>> So I would like to work through an example spec. and how the privacy considerations ended up being written, as a way to show/teach people how to fish for themselves. The model where a small interest group does the privacy review post-facto is unsustainable, IMHO, for two reasons (a) the group is too small and (b) ‘wide review’ stage is waaay too late to be thinking about privacy implications.
>>
>> Makes sense?
Yes :)
Here is an example presentation from 2013 by Hannes Tschofenig that may be helpful in this context:
https://github.com/hannestschofenig/tschofenig-ids/raw/master/PrivacyTutorial/iab-privacy-considerations.pptx
Suggestion for a walkthrough:
1. Description of what was done.
2. What privacy concerns were raised / discussed?
3. What changes have been made in response to those discussions?
4. Lessons learned
Rob
—
Sent from browser, all error self inflicted.
PGP id: CC4F3863
PGP fingerprint: 1D00 A9FD 7CCB A5A5 850E 2149 BEA0 20B7 CC4F 3863 [public key]
Social media: @rvaneijk, github, linkedin, ssrn, stackoverflow <http://stackoverflow.com/users/4725192/rvaneijk?tab=profile> .