as legal experts would
not be involved in the implementation of PETs, but rather must be knowledgeable on the topic in
general, i.e., know the facts. In Table 4a, a clear preference from technical experts towards factual
and procedural knowledge can be observed. Thus, these experts must not only be cognizant of
the facts, but also be skilled in the procedural know-how required for the implementation of PETs.
Another interesting finding arrives with an analysis of the learning goals of Go-Between roles,
whose preferences seemingly reside distinctly in conceptual knowledge. Looking to Table 3 for
an explanation, one can see that conceptual knowledge truly lies on the border between factual
and procedural knowledge, in the way that factual knowledge becomes important more from an
IT architecture and policy point of view, rather than pure implementation. Indeed, members of
the Go-Between category do exist to bridge this gap, serving as a crucial link between legal
mandate and technical specification.</p>
    </sec>
    <sec id="sec-6">
      <title>6. Conclusion and Outlook</title>
      <p>In this research in progress, we explore the educational needs of privacy professionals with
respect to learning about Privacy-Enhancing Technologies. Under the framework of Bloom's
Revised Taxonomy, we subdivide PET education into learning goals based on six cognitive
processes and four knowledge levels. Moreover, we probe the relevance of each of these
categories with different subgroups of privacy professionals: technical and legal experts, as well
as Go-Betweens. The results of the survey provide insights into differing educational needs
governed by the requirements of each role.</p>
      <p>The practical relevance of this work is grounded in the underlying complexities of
state-ofthe-art PETs, which, without the necessary expertise, can hinder their adoption, calling for
focused educational efforts to foster the development of such expertise. Looking forward, we plan
not only to continue working on making knowledge on PETs open, accessible, and
understandable, but also to do so in a way that considers the expertise of the learner. Our next
steps include the creation of learning material on PETs, the validation of such material, and the
deployment of an e-learning platform to encapsulate the learning content. In the creation of
learning material, the findings presented in this work will be integral to tailoring the learning
experience to different professional backgrounds with specific learning needs. The e-learning
platform will provide the opportunity for collaboration with industry partners, further closing
the gap between academia and industry on the topic of Privacy-Enhancing Technologies.</p>
    </sec>
    <sec id="sec-7">
      <title>Acknowledgements References</title>
      <p>This work has been supported by the German Federal Ministry of Education and Research
(BMBF) Software Campus grant LACE 01IS17049.
[9] G. W. Van Blarkom, J. J. Borking, and J. G. E. Olk, Handbook of privacy and privacy-enhancing
technologies, Privacy Incorporated Software Agent (PISA) Consortium, The Hague, vol. 198,
p. 14, 2003.
[10] Information Commissioner’s Office, Privacy-enhancing technologies (PETs), 2023.
[11] The Royal Society, From privacy to partnership: the role of Privacy Enhancing Technologies
in data governance and collaborative analysis, 2023.
[12] United Nations, The United Nations Guide on Privacy-Enhancing Technologies for Official</p>
      <p>Statistics, 2023.
[13] V. Braun and V. Clarke, Using thematic analysis in psychology, Qualitative research in
psychology, vol. 3, no. 2, pp. 77–101, 2006.
[14] M. Wiesche, M. C. Jurisch, P. W. Yetton, and H. Krcmar, Grounded theory methodology in
information systems research, MIS quarterly, vol. 41, no. 3, pp. 685-A9, 2017.
[15] L. W. Anderson and D. R. Krathwohl, A Taxonomy for Learning, Teaching, and Assessing: A</p>
      <p>Revision of Bloom’s Taxonomy of Educational Objectives. Longman, 2001.
