Privacy, security, legal and technology acceptance elicited and consolidated requirements for a GDPR compliance platform

被引:10
|
作者
Tsohou, Aggeliki [1 ]
Magkos, Emmanouil [1 ]
Mouratidis, Haralambos [2 ]
Chrysoloras, George [3 ]
Piras, Luca [2 ]
Pavlidis, Michalis [2 ]
Debussche, Julien [4 ]
Rotoloni, Marco [5 ]
Crespo, Beatriz Gallego-Nicasio [6 ]
机构
[1] Ionian Univ, Dept Informat, Corfu, Greece
[2] Univ Brighton, Sch Comp Engn & Math, Brighton, E Sussex, England
[3] Univ Aegean, Sch Sci, Samos, Greece
[4] Bird & Bird Belgium, Brussels, Belgium
[5] AbiLab Ctr Ric & Innovaz Banca, Rome, Italy
[6] ATOS, Madrid, Spain
基金
欧盟地平线“2020”;
关键词
Compliance; Consolidation; GDPR; Software requirements; Prioritization;
D O I
10.1108/ICS-01-2020-0002
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Purpose General data protection regulation (GDPR) entered into force in May 2018 for enhancing personal data protection. Even though GDPR leads toward many advantages for the data subjects it turned out to be a significant challenge. Organizations need to implement long and complex changes to become GDPR compliant. Data subjects are empowered with new rights, which, however, they need to become aware of. GDPR compliance is a challenging matter for the relevant stakeholders calls for a software platform that can support their needs. The aim of data governance for supporting GDPR (DEFeND) EU project is to deliver such a platform. The purpose of this paper is to describe the process, within the DEFeND EU project, for eliciting and analyzing requirements for such a complex platform. Design/methodology/approach The platform needs to satisfy legal and privacy requirements and provide functionalities that data controllers request for supporting GDPR compliance. Further, it needs to satisfy acceptance requirements, for assuring that its users will embrace and use the platform. In this paper, the authors describe the methodology for eliciting and analyzing requirements for such a complex platform, by analyzing data attained by stakeholders from different sectors. Findings The findings provide the process for the DEFeND platform requirements' elicitation and an indicative sample of those. The authors also describe the implementation of a secondary process for consolidating the elicited requirements into a consistent set of platform requirements. Practical implications The proposed software engineering methodology and data collection tools (i.e. questionnaires) are expected to have a significant impact for software engineers in academia and industry. Social implications It is reported repeatedly that data controllers face difficulties in complying with the GDPR. The study aims to offer mechanisms and tools that can assist organizations to comply with the GDPR, thus, offering a significant boost toward the European personal data protection objectives. Originality/value This is the first paper, according to the best of the authors' knowledge, to provide software requirements for a GDPR compliance platform, including multiple perspectives.
引用
收藏
页码:531 / 553
页数:23
相关论文
共 26 条
  • [1] Privacy, Security, Legal and Technology Acceptance Requirements for a GDPR Compliance Platform
    Tsohou, Aggeliki
    Magkos, Manos
    Mouratidis, Haralambos
    Chrysoloras, George
    Piras, Luca
    Pavlidis, Michalis
    Debussche, Julien
    Rotoloni, Marco
    Gallego-Nicasio Crespo, Beatriz
    COMPUTER SECURITY, ESORICS 2019, 2020, 11980 : 204 - 223
  • [2] Evaluating existing security and privacy requirements for legal compliance
    Aaron K. Massey
    Paul N. Otto
    Lauren J. Hayward
    Annie I. Antón
    Requirements Engineering, 2010, 15 : 119 - 137
  • [3] Evaluating existing security and privacy requirements for legal compliance
    Massey, Aaron K.
    Otto, Paul N.
    Hayward, Lauren J.
    Anton, Annie I.
    REQUIREMENTS ENGINEERING, 2010, 15 (01) : 119 - 137
  • [4] Privacy Implication and Technical Requirements Toward GDPR Compliance
    Huang, Ching-Chun
    Yuan, Zih-shiuan
    PROCEEDINGS OF THE FUTURE TECHNOLOGIES CONFERENCE (FTC) 2019, VOL 2, 2020, 1070 : 353 - 367
  • [5] A Framework for Privacy and Security Requirements Analysis and Conflict Resolution for Supporting GDPR Compliance Through Privacy-by-Design
    Alkubaisy, Duaa
    Piras, Luca
    Al-Obeidallah, Mohammed Ghazi
    Cox, Karl
    Mouratidis, Haralambos
    EVALUATION OF NOVEL APPROACHES TO SOFTWARE ENGINEERING (ENASE 2021), 2022, 1556 : 67 - 87
  • [6] DEFeND Architecture: A Privacy by Design Platform for GDPR Compliance
    Piras, Luca
    Al-Obeidallah, Mohammed Ghazi
    Praitano, Andrea
    Tsohou, Aggeliki
    Mouratidis, Haralambos
    Gallego-Nicasio Crespo, Beatriz
    Bernard, Jean Baptiste
    Fiorani, Marco
    Magkos, Emmanouil
    Castillo Sanz, Andres
    Pavlidis, Michalis
    D'Addario, Roberto
    Zorzino, Giuseppe Giovanni
    TRUST, PRIVACY AND SECURITY IN DIGITAL BUSINESS, TRUSTBUS 2019, 2019, 11711 : 78 - 93
  • [7] Smart City IoT Platform Respecting GDPR Privacy and Security Aspects
    Badii, Claudio
    Bellini, Pierfrancesco
    Difino, Angelo
    Nesi, Paolo
    IEEE ACCESS, 2020, 8 (08): : 23601 - 23623
  • [8] Operationalization of Privacy and Security Requirements for eHealth IoT Applications in the Context of GDPR and CSL
    Tomashchuk, Oleksandr
    Li, Yuan
    Van Landuyt, Dimitri
    Joosen, Wouter
    PRIVACY TECHNOLOGIES AND POLICY, APF 2020, 2020, 12121 : 143 - 160
  • [9] Developing a new technology acceptance model for smart city applications in compliance with GDPR
    Ozcagdavul, Mazlum
    Sayan, Hasan Huseyin
    INTELLIGENT BUILDINGS INTERNATIONAL, 2025,
  • [10] ConfIs: A Tool for Privacy and Security Analysis and Conflict Resolution for Supporting GDPR Compliance through Privacy-by-Design
    Alkubaisy, Duaa
    Piras, Luca
    Al-Obeidallah, Mohammed Ghazi
    Cox, Karl
    Mouratidis, Haralambos
    ENASE: PROCEEDINGS OF THE 16TH INTERNATIONAL CONFERENCE ON EVALUATION OF NOVEL APPROACHES TO SOFTWARE ENGINEERING, 2021, : 80 - 91