Hawk: DevOps-driven Transparency and Accountability in Cloud Native Systems

06/04/2023
by   Elias Grünewald, et al.
0

Transparency is one of the most important principles of modern privacy regulations, such as the GDPR or CCPA. To be compliant with such regulatory frameworks, data controllers must provide data subjects with precise information about the collection, processing, storage, and transfer of personal data. To do so, respective facts and details must be compiled and always kept up to date. In traditional, rather static system environments, this inventory (including details such as the purposes of processing or the storage duration for each system component) could be done manually. In current circumstances of agile, DevOps-driven, and cloud-native information systems engineering, however, such manual practices do not suit anymore, making it increasingly hard for data controllers to achieve regulatory compliance. To allow for proper collection and maintenance of always up-to-date transparency information smoothly integrating into DevOps practices, we herein propose a set of novel approaches explicitly tailored to specific phases of the DevOps lifecycle most relevant in matters of privacy-related transparency and accountability at runtime: Release, Operation, and Monitoring. For each of these phases, we examine the specific challenges arising in determining the details of personal data processing, develop a distinct approach and provide respective proof of concept implementations that can easily be applied in cloud native systems. We also demonstrate how these components can be integrated with each other to establish transparency information comprising design- and runtime-elements. Furthermore, our experimental evaluation indicates reasonable overheads. On this basis, data controllers can fulfill their regulatory transparency obligations in line with actual engineering practices.

READ FULL TEXT
research
12/18/2020

TILT: A GDPR-Aligned Transparency Information Language and Toolkit for Practical Privacy Engineering

In this paper, we present TILT, a transparency information language and ...
research
06/10/2021

TIRA: An OpenAPI Extension and Toolbox for GDPR Transparency in RESTful Architectures

Transparency - the provision of information about what personal data is ...
research
09/09/2022

Scalable Discovery and Continuous Inventory of Personal Data at Rest in Cloud Native Systems

Cloud native systems are processing large amounts of personal data throu...
research
07/05/2023

A design theory for transparency of information privacy practices

The rising diffusion of information systems (IS) throughout society pose...
research
09/01/2023

Towards Cross-Provider Analysis of Transparency Information for Data Protection

Transparency and accountability are indispensable principles for modern ...
research
08/02/2021

Cloud Native Privacy Engineering through DevPrivOps

Cloud native information systems engineering enables scalable and resili...
research
06/12/2021

Amplifying Privacy: Scaling Up Transparency Research Through Delegated Access Requests

In recent years, numerous studies have used 'data subject access request...

Please sign up or login with your details

Forgot password? Click here to reset