Comparing and Conceptualizing Data Protection Requirements Worldwide for Privacy Regulatory Compliance
Authors/Creators
Description
Introduction
This dataset comprises of different materials of the [NAME PROJECT]. Materials includes: semi-structure interviews material, documentation and regulation notation.
Each material has an explanation below.
This material is part of a research output that is under a review process. Therefore, all material has been anonymous and it is under restricted visibility.
Semi-structured interviews
Part of the data set includes the semi-structured interviews conducted with domain experts in data protection and privacy regulations from various jurisdictions. All interviewees have formal legal education or are recognized as experts in the domain (ex: data protection authority, known authors/speakers). The purpose of the interviews is to identify common and divergent data protection regulatory requirements that impact transborder personal data flows and compliance in multiple systems, alongside other issues in the SDLC (such as communication, collaboration).
The database includes transcripts of expert interviews that have been made publicly available, upon informed and explicit consent from the participants. By default, all interviews are anonymized to protect the identity of the participants and to reduce potential bias during analysis. Other interviews may be available upon request, and other are kept confidential depending on the participants consent.
The (public) files have been named in the following manner: [COUNTRY OF EXPERTISE]-[Random letters]. This way, when referring to the specific participants, we can identify them this way within the project files. All other interviews and the results reported in papers does not use this identification rule to avoid re-identification of participants who did not want to be identified.
Transcripts were done with AI models upon the consent of the subject. The section in bold represent the interviewer, and normal font is the interviewee. For more details on the transcription purpose, you can check here [unavailable for reviewing reasons]
In addition we have included a detailed codebook used to support qualitative analysis. The codebook provides definitions for each code used. When new codes emerged, these were added to the codebook with appropriate annotation (ex: labelled as new), including a definition and possibly verbatims.
The guiding semi-structured interview and blinded consent form are included. The privacy policy and information notice sheet is not included for reviewing reason, until the data set is made public.
Interview anlaysis
The interview analysis was done in MaxQDA. These results can be found in directory 03-Data-Analysis > Interviews, including the codebook.
For notation purposes, we use the following acronyms:
- EU : Europe/ European Union
- NA: North America
- SA: South America
- AF: Africa
- AS-OC: Asia and Oceania
Regulation analysis and codebook
There are two Excel files, one for the whole regulation and another one for coding the type of information the privacy notice should contain. Each has the corresponding codebook attached. The file 'Regulation-analysis-codebook-notation' contains a README that provides more information.
Given the number of sources used to analyze the regulation, a dedicated PDF was created ('sources-regulation-notation'), which contains all sources used for this section.