Analyzing GDPR Compliance Through the Lens of Privacy Policy

06/28/2019
by   Jayashree Mohan, et al.
0

With the arrival of the European Union's General Data Protection Regulation (GDPR), several companies are making significant changes to their systems to achieve compliance. The changes range from modifying privacy policies to redesigning systems which process personal data. This work analyzes the privacy policies of large-scaled cloud services which seek to be GDPR compliant. The privacy policy is the main medium of information dissemination between the data controller and the users. We show that many services that claim compliance today do not have clear and concise privacy policies. We identify several points in the privacy policies which potentially indicate non-compliance; we term these GDPR vulnerabilities. We identify GDPR vulnerabilities in ten cloud services. Based on our analysis, we propose seven best practices for crafting GDPR privacy policies.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
11/08/2021

Automated Detection of GDPR Disclosure Requirements in Privacy Policies using Deep Active Learning

Since GDPR came into force in May 2018, companies have worked on their d...
research
02/21/2021

Detecting Compliance of Privacy Policies with Data Protection Laws

Privacy Policies are the legal documents that describe the practices tha...
research
12/09/2020

PrivFramework: A System for Configurable and Automated Privacy Policy Compliance

Today's massive scale of data collection coupled with recent surges of c...
research
03/09/2019

Analyzing the Impact of GDPR on Storage Systems

The recently introduced General Data Protection Regulation (GDPR) is for...
research
01/08/2019

Designing Data Protection for GDPR Compliance into IoT Healthcare Systems

In this paper, we investigate the implications of the General Data Priva...
research
09/28/2018

A SwarmESB Based Architecture for an European Healthcare Insurance System in Compliance with GDPR

With the everlasting development of technology and society, data privacy...
research
02/27/2022

Associating eHealth Policies and National Data Privacy Regulations

As electronic data becomes the lifeline of modern society, privacy conce...

Please sign up or login with your details

Forgot password? Click here to reset