End-to-end privacy control in service outsourcing of human intensive processes: A multi-layered Web service integration approach

Patrick C.K. Hung*, Dickson K.W. Chiu, W. W. Fung, Kwok Wai CHEUNG, Raymond Wong, Samuel P.M. Choi, Eleanna Kafeza, James Kwok, Joshua C.C. Pun, Vivying S.Y. Cheng

*Corresponding author for this work

Research output: Contribution to journalJournal articlepeer-review

29 Citations (Scopus)


With the recent adoption of service outsourcing, there have been increasing general demands and concerns for privacy control, in addition to basic requirement of integration. The traditional practice of a bulk transmission of the customers' information to an external service provider is no longer adequate, especially in the finance and healthcare sectors. From our consultancy experience, application-to-application privacy protection technologies at the middleware layer alone are also inadequate to solve this problem, particularly when human service providers are heavily involved in the outsourced process. Therefore, we propose a layered architecture and a development methodology for enforcing end-to-end privacy control policies of enterprises over the export of personal information. We illustrate how Web services, augmented with updated privacy facilities such as Service Level Agreement (SLA), Platform for Privacy Preferences Project (P3P), and the P3P Preference Exchange Language (APPEL), can provide a suitable interoperation platform for service outsourcing. We further develop a conceptual model and an interaction protocol to send only the required part of a customer's record at a time. We illustrate our approach for end-to-end privacy control in service outsourcing with a tele-marketing case study and show how the software of the outsourced call center can be integrated effectively with the Web services of a bank to protect privacy.

Original languageEnglish
Pages (from-to)85-101
Number of pages17
JournalInformation Systems Frontiers
Issue number1
Publication statusPublished - Mar 2007

Scopus Subject Areas

  • Software
  • Theoretical Computer Science
  • Information Systems
  • Computer Networks and Communications

User-Defined Keywords

  • Layered architecture
  • Need-to-know principle
  • P3P
  • Privacy policies
  • SLA
  • Web service integration


Dive into the research topics of 'End-to-end privacy control in service outsourcing of human intensive processes: A multi-layered Web service integration approach'. Together they form a unique fingerprint.

Cite this