Compliance as Baseline, or Striving for More? How Privacy Engineers Work and Use Privacy Standards

Zachary Kilhoffer, Devyn Wilder, Masooda Bashir

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

The privacy field is becoming more rigorous and standardized with privacy engineers (PEs) playing key roles in the process. Yet, privacy engineering remains vaguely defined, and privacy standards remain far from the wide demand and acceptance of security standards like ISO 27001 or FedRAMP. To better understand the work PEs do, and how privacy standards fit in, we conducted an interview study with (n=14) privacy engineers. The findings revealed two new roles PEs fulfill: (1) Liaison between Legal and Engineering teams, and (2) Educator. We found that PEs are often too caught up in baseline legal compliance issues to think about implementing more ambitious privacy goals. The more senior PEs were more likely to have the need, flexibility, and resources to effect organizational change using privacy standards. This study provides timely information to ensure privacy standards remain current, relevant, and effective by detailing the challenges and opportunities PEs experience on the job generally, and with privacy standards specifically.

Original languageEnglish (US)
Title of host publicationProceedings - 9th IEEE European Symposium on Security and Privacy Workshops, Euro S and PW 2024
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages9-18
Number of pages10
ISBN (Electronic)9798350367294
DOIs
StatePublished - 2024
Event9th IEEE European Symposium on Security and Privacy Workshops, Euro S and PW 2024 - Vienna, Austria
Duration: Jul 8 2024Jul 12 2024

Publication series

NameProceedings - 9th IEEE European Symposium on Security and Privacy Workshops, Euro S and PW 2024

Conference

Conference9th IEEE European Symposium on Security and Privacy Workshops, Euro S and PW 2024
Country/TerritoryAustria
CityVienna
Period7/8/247/12/24

Keywords

  • privacy engineering
  • privacy standards

ASJC Scopus subject areas

  • Information Systems and Management
  • Safety, Risk, Reliability and Quality
  • Computer Networks and Communications
  • Information Systems

Fingerprint

Dive into the research topics of 'Compliance as Baseline, or Striving for More? How Privacy Engineers Work and Use Privacy Standards'. Together they form a unique fingerprint.

Cite this