| elap:PURI | http://data.europa.eu/2sa/elap/privacy |
| dct:title | Privacy |
| dct:description | (Statement) Privacy signifies the agreement to the processing of personal data related to an individual, ensuring that personal data is handled with respect and in compliance with legal frameworks. |
| dct:description | (Rationale) Privacy refers to any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which they, through a statement or clear affirmative action, signify agreement to the processing of personal data relating to them. This principle ensures that the vast amounts of citizens' personal data held and processed by public bodies, solutions, and public services are protected by complying with the applicable legal framework, such as the GDPR. In the context of artificial intelligence, privacy is crucial to prevent misuse of personal data and to maintain trust in AI systems. Ensuring privacy compliance not only protects individuals' rights but also enhances the credibility and reliability of digital solutions and public services. |
| dct:description | (Implications) Public bodies and administrations must implement appropriate technical and organisational measures to ensure and demonstrate that processing is performed according to the GDPR. These measures should be regularly reviewed and updated as necessary. Public administrations must establish data protection policies and procedures, conduct regular privacy impact assessments, and ensure that all staff are trained on data protection principles. They should also adopt privacy-by-design principles, integrating privacy considerations into the development and deployment of systems, including AI-related solutions. This involves using robust data anonymisation techniques, ensuring transparency in data processing activities, and implementing secure data management practices. Additionally, public bodies must encourage the establishment of data protection certification mechanisms and data protection seals and marks to demonstrate compliance. All interoperability layers within public services must consider and foresee the implementation of mechanisms to achieve GDPR compliance, ensuring that data is protected across all systems and processes. Additionally, Public bodies should also consider the use of pseudonymity techniques to protect individuals' identities in certain cases, ensuring that personal data is processed in a manner that prevents direct identification while still allowing for necessary data analysis and processing. |
| elap:scope | Business agnostic |
| elap:Category | Digital Public Service Implementation |
| dct:source | Security and Privacy Underlying Principle (8) of the European Interoperability Framework (EIF) |
| dct:source | https://interoperable-europe.ec.europa.eu/collection/nifo-national-interoperability-framework-observatory/2-underlying-principles-european-public-services#2.4 |
| rdfs:comment | The European Interoperability Framework is part of the Communication (COM(2017)134) from the European Commission adopted on 23 March 2017. The framework gives specific guidance on how to set up interoperable digital public services. |
| dcat:theme | Legal IoP, Organisational IoP, Semantic IoP, Technical IoP |
| elap:paGovernance | Common |
| elap:influenceInDPSLifecycle | Obligation |
| elap:influenceInDPSAttribute | Obligation |