Exploring Automated GDPR-Compliance in Requirements Engineering: A Systematic Mapping Study

被引:14
作者
Aberkane, Abdel-Jaouad [1 ]
Poels, Geert [1 ]
Broucke, Seppe Vanden [1 ]
机构
[1] Univ Ghent, Fac Econ & Business Adm, Business Informat Res Grp, B-9000 Ghent, Belgium
关键词
Systematics; Natural language processing; General Data Protection Regulation; Unified modeling language; Bibliographies; Software systems; Regulation; General data protection regulation; systematic mapping study; requirements engineering; natural language processing;
D O I
10.1109/ACCESS.2021.3076921
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The General Data Protection Regulation (GDPR), adopted in 2018, profoundly impacts information processing organizations as they must comply with this regulation. In this research, we consider GDPR-compliance as a high-level goal in software development that should be addressed at the outset of software development, meaning during requirements engineering (RE). In this work, we hypothesize that natural language processing (NLP) can offer a viable means to automate this process. We conducted a systematic mapping study to explore the existing literature on the intersection of GDPR, NLP, and RE. As a result, we identified 448 relevant studies, of which the majority (420) were related to NLP and RE. Research on the intersection of GDPR and NLP yielded nine studies, while 20 studies were related to GDPR and RE. Even though only one study was identified on the convergence of GDPR, NLP, and RE, the mapping results indicate opportunities for bridging the gap between these fields. In particular, we identified possibilities for introducing NLP techniques to automate manual RE tasks in the crossing of GDPR and RE, in addition to possibilities of using NLP-based machine learning techniques to achieve GDPR-compliance in RE.
引用
收藏
页码:66542 / 66559
页数:18
相关论文
共 72 条
[11]  
Bartolini C., 2019, CCIS, V1010, P3, DOI DOI 10.1007/978-3-030
[12]  
Batista-Navarro, 2020, ARXIV200401099
[13]  
Blohm M., 2019, P 21 INT C ENT INF S, V1, P442
[14]   Lessons from applying the systematic literature review process within the software engineering domain [J].
Brereton, Pearl ;
Kitchenham, Barbara A. ;
Budgen, David ;
Turner, Mark ;
Khalil, Mohamed .
JOURNAL OF SYSTEMS AND SOFTWARE, 2007, 80 (04) :571-583
[15]  
Budgen D., 2008, In Psychology of Programming Interest Group, P195, DOI DOI 10.1007/978-3-642-02152-7_36
[16]   Automated and Personalized Privacy Policy Extraction Under GDPR Consideration [J].
Chang, Cheng ;
Li, Huaxin ;
Zhang, Yichi ;
Du, Suguo ;
Cao, Hui ;
Zhu, Haojin .
WIRELESS ALGORITHMS, SYSTEMS, AND APPLICATIONS, WASA 2019, 2019, 11604 :43-54
[17]   Tool-supporting Data Protection Impact Assessments with CAIRIS [J].
Coles, Joshua ;
Faily, Shamal ;
Ki-Aries, Duncan .
2018 IEEE 5TH INTERNATIONAL WORKSHOP ON EVOLVING SECURITY & PRIVACY REQUIREMENTS ENGINEERING (ESPRE 2018), 2018, :21-27
[18]   Designing a Data Protection Process Assessment Model Based on the GDPR [J].
Cortina, Stephane ;
Valoggia, Philippe ;
Barafort, Beatrix ;
Renault, Alain .
SYSTEMS, SOFTWARE AND SERVICES PROCESS IMPROVEMENT (EUROSPI 2019), 2019, 1060 :136-148
[19]   Agile Requirements Engineering with User Stories [J].
Dalpiaz, Fabiano ;
Brinkkemper, Sjaak .
2018 IEEE 26TH INTERNATIONAL REQUIREMENTS ENGINEERING CONFERENCE (RE 2018), 2018, :506-507
[20]   Natural Language Processing for Requirements Engineering The Best Is Yet to Come [J].
Dalpiaz, Fabiano ;
Ferrari, Alessio ;
Franch, Xavier ;
Palomares, Cristina .
IEEE SOFTWARE, 2018, 35 (05) :115-119