Privacy in Context
Doxa is built on Contextual Integrity — a framework that evaluates privacy not as a binary state, but as the appropriateness of information flows in specific contexts.
What is Contextual Integrity?
Developed by privacy scholar Helen Nissenbaum, Contextual Integrity (CI) recognizes that privacy is not about keeping information secret — it's about ensuring that information flows appropriately according to the norms of the context in which it is shared.
In healthcare, sharing patient data with a doctor is appropriate. Sharing that same data with an advertiser is not. The difference is the context, not the data itself.
The Five CI Parameters
Every privacy assessment at Doxa is structured around five parameters that define any information flow:
Subject
Whose information is being shared?
Attribute
What type of information is being shared?
Sender
Who is sending the information?
Recipient
Who is receiving the information?
Purpose
Why is the information being shared? The purpose determines whether the flow is appropriate.
How Doxa Applies CI
Every product at Doxa — from the Privacy Notice Scanner to the Privacy Impact Assessment — is built on the CI framework:
1. The Scanner
Checks if privacy notices disclose the five CI parameters correctly.
2. Notice Generation
Uses CI parameters to structure compliant privacy notices.
3. Privacy Impact Assessment
Evaluates data flows against CI norms to identify privacy risks.
Why Context Matters
Privacy laws like CCPA, GDPR, and HIPAA are built on context-specific rules. A one-size-fits-all approach to privacy fails because it ignores the context in which information flows.
Doxa's CI-based approach ensures your compliance efforts are grounded in how privacy actually works — not in generic checklists.