Identity and privacy in the digital age

Organisations and data subjects alike are all facing up to the new challenges of online identity and privacy. For all the activity in this field, there is still much confusion and argument over basic terms and concepts. Technologists, systems architects, business people and policy-makers, for example, all describe privacy in different and sometimes incompatible terms and yet, for any given system to work, the views of all these different stakeholders must be successfully translated into technical implementation and coherent policy enforcement. This paper sets out a simple data model to describe the different types of identity data and relates this to typical system architectures and then to privacy as an information systems policy objective. The aim is to provide a consistent framework for thinking about identity data so we can understand how privacy arises from the correct interaction of data and policy.