AI-enabled Automation for Completeness Checking of Privacy Policies

06/10/2021
by   Orlando Amaral, et al.
0

Technological advances in information sharing have raised concerns about data protection. Privacy policies contain privacy-related requirements about how the personal data of individuals will be handled by an organization or a software system (e.g., a web service or an app). In Europe, privacy policies are subject to compliance with the General Data Protection Regulation (GDPR). A prerequisite for GDPR compliance checking is to verify whether the content of a privacy policy is complete according to the provisions of GDPR. Incomplete privacy policies might result in large fines on violating organization as well as incomplete privacy-related software specifications. Manual completeness checking is both time-consuming and error-prone. In this paper, we propose AI-based automation for the completeness checking of privacy policies. Through systematic qualitative methods, we first build two artifacts to characterize the privacy-related provisions of GDPR, namely a conceptual model and a set of completeness criteria. Then, we develop an automated solution on top of these artifacts by leveraging a combination of natural language processing and supervised machine learning. Specifically, we identify the GDPR-relevant information content in privacy policies and subsequently check them against the completeness criteria. To evaluate our approach, we collected 234 real privacy policies from the fund industry. Over a set of 48 unseen privacy policies, our approach detected 300 of the total of 334 violations of some completeness criteria correctly, while producing 23 false positives. The approach thus has a precision of 92.9 keyword search only, our approach results in an improvement of 24.5 precision and 38

READ FULL TEXT

page 7

page 12

page 13

research
09/20/2022

NLP-based Automated Compliance Checking of Data Processing Agreements against GDPR

Processing personal data is regulated in Europe by the General Data Prot...
research
04/05/2023

The Saudi Privacy Policy Dataset

This paper introduces the Saudi Privacy Policy Dataset, a diverse compil...
research
12/09/2020

PrivFramework: A System for Configurable and Automated Privacy Policy Compliance

Today's massive scale of data collection coupled with recent surges of c...
research
08/29/2022

NL2GDPR: Automatically Develop GDPR Compliant Android Application Features from Natural Language

The recent privacy leakage incidences and the more strict policy regulat...
research
07/23/2020

Model Driven Engineering for Data Protection and Privacy: Application and Experience with GDPR

In Europe and indeed worldwide, the General Data Protection Regulation (...
research
11/03/2020

Investigating the automation of building permit checks through 3D GeoBIM information

The automation of building permits has great relevance within the worldw...
research
01/16/2020

Fast Compliance Checking with General Vocabularies

We address the problem of complying with the GDPR while processing and t...

Please sign up or login with your details

Forgot password? Click here to reset