Privacy Requirements and Realities of Digital Public Goods

Tuesday, September 12, 2023 - 4:45 pm5:00 pm

Geetika Gopi, Carnegie Mellon University School of Computer Science, CMU CyLab Security & Privacy Institute

Abstract: 

Digital Public Goods (DPGs) are a recent concept describing open-source digital artifacts (e.g., software, datasets) that aim to address the UN Sustainable Development Goals. DPGs are increasingly being used to deliver essential government services around the world (e.g., ID management, healthcare registration). The privacy risks of DPGs are currently managed in part by the DPG standard, which is a prerequisite checklist for being classified a DPG; the standard includes requirements about protecting user privacy. This talk will examine the effectiveness of the current DPG standard for ensuring adequate privacy protections. We explain the DPG standard's current rubric, followed by a systematic assessment of responses from major DPGs regarding their protections of users' privacy. We will also present in-depth case studies from major DPGs to identify critical privacy threats. Our findings reveal serious limitations in the current evaluation approach. We will conclude by presenting preliminary recommendations and improvements to the DPG standard.

Geetika Gopi, Carnegie Mellon University School of Computer Science, CMU CyLab Security & Privacy Institute

Geetika Gopi is a graduate student at Carnegie Mellon University's School of Computer Science, where she's pursuing a Master's degree in Privacy Engineering. She's also a Research Assistant at CyLab, a leading research center at CMU that focuses on cutting-edge research on security and privacy. With a background in Cyber Security and previous experience as a Security Consultant at Ernst and Young, Geetika is committed to exploring new approaches and techniques for building secure and private-by-design systems.

BibTeX
@conference {290825,
author = {Geetika Gopi},
title = {Privacy Requirements and Realities of Digital Public Goods},
year = {2023},
address = {Santa Clara, CA},
publisher = {USENIX Association},
month = sep
}

Presentation Video