"The Grace Period Has Ended": An Approach to Operationalize GDPR Requirements

被引:51
作者
Ayala-Rivera, Vanessa [1 ]
Pasquale, Liliana [1 ]
机构
[1] Univ Coll Dublin, Sch Comp Sci, Lero UCD, Dublin, Ireland
来源
2018 IEEE 26TH INTERNATIONAL REQUIREMENTS ENGINEERING CONFERENCE (RE 2018) | 2018年
关键词
GDPR; Compliance; Privacy; Requirements; LEGAL REQUIREMENTS;
D O I
10.1109/RE.2018.00023
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The General Data Protection Regulation (GDPR) aims to protect personal data of EU residents and can impose severe sanctions for non-compliance. Organizations are currently implementing various measures to ensure their software systems fulfill GDPR obligations such as identifying a legal basis for data processing or enforcing data anonymization. However, as regulations are formulated vaguely, it is difficult for practitioners to extract and operationalize legal requirements from the GDPR. This paper aims to help organizations understand the data protection obligations imposed by the GDPR and identify measures to ensure compliance. To achieve this goal, we propose GuideMe, a 6-step systematic approach that supports elicitation of solution requirements that link GDPR data protection obligations with the privacy controls that fulfill these obligations and that should be implemented in an organization's software system. We illustrate and evaluate our approach using an example of a university information system. Our results demonstrate that the solution requirements elicited using our approach are aligned with the recommendations of privacy experts and are expressed correctly.
引用
收藏
页码:136 / 146
页数:11
相关论文
共 24 条
  • [11] Ghanavati S, 2014, INT WORKSHOP PATTERN
  • [12] privacyTracker: A Privacy-by-Design GDPR-Compliant Framework with Verifiable Data Traceability Controls
    Gjermundrod, Harald
    Dionysiou, Ioanna
    Costa, Kyriakos
    [J]. CURRENT TRENDS IN WEB ENGINEERING, ICWE 2016 INTERNATIONAL WORKSHOPS, 2016, 9881 : 3 - 15
  • [13] Hoepman JH, 2014, IFIP ADV INF COMM TE, V428, P446
  • [14] International Institute of Business Analysis, 2014, GUID BUS AN BOD KNOW
  • [15] Koffel C., 2010, HCI PATTERN COLLECTI
  • [16] Koops Bert-Jaap., 2014, INT REV LAW COMPUTER, V28, P159, DOI DOI 10.1080/13600869.2013.801589
  • [17] Mannion M., 1995, SIGSOFT Software Engineering Notes, V20, P42, DOI 10.1145/224155.224157
  • [18] N-FOLD INSPECTION - A REQUIREMENTS ANALYSIS TECHNIQUE
    MARTIN, J
    TSAI, WT
    [J]. COMMUNICATIONS OF THE ACM, 1990, 33 (02) : 225 - 232
  • [19] Nadeau M., 2017, GDPR REQUIREMENTS DE
  • [20] Addressing legal requirements in requirements engineering
    Otto, Paul N.
    Anton, Annie I.
    [J]. 15TH IEEE INTERNATIONAL REQUIREMENTS ENGINEERING CONFERENCE, PROCEEDINGS, 2007, : 5 - +