Encoding Privacy Principles
The DEPA framework encodes most of the privacy principles that run through most privacy regulations into the framework of data transfers. However, while it solves the questions of notice, consent and purpose limitation, once the data is in the possession of the transferee, the traditional DEPA framework has no control over what is subsequently done with it. This means that it will no address issues of use restriction, data minimisation and retention limitation. If we can integrate into the traditional DEPA framework the concept of Confidential Clean Rooms we should be able to address these remaining privacy principles as well.
