The advent of the General Data Protection Regulation (GDPR) and analogous global data protection laws has profoundly influenced organizations' socio-technical structures, mandating compliance with stringent personal data processing standards. These laws compel entities to critically understand their socio-technical systems, encompassing the complex interplay between legal, managerial, and technical components. This thesis addresses the challenge of ensuring compliance through empirical methodologies and field studies, enhancing both theoretical understanding and practical application. Chapter 2 explores the multifaceted role of Data Protection Officers (DPOs) as mediators between compliance auditors and organizational management. It highlights the tension inherent in their dual role and the socio-technical risks DPOs navigate in diverse operational contexts. Chapter 3 focuses on user understanding of privacy policies across linguistic boundaries, proposing a methodology for creating cross-language comparable corpora. Using English and Italian privacy policies, it showcases how language and cultural adaptations influence user comprehension of technical terms and offers a replicable approach for cross-language research. Chapter 4 extends this work by refining tools for analyzing cross-language privacy policies. By mapping technical terms and assessing their frequency and relevance, it identifies the limitations of automated methods and underscores the importance of manual intervention for nuanced cross-lingual analyses. Chapter 5 examines GDPR implementation in resource-constrained settings, such as schools, revealing gaps between theoretical compliance and practical execution. A risk-based approach is proposed, advocating feasible and continuously improvable data protection practices over rigid adherence to legal stipulations. The conclusions (Chapter 6) summarizes the findings for cross-language privacy research and practical insights for improving compliance in socio-technical systems.

Privacy in the small / Ciclosi, Francesco. - (2025 Apr 14), pp. 1-272.

Privacy in the small

Ciclosi, Francesco
2025-04-14

Abstract

The advent of the General Data Protection Regulation (GDPR) and analogous global data protection laws has profoundly influenced organizations' socio-technical structures, mandating compliance with stringent personal data processing standards. These laws compel entities to critically understand their socio-technical systems, encompassing the complex interplay between legal, managerial, and technical components. This thesis addresses the challenge of ensuring compliance through empirical methodologies and field studies, enhancing both theoretical understanding and practical application. Chapter 2 explores the multifaceted role of Data Protection Officers (DPOs) as mediators between compliance auditors and organizational management. It highlights the tension inherent in their dual role and the socio-technical risks DPOs navigate in diverse operational contexts. Chapter 3 focuses on user understanding of privacy policies across linguistic boundaries, proposing a methodology for creating cross-language comparable corpora. Using English and Italian privacy policies, it showcases how language and cultural adaptations influence user comprehension of technical terms and offers a replicable approach for cross-language research. Chapter 4 extends this work by refining tools for analyzing cross-language privacy policies. By mapping technical terms and assessing their frequency and relevance, it identifies the limitations of automated methods and underscores the importance of manual intervention for nuanced cross-lingual analyses. Chapter 5 examines GDPR implementation in resource-constrained settings, such as schools, revealing gaps between theoretical compliance and practical execution. A risk-based approach is proposed, advocating feasible and continuously improvable data protection practices over rigid adherence to legal stipulations. The conclusions (Chapter 6) summarizes the findings for cross-language privacy research and practical insights for improving compliance in socio-technical systems.
14-apr-2025
XXXVII
2023-2024
Ingegneria e scienza dell'Informaz (29/10/12-)
Information and Communication Technology
Massacci, Fabio
Varni, Giovanna Paola
no
Inglese
Settore ING-INF/05 - Sistemi di Elaborazione delle Informazioni
Settore IINF-05/A - Sistemi di elaborazione delle informazioni
File in questo prodotto:
File Dimensione Formato  
PHD_Thesis_CICLOSI_Final.pdf

accesso aperto

Descrizione: Tesi di dottorato
Tipologia: Tesi di dottorato (Doctoral Thesis)
Licenza: Tutti i diritti riservati (All rights reserved)
Dimensione 3.69 MB
Formato Adobe PDF
3.69 MB Adobe PDF Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11572/450692
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
  • OpenAlex ND
social impact