Paper published in a book (Scientific congresses, symposiums and conference proceedings)
A Model-based Conceptualization of Requirements for Compliance Checking of Data Processing against GDPR
Amaral Cejas, Orlando; Abualhaija, Sallam; Sabetzadeh, Mehrdad et al.
2021In Proceedings of the 2021 IEEE 29th International Requirements Engineering Conference Workshops (REW)
Peer reviewed
 

Files


Full Text
MoDRE21-AASB.pdf
Author postprint (444.18 kB)
Download

All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
Conceptual Modeling; Qualitative Research; Regulatory Compliance; Data Processing Agreements; , General Data Protection Regulation (GDPR)
Abstract :
[en] The General Data Protection Regulation (GDPR) has been recently introduced to harmonize the different data privacy laws across Europe. Whether inside the EU or outside, organizations have to comply with the GDPR as long as they handle personal data of EU residents. The organizations with whom personal data is shared are referred to as data controllers. When controllers subcontract certain services that involve processing personal data to service providers (also known as data processors), then a data processing agreement (DPA) has to be issued. This agreement regulates the relationship between the controllers and processors and also ensures the protection of individuals’ personal data. Compliance with the GDPR is challenging for organizations since it is large and relies on complex legal concepts. In this paper, we draw on model-driven engineering to build a machine-analyzable conceptual model that characterizes DPA-related requirements in the GDPR. Further, we create a set of criteria for checking the compliance of a given DPA against the GDPR and discuss how our work in this paper can be adapted to develop an automated compliance checking solution.
Research center :
Interdisciplinary Centre for Security, Reliability and Trust (SnT) > SVV - Software Verification and Validation
Disciplines :
Computer science
Author, co-author :
Amaral Cejas, Orlando  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > SVV
Abualhaija, Sallam  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > SVV
Sabