{"id":{"repo_id":"trento","oai_identifier":"oai:iris.unitn.it:11572/450692"},"canonical_url":"https://search.dev.ndltd.org/etd/trento/oai:iris.unitn.it:11572/450692","repository":{"repo_id":"trento","name":"Università degli Studi di Trento","base_url":"https://iris.unitn.it/oai/request"},"display":{"title":"Privacy in the small","abstract":"The advent of the General Data Protection Regulation (GDPR) and analogous global data protection laws has profoundly influenced organizations' socio-technical structures, mandating compliance with stringent personal data processing standards. These laws compel entities to critically understand their socio-technical systems, encompassing the complex interplay between legal, managerial, and technical components. This thesis addresses the challenge of ensuring compliance through empirical methodologies and field studies, enhancing both theoretical understanding and practical application. Chapter 2 explores the multifaceted role of Data Protection Officers (DPOs) as mediators between compliance auditors and organizational management. It highlights the tension inherent in their dual role and the socio-technical risks DPOs navigate in diverse operational contexts. Chapter 3 focuses on user understanding of privacy policies across linguistic boundaries, proposing a methodology for creating cross-language comparable corpora. Using English and Italian privacy policies, it showcases how language and cultural adaptations influence user comprehension of technical terms and offers a replicable approach for cross-language research. Chapter 4 extends this work by refining tools for analyzing cross-language privacy policies. By mapping technical terms and assessing their frequency and relevance, it identifies the limitations of automated methods and underscores the importance of manual intervention for nuanced cross-lingual analyses. Chapter 5 examines GDPR implementation in resource-constrained settings, such as schools, revealing gaps between theoretical compliance and practical execution. A risk-based approach is proposed, advocating feasible and continuously improvable data protection practices over rigid adherence to legal stipulations. The conclusions (Chapter 6) summarizes the findings for cross-language privacy research and practical insights for improving compliance in socio-technical systems.","abstract_html":"The advent of the General Data Protection Regulation (GDPR) and analogous global data protection laws has profoundly influenced organizations&#x27; socio-technical structures, mandating compliance with stringent personal data processing standards. These laws compel entities to critically understand their socio-technical systems, encompassing the complex interplay between legal, managerial, and technical components. This thesis addresses the challenge of ensuring compliance through empirical methodologies and field studies, enhancing both theoretical understanding and practical application. Chapter 2 explores the multifaceted role of Data Protection Officers (DPOs) as mediators between compliance auditors and organizational management. It highlights the tension inherent in their dual role and the socio-technical risks DPOs navigate in diverse operational contexts. Chapter 3 focuses on user understanding of privacy policies across linguistic boundaries, proposing a methodology for creating cross-language comparable corpora. Using English and Italian privacy policies, it showcases how language and cultural adaptations influence user comprehension of technical terms and offers a replicable approach for cross-language research. Chapter 4 extends this work by refining tools for analyzing cross-language privacy policies. By mapping technical terms and assessing their frequency and relevance, it identifies the limitations of automated methods and underscores the importance of manual intervention for nuanced cross-lingual analyses. Chapter 5 examines GDPR implementation in resource-constrained settings, such as schools, revealing gaps between theoretical compliance and practical execution. A risk-based approach is proposed, advocating feasible and continuously improvable data protection practices over rigid adherence to legal stipulations. The conclusions (Chapter 6) summarizes the findings for cross-language privacy research and practical insights for improving compliance in socio-technical systems.","abstract_has_math":false,"creators":["Ciclosi, Francesco"],"institution":"Università degli studi di Trento","degree_name":null,"degree_level":null,"degree_discipline":null,"degree_department":null,"school":null,"contributors":["Massacci, Fabio","Varni, Giovanna Paola"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2025,"date_issued":"2025-04-14","date_published":"2025-04-14","updated_at":"2026-07-24T05:04:45Z","subjects":["Field Study","GDPR","Privacy procedures","Privacy violations","Usable privacy","Studi di campo","Procedure di privacy","Violazioni privacy","Privacy fruibile","Settore ING-INF/05 - Sistemi di Elaborazione delle Informazioni","Settore IINF-05/A - Sistemi di elaborazione delle informazioni"],"languages":["eng"],"rights":["info:eu-repo/semantics/openAccess","license:Tutti i diritti riservati (All rights reserved)","license uri:iris.PRI01"],"rights_urls":[],"identifier_entries":[{"key":"dc:identifier","label":"Identifier","values":["http://dx.doi.org/10.15168/11572_450692","10.15168/11572_450692"],"render_values":[{"text":"http://dx.doi.org/10.15168/11572_450692","href":"http://dx.doi.org/10.15168/11572_450692","code":true},{"text":"10.15168/11572_450692","href":"https://doi.org/10.15168/11572_450692","code":true}]}]},"links":{"outbound_url":"https://hdl.handle.net/11572/450692","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Ciclosi, Francesco","Massacci, Fabio","Varni, Giovanna Paola"]},{"key":"dc:creator","label":"Author","values":["Ciclosi, Francesco"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2025-04-14"]},{"key":"dc:publisher","label":"Institution","values":["Università degli studi di Trento","place:TRENTO"]},{"key":"dc:relation","label":"Dc