[16] C. Servin, C. Tang, M. Geissler, M. Stange, and C. Tucker, Enhanced Verbs for Bloom’s
Taxonomy with Focus on Computing and Technical Areas, in Proceedings of the 52nd ACM
Technical Symposium on Computer Science Education, Virtual Event, USA, 2021, p. 1270.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>J.</given-names>
            <surname>Wolff</surname>
          </string-name>
          and
          <string-name>
            <given-names>N.</given-names>
            <surname>Atallah</surname>
          </string-name>
          ,
          <source>Early GDPR Penalties: Analysis of Implementation and Fines Through May</source>
          <year>2020</year>
          ,
          <source>Journal of Information Policy</source>
          , vol.
          <volume>11</volume>
          , no.
          <issue>1</issue>
          , pp.
          <fpage>63</fpage>
          -
          <lpage>103</lpage>
          , Jan.
          <year>2021</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>M.</given-names>
            <surname>Goddard</surname>
          </string-name>
          ,
          <article-title>The EU General Data Protection Regulation (GDPR): European Regulation that has a Global Impact</article-title>
          ,
          <source>International Journal of Market Research</source>
          , vol.
          <volume>59</volume>
          , no.
          <issue>6</issue>
          , pp.
          <fpage>703</fpage>
          -
          <lpage>705</lpage>
          , Nov.
          <year>2017</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>O.</given-names>
            <surname>Klymenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Meisenbacher</surname>
          </string-name>
          , and
          <string-name>
            <given-names>F.</given-names>
            <surname>Matthes</surname>
          </string-name>
          ,
          <article-title>Identifying Practical Challenges in the Implementation of Technical Measures for Data Privacy Compliance</article-title>
          ,
          <source>AMCIS 2023 Proceedings. 2</source>
          ,
          <year>2023</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>M.</given-names>
            <surname>Hansen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.-H.</given-names>
            <surname>Hoepman</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Jensen</surname>
          </string-name>
          , and
          <string-name>
            <given-names>S.</given-names>
            <surname>Schiffner</surname>
          </string-name>
          ,
          <article-title>Readiness analysis for the adoption and evolution of privacy enhancing technologies: methodology, pilot assessment, and continuity plan</article-title>
          ,
          <source>Technical report: ENISA</source>
          ,
          <year>2015</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>O.</given-names>
            <surname>Klymenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Kosenkov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Meisenbacher</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Elahidoost</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Mendez</surname>
          </string-name>
          , and
          <string-name>
            <given-names>F.</given-names>
            <surname>Matthes</surname>
          </string-name>
          ,
          <article-title>Understanding the Implementation of Technical Measures in the Process of Data Privacy Compliance: A Qualitative Study</article-title>
          ,
          <source>in Proceedings of the 16th ACM/IEEE International Symposium on Empirical Software Engineering and Measurement</source>
          ,
          <year>2022</year>
          , pp.
          <fpage>261</fpage>
          -
          <lpage>271</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>S.</given-names>
            <surname>Gürses and J. M. Del Alamo</surname>
          </string-name>
          ,
          <article-title>Privacy engineering: Shaping an emerging field of research and practice</article-title>
          ,
          <source>IEEE Security &amp; Privacy</source>
          , vol.
          <volume>14</volume>
          , no.
          <issue>2</issue>
          , pp.
          <fpage>40</fpage>
          -
          <lpage>46</lpage>
          ,
          <year>2016</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>S.</given-names>
            <surname>Fischer-Hübner</surname>
          </string-name>
          and
          <string-name>
            <given-names>H.</given-names>
            <surname>Lindskog</surname>
          </string-name>
          ,
          <article-title>Teaching privacy-enhancing technologies</article-title>
          ,
          <source>in Proceedings of the IFIP WG 11.8 2nd World Conference on Information Security Education</source>
          ,
          <year>2001</year>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>17</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>D. R.</given-names>
            <surname>Krathwohl</surname>
          </string-name>
          ,
          <article-title>A Revision of Bloom's Taxonomy: An Overview</article-title>
          ,
          <source>Theory Into Practice</source>
          , vol.
          <volume>41</volume>
          , no.
          <issue>4</issue>
          , pp.
          <fpage>212</fpage>
          -
          <lpage>218</lpage>
          ,
          <year>2002</year>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>