26.11.2012 Views

Wirtschaftsuniversität Wien Magisterarbeit - SemanticLab

Wirtschaftsuniversität Wien Magisterarbeit - SemanticLab

Wirtschaftsuniversität Wien Magisterarbeit - SemanticLab

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Element Value<br />

ruling allow<br />

user category sales department<br />

action store<br />

data category customer-record<br />

purpose order-processing<br />

condition the customer is older than 13 years of age<br />

obligation delete the data 3 years from now<br />

Table 3.4.: An example EPAL privacy rule (Source: [IBM03])<br />

Element Value<br />

user category sales department<br />

action store<br />

data category customer-record<br />

purpose order-processing<br />

Table 3.5.: An example EPAL request (Source: [IBM03])<br />

would be translated into the formal EPAL privacy rule as shown in Table 3.4. Such<br />

rules are used to determine whether a request is allowed or not. Not surprisingly, a<br />

request contains a user category, an action, a data category, and a purpose. Assume the<br />

following informal request:<br />

A person acting as a sales agent and an employee requests to collect a customer’s<br />

email for order entry. (Source: [IBM03])<br />

This informal request would be translated into the formal EPAL request as shown in<br />

Table 3.5, based on the elements predefined by EPAL and used by the above created<br />

privacy rule. This request matches the rule defined above and therefore it would be<br />

allowed.<br />

As EPAL was especially designed for enterprises, it offers vocabularies that enables<br />

businesses to express sector-specific privacy policies. Although usually one enterprise will<br />

create a policy, the aim is also that companies agree on a set of vocabularies, exchange<br />

these policies and hence use them in their business transactions. The following section<br />

is going to highlight these EPAL vocabularies.<br />

3.2.4. EPAL vocabularies<br />

By using the epal-vocabulary element, industry-specific vocabularies can be defined<br />

using the following subelements:<br />

34<br />

• vocabulary-information: This element provides information about the vocabulary<br />

- the name (id), the issuer of the vocabulary (issuer) and the version<br />

(version-info).

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!