Relation","values":["firstpage:1","lastpage:272","numberofpages:272"]},{"key":"dc:type","label":"Dc Type","values":["info:eu-repo/semantics/doctoralThesis"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Field Study","GDPR","Privacy procedures","Privacy violations","Usable privacy","Studi di campo","Procedure di privacy","Violazioni privacy","Privacy fruibile","Settore ING-INF/05 - Sistemi di Elaborazione delle Informazioni","Settore IINF-05/A - Sistemi di elaborazione delle informazioni"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["eng"]},{"key":"dc:rights","label":"Dc Rights","values":["info:eu-repo/semantics/openAccess","license:Tutti i diritti riservati (All rights reserved)","license uri:iris.PRI01"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["https://hdl.handle.net/11572/450692","http://dx.doi.org/10.15168/11572_450692","10.15168/11572_450692"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["The advent of the General Data Protection Regulation (GDPR) and analogous global data protection laws has profoundly influenced organizations' socio-technical structures, mandating compliance with stringent personal data processing standards. These laws compel entities to critically understand their socio-technical systems, encompassing the complex interplay between legal, managerial, and technical components. This thesis addresses the challenge of ensuring compliance through empirical methodologies and field studies, enhancing both theoretical understanding and practical application. Chapter 2 explores the multifaceted role of Data Protection Officers (DPOs) as mediators between compliance auditors and organizational management. It highlights the tension inherent in their dual role and the socio-technical risks DPOs navigate in diverse operational contexts. Chapter 3 focuses on user understanding of privacy policies across linguistic boundaries, proposing a methodology for creating cross-language comparable corpora. Using English and Italian privacy policies, it showcases how language and cultural adaptations influence user comprehension of technical terms and offers a replicable approach for cross-language research. Chapter 4 extends this work by refining tools for analyzing cross-language privacy policies. By mapping technical terms and assessing their frequency and relevance, it identifies the limitations of automated methods and underscores the importance of manual intervention for nuanced cross-lingual analyses. Chapter 5 examines GDPR implementation in resource-constrained settings, such as schools, revealing gaps between theoretical compliance and practical execution. A risk-based approach is proposed, advocating feasible and continuously improvable data protection practices over rigid adherence to legal stipulations. The conclusions (Chapter 6) summarizes the findings for cross-language privacy research and practical insights for improving compliance in socio-technical systems."]},{"key":"dc:title","label":"Title","values":["Privacy in the small"]}]}],"canonical_facts":{"dc:contributor":["Ciclosi, Francesco","Massacci, Fabio","Varni, Giovanna Paola"],"dc:creator":["Ciclosi, Francesco"],"dc:date":["2025-04-14"],"dc:description":["The advent of the General Data Protection Regulation (GDPR) and analogous global data protection laws has profoundly influenced organizations' socio-technical structures, mandating compliance with stringent personal data processing standards. These laws compel entities to critically understand their socio-technical systems, encompassing the complex interplay between legal, managerial, and technical components. This thesis addresses the challenge of ensuring compliance through empirical methodologies and field studies, enhancing both theoretical understanding and practical application. Chapter 2 explores the multifaceted role of Data Protection Officers (DPOs) as mediators between compliance auditors and organizational management. It highlights the tension inherent in their dual role and the socio-technical risks DPOs navigate in diverse operational contexts. Chapter 3 focuses on user understanding of privacy policies across linguistic boundaries, proposing a methodology for creating cross-language comparable corpora. Using English and Italian privacy policies, it showcases how language and cultural adaptations influence user comprehension of technical terms and offers a replicable approach for cross-language research. Chapter 4 extends this work by refining tools for analyzing cross-language privacy policies. By mapping technical terms and assessing their frequency and relevance, it identifies the limitations of automated methods and underscores the importance of manual intervention for nuanced cross-lingual analyses. Chapter 5 examines GDPR implementation in resource-constrained settings, such as schools, revealing gaps between theoretical compliance and practical execution. A risk-based approach is proposed, advocating feasible and continuously improvable data protection practices over rigid adherence to legal stipulations. The conclusions (Chapter 6) summarizes the findings for cross-language privacy research and practical insights for improving compliance in socio-technical systems."],"dc:identifier":["https://hdl.handle.net/11572/450692","http://dx.doi.org/10.15168/11572_450692","10.15168/11572_450692"],"dc:language":["eng"],"dc:publisher":["Università degli studi di Trento","place:TRENTO"],"dc:relation":["firstpage:1","lastpage:272","numberofpages:272"],"dc:rights":["info:eu-repo/semantics/openAccess","license:Tutti i diritti riservati (All rights reserved)","license uri:iris.PRI01"],"dc:subject":["Field Study","GDPR","Privacy procedures","Privacy violations","Usable privacy","Studi di campo","Procedure di privacy","Violazioni privacy","Privacy fruibile","Settore ING-INF/05 - Sistemi di Elaborazione delle Informazioni","Settore IINF-05/A - Sistemi di elaborazione delle informazioni"],"dc:title":["Privacy in the small"],"dc:type":["info:eu-repo/semantics/doctoralThesis"]},"updated_at":"2026-07-24T05:04:45Z"}