Helping Software Architects Familiarize with the General Data Protection Regulation

被引:5
作者
Colesky, Michael [1 ]
Demetzou, Katerina [1 ]
Fritsch, Lothar [2 ]
Herold, Sebastian [2 ]
机构
[1] Radboud Univ Nijmegen, Nijmegen, Netherlands
[2] Karlstad Univ, Karlstad, Sweden
来源
2019 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE ARCHITECTURE COMPANION (ICSA-C 2019) | 2019年
关键词
software architecture; data privacy; decision support systems; design decisions;
D O I
10.1109/ICSA-C.2019.00046
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The General Data Protection Regulation (GDPR) impacts any information systems that process personal data in or from the European Union. Yet its enforcement is still recent. Organizations under its effect are slow to adopt its principles. One particular difficulty is the low familiarity with the regulation among software architects and designers. The difficulty to interpret the content of the legal regulation at a technical level adds to that. This results in problems in understanding the impact and consequences that the regulation may have in detail for a particular system or project context. In this paper we present some early work and emerging results related to supporting software architects in this situation. Specifically, we target those who need to understand how the GDPR might impact their design decisions. In the spirit of architectural tactics and patterns, we systematically identified and categorized 155 forces in the regulation. These results form the conceptual base for a first prototypical tool. It enables software architects to identify the relevant forces by guiding them through an online questionnaire. This leads them to relevant fragments of the GDPR and potentially relevant privacy patterns. We argue that this approach may help software professionals, in particular architects, familiarize with the GDPR and outline potential paths for evaluation.
引用
收藏
页码:226 / 229
页数:4
相关论文
共 13 条
[1]  
[Anonymous], 1996, Pattern-Oriented Software Architecture, Volume 1: A System of Patterns
[2]  
[Anonymous], 2014, TECH REP
[3]  
[Anonymous], 2010, Tech.rep
[4]  
Bass L, 2012, EDUC LEADER SOC JUST, P39
[5]  
Bier C, 2012, 2012 7TH INTERNATIONAL CONFERENCE ON COMPUTING AND CONVERGENCE TECHNOLOGY (ICCCT2012), P610
[6]  
Cavoukian A., 2009, Tech. Rep.
[7]  
European Parliament and Council of the European Union, 2015, OFFICIAL J EUROPEAN, V119
[8]   Privacy by designers: software developers' privacy mindset [J].
Hadar, Irit ;
Hasson, Tomer ;
Ayalon, Oshrat ;
Toch, Eran ;
Birnhack, Michael ;
Sherman, Sofia ;
Balissa, Arod .
EMPIRICAL SOFTWARE ENGINEERING, 2018, 23 (01) :259-289
[9]  
Hoepman JH, 2014, IFIP ADV INF COMM TE, V428, P446
[10]   A Literature Study on Privacy Patterns Research [J].
Lenhard, Jorg ;
Fritsch, Lothar ;
Herold, Sebastian .
2017 43RD EUROMICRO CONFERENCE ON SOFTWARE ENGINEERING AND ADVANCED APPLICATIONS (SEAA), 2017, :194-200