Information assurance typically analyses the risks to a data owner, costs of a data breach, value to an attacker, resources available to the attacker and time scales over which the value and risks are valid. Similar ideas are also used in safety engineering. The research would investigate the applicability of these facets to the public’s perceptions of data privacy i.e. how do people think about data privacy and what constructs do they use to help them make decisions about how and when to share personal data? How well do the constructs of risk, cost, value and time influence how, when and where we share and store our personal data.

Example Approaches:

Perceptions of data privacy vary from person to person, and is affected not only by individual perceptions but also by cultural and social norms. Because of this, how people think about data privacy is very different to large organizations, who tend to think about data security in monetary terms. This research should investigate how people make decisions about privacy, and whether it would be possible to devise a single scale on which people make judgments about data privacy. When researching whether such a scale is possible, the research should investigate the overlapping facets by which people make their decisions.
Linked to this research should be the concept of risk - What are the risks to privacy in a world in which public information about individuals is easy to gather and is it possible to assess the power of linkage across data sources? Is this a problem with a technical solution at all? And most importantly, how do people think about risks to personal data?
And there are also technical strands to this area: The benefits of statistical analysis of personal data are huge. What technical means are there to limit access to personal data, and what is information-theoretic basis of the concept of anonymization? Is it possible in principle to work with personal data while eliminating the personal element?
What are the public perceptions of privacy, and how to they map onto technical aspects of data storage and control? Are there identifiable sub-populations with different or even incompatible views? Is there a sufficient public understanding of risk in general and privacy risk in particular to sustain a viable policy framework?
