A Reference Design Model to Manage Consent in Data Subjects-Centered Internet of Things Devices

被引:0
作者
Khatiwada, Pankaj [1 ]
Yang, Bian [1 ]
Lin, Jia-Chun [1 ]
Mugurusi, Godfrey [2 ]
Underbekken, Stian [3 ]
机构
[1] Norwegian Univ Sci & Technol NTNU, Dept Informat Secur & Commun Technol IIK, N-7034 Trondheim, Norway
[2] Norwegian Univ Sci & Technol NTNU, Dept Ind Econ & Technol Management IOT, N-7034 Trondheim, Norway
[3] IKOMM AS, N-2624 Lillehammer, Norway
来源
IOT | 2024年 / 5卷 / 01期
关键词
consent management; internet of things (IoT); data protection; privacy; GDPR; user control; transparency;
D O I
10.3390/iot5010006
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Internet of Things (IoT) devices have changed how billions of people in the world connect and interact with each other. But, as more people use IoT devices, many questions arise about how these devices handle private data and whether they properly ask for permission when using it. Due to information privacy regulations such as the EU's General Data Protection Regulation (GDPR), which requires companies to seek permission from data subjects (DS) before using their data, it is crucial for IoT companies to obtain this permission correctly. However, this can be really challenging in the IoT world because people often find it difficult to interact with and manage multiple IoT devices under their control. Also, the rules about privacy are not always clear. As such, this paper proposes a new model to improve how consent is managed in the world of IoT. The model seeks to minimize "consent fatigue" (when people get tired of always being asked for permission) and give DS more control over how their data are shared. This includes having default permission settings, being able to compare similar devices, and, in the future, using AI to give personalized advice. The model allows users to easily review and change their IoT device permissions if previous conditions are not met. It also emphasizes the need for easily understandable privacy rules, clear communication with users, and robust tracking of consent for data usage. By using this model, companies that provide IoT services can do a better job of protecting user privacy and managing DS consent. In addition, companies can more easily comply with data protection laws and build stronger relationships with their customers.
引用
收藏
页码:100 / 122
页数:23
相关论文
共 24 条
  • [1] A Blockchain-Based Consent Mechanism for Access to Fitness Data in the Healthcare Context
    Alhajri, May
    Rudolph, Carsten
    Shahraki, Ahmad Salehi
    [J]. IEEE ACCESS, 2022, 10 : 22960 - 22979
  • [2] Helping Users Managing Context-based Privacy Preferences
    Alom, Md. Zulfikar
    Carminati, Barbara
    Ferrari, Elena
    [J]. 2019 IEEE INTERNATIONAL CONFERENCE ON SERVICES COMPUTING (IEEE SCC 2019), 2019, : 100 - 107
  • [3] [Anonymous], 2023, Top 7 Open Source Home Automation Software
  • [4] Broring A., 2016, P 6 INT C INTERNET T, P131, DOI 10.1145/2991561.2991570
  • [5] Chikukwa G., 2021, Dak. State
  • [6] A Generic Information and Consent Framework for the IoT
    Cunche, Mathieu
    Le Metayer, Daniel
    Morel, Victor
    [J]. 2019 18TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS/13TH IEEE INTERNATIONAL CONFERENCE ON BIG DATA SCIENCE AND ENGINEERING (TRUSTCOM/BIGDATASE 2019), 2019, : 366 - 373
  • [7] European Union, 2016, Regulation (EU) 2016/679 Of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of per- sonal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), VL110, P1
  • [8] Value-based Consent Model: A Design Thinking Approach for Enabling Informed Consent in Medical Data Research
    Geller, Simon
    Mueller, Sebastian
    Scheider, Simon
    Woopen, Christiane
    Meister, Sven
    [J]. HEALTHINF: PROCEEDINGS OF THE 15TH INTERNATIONAL JOINT CONFERENCE ON BIOMEDICAL ENGINEERING SYSTEMS AND TECHNOLOGIES - VOL 5: HEALTHINF, 2021, : 81 - 92
  • [9] A survey on data provenance in IoT
    Hu, Rui
    Yan, Zheng
    Ding, Wenxiu
    Yang, Laurence T.
    [J]. WORLD WIDE WEB-INTERNET AND WEB INFORMATION SYSTEMS, 2020, 23 (02): : 1441 - 1463
  • [10] Internet of My Things, Internet of My Things