Other Activities
Introduction
This pages covers other activities which could be of interest: guidelines, studies, events
Guidelines
EC Data Protection Impact Assessment Template for Smart Grid and Smart Metering Systems
Context |
The Smart Grids Task Force was set up by the European Commission in 2009 to advise on issues related to smart grid deployment and development. One of the working group (WG2) is on security and privacy. The EC has provided a Data Protection Impact Assessment Template for smart grid and smart metering systems. The EC has decided to have a two-year trial of the template starting from March 2015. |
URL |
Smart grid task force: http://ec.europa.eu/energy/en/topics/markets-and-consumers/smart-grids-and-meters Test phase for template: https://ec.europa.eu/energy/en/test-phase-data-protection-impact-assessment-dpia-template-smart-grid-and-smart-metering-systems |
Documents | Template document: https://ec.europa.eu/energy/sites/ener/files/documents/2014_dpia_smart_grids_forces.pdf |
Comments |
[Antonio Kung]
|
CNIL Privacy Risk analysis
Context | CNIL is the French DPA. It has produced two guidelines in November 2012
The two new guides propose a way to build a comprehensive analysis to handle complex personal data processing operations. These documents are primarily intended for use by controllers, data protection officers (DPO) and chief information security officers (CISO). They assist them in creating a rational understanding of the risks arising from the processing of personal data and to choose necessary and sufficient organizational and technical measures to protect privacy. |
URL | English web page: http://www.cnil.fr/english/news-and-events/news/article/the-cnil-publishes-an-english-translation-of-its-two-advanced-security-and-privacy-risk-management/ |
Document |
Methodology to manage risk: http://www.cnil.fr/fileadmin/documents/en/CNIL-ManagingPrivacyRisks-Methodology.pdf Measures for the privacy risk treatment: http://www.cnil.fr/fileadmin/documents/en/CNIL-ManagingPrivacyRisks-Measures.pdf |
Comments |
NIST study on privacy risk management framework for Federal Information Systems
Context |
NIST issued in May 2015 a draft report: NISTIR 8062, Privacy Risk Management for Federal Information Systems The report describes a privacy risk management framework for federal information systems. The framework provides the basis for establishing a common vocabulary to facilitate better understanding of - and communication about - privacy risks and the effective implementation of privacy principles in federal information systems. Comments are expected by July 13, 2015 at 5:00pm. |
URL | See 8062 dated May 28: http://csrc.nist.gov/publications/PubsDrafts.html and http://www.nist.gov/itl/201506_privacy_framework.cfm |
Document |
Draft document: http://csrc.nist.gov/publications/drafts/nistir-8062/nistir_8062_draft.pdf Comment matrix form: http://csrc.nist.gov/publications/drafts/nistir-8062/nistir_8062_draft_comment_matrix.xls |
Comments |
[Antonio Kung]
|