TILT: A GDPR-Aligned Transparency Information Language and Toolkit for Practical Privacy Engineering

12/18/2020
by   Elias Grünewald, et al.
0

In this paper, we present TILT, a transparency information language and toolkit explicitly designed to represent and process transparency information in line with the requirements of the GDPR and allowing for a more automated and adaptive use of such information than established, legalese data protection policies do. We provide a detailed analysis of transparency obligations from the GDPR to identify the expressiveness required for a formal transparency language intended to meet respective legal requirements. In addition, we identify a set of further, non-functional requirements that need to be met to foster practical adoption in real-world (web) information systems engineering. On this basis, we specify our formal language and present a respective, fully implemented toolkit around it. We then evaluate the practical applicability of our language and toolkit and demonstrate the additional prospects it unlocks through two different use cases: a) the inter-organizational analysis of personal data-related practices allowing, for instance, to uncover data sharing networks based on explicitly announced transparency information and b) the presentation of formally represented transparency information to users through novel, more comprehensible, and potentially adaptive user interfaces, heightening data subjects' actual informedness about data-related practices and, thus, their sovereignty. Altogether, our transparency information language and toolkit allow - differently from previous work - to express transparency information in line with actual legal requirements and practices of modern (web) information systems engineering and thereby pave the way for a multitude of novel possibilities to heighten transparency and user sovereignty in practice.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
02/21/2023

Enabling Versatile Privacy Interfaces Using Machine-Readable Transparency Information

Transparency regarding the processing of personal data in online service...
research
06/04/2023

Hawk: DevOps-driven Transparency and Accountability in Cloud Native Systems

Transparency is one of the most important principles of modern privacy r...
research
03/19/2021

Trustworthy Transparency by Design

Individuals lack oversight over systems that process their data. This ca...
research
09/01/2023

Towards Cross-Provider Analysis of Transparency Information for Data Protection

Transparency and accountability are indispensable principles for modern ...
research
07/05/2023

A design theory for transparency of information privacy practices

The rising diffusion of information systems (IS) throughout society pose...
research
12/06/2019

An Algorithmic Equity Toolkit for Technology Audits by Community Advocates and Activists

A wave of recent scholarship documenting the discriminatory harms of alg...
research
12/07/2021

Datensouveränität für Verbraucher:innen: Technische Ansätze durch KI-basierte Transparenz und Auskunft im Kontext der DSGVO

A sufficient level of data sovereignty is extremely difficult for consum...

Please sign up or login with your details

Forgot password? Click here to reset