Real Time Reasoning in OWL2 for GDPR Compliance

01/15/2020
by   P. A. Bonatti, et al.
0

This paper shows how knowledge representation and reasoning techniques can be used to support organizations in complying with the GDPR, that is, the new European data protection regulation. This work is carried out in a European H2020 project called SPECIAL. Data usage policies, the consent of data subjects, and selected fragments of the GDPR are encoded in a fragment of OWL2 called PL (policy language); compliance checking and policy validation are reduced to subsumption checking and concept consistency checking. This work proposes a satisfactory tradeoff between the expressiveness requirements on PL posed by the GDPR, and the scalability requirements that arise from the use cases provided by SPECIAL's industrial partners. Real-time compliance checking is achieved by means of a specialized reasoner, called PLR, that leverages knowledge compilation and structural subsumption techniques. The performance of a prototype implementation of PLR is analyzed through systematic experiments, and compared with the performance of other important reasoners. Moreover, we show how PL and PLR can be extended to support richer ontologies, by means of import-by-query techniques. PL and its integration with OWL2's profiles constitute new tractable fragments of OWL2. We prove also some negative results, concerning the intractability of unrestricted reasoning in PL, and the limitations posed on ontology import.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
01/16/2020

Fast Compliance Checking with General Vocabularies

We address the problem of complying with the GDPR while processing and t...
research
01/24/2020

Machine Understandable Policies and GDPR Compliance Checking

The European General Data Protection Regulation (GDPR) calls for technic...
research
01/26/2020

The SPECIAL-K Personal Data Processing Transparency and Compliance Platform

The European General Data Protection Regulation (GDPR) brings new challe...
research
06/30/2023

An ontological approach to compliance verification of the NIS 2 directive

Cybersecurity, which notoriously concerns both human and technological a...
research
08/30/2019

Data Capsule: A New Paradigm for Automatic Compliance with Data Privacy Regulations

The increasing pace of data collection has led to increasing awareness o...
research
06/13/2022

Consent verification monitoring

Advances in service personalization are driven by low-cost data collecti...
research
11/01/2010

Reasoning about Cardinal Directions between Extended Objects: The Hardness Result

The cardinal direction calculus (CDC) proposed by Goyal and Egenhofer is...

Please sign up or login with your details

Forgot password? Click here to reset