Model Driven Engineering for Data Protection and Privacy: Application and Experience with GDPR

07/23/2020
by   Damiano Torre, et al.
0

In Europe and indeed worldwide, the General Data Protection Regulation (GDPR) provides protection to individuals regarding their personal data in the face of new technological developments. GDPR is widely viewed as the benchmark for data protection and privacy regulations that harmonizes data privacy laws across Europe. Although the GDPR is highly beneficial to individuals, it presents significant challenges for organizations monitoring or storing personal information. Since there is currently no automated solution with broad industrial applicability, organizations have no choice but to carry out expensive manual audits to ensure GDPR compliance. In this paper, we present a complete GDPR UML model as a first step towards designing automated methods for checking GDPR compliance. Given that the practical application of the GDPR is influenced by national laws of the EU Member States, we suggest a two-tiered description of the GDPR, generic and specialized. In this paper, we provide (1) the GDPR conceptual model we developed with complete traceability from its classes to the GDPR, (2) a glossary to help understand the model, (3) the plain-English description of 35 compliance rules derived from GDPR along with their encoding in OCL, and (4) the set of 20 variations points derived from GDPR to specialize the generic model. We further present the challenges we faced in our modeling endeavor, the lessons we learned from it, and future directions for research.

READ FULL TEXT

page 6

page 22

research
02/17/2020

GDPR Compliance in the Context of Continuous Integration

The enactment of the General Data Protection Regulation (GDPR) in 2018 f...
research
12/23/2020

Compliance Generation for Privacy Documents under GDPR: A Roadmap for Implementing Automation and Machine Learning

Most prominent research today addresses compliance with data protection ...
research
08/22/2018

Are we there yet? Understanding the challenges faced in complying with the General Data Protection Regulation (GDPR)

The EU General Data Protection Regulation (GDPR), enforced from 25th May...
research
06/10/2021

AI-enabled Automation for Completeness Checking of Privacy Policies

Technological advances in information sharing have raised concerns about...
research
07/08/2023

Right to be Forgotten in the Era of Large Language Models: Implications, Challenges, and Solutions

The Right to be Forgotten (RTBF) was first established as the result of ...
research
12/08/2020

Class Clown: Data Redaction in Machine Unlearning at Enterprise Scale

Individuals are gaining more control of their personal data through rece...
research
03/22/2020

Annotation-Based Static Analysis for Personal Data Protection

This paper elaborates the use of static source code analysis in the cont...

Please sign up or login with your details

Forgot password? Click here to reset