The rapid proliferation of Application Programming Interfaces (APIs) enhances data exchange. Still, it introduces significant privacy and security risks, especially in the Internet of Things (IoT), where APIs often lack mechanisms to manage privacy and security, leading to vulnerabilities. Hippocratic Databases (HDBs) provide mechanisms, e.g., purpose-based access, to control database use. However, to effectively manage data access to the HDB, proper API design is crucial. This paper proposes a conceptual framework for a Hippocratic API (HAPI), revising traditional API design aiming to protect data subjects’ rights and enhance security. By embedding data protection and ethical standards into API operations, HAPIs rectify inadequacies in consent mechanisms and mitigate privacy risks. We identify non-functional requirements, design objectives, and techniques through extensive research of recent literature, informed by the ethical principles of the GDPR, ISO/IEC 27001, and HDBs. We present our findings by knowledge graphs, providing a comprehensive conceptual view of the relevant design knowledge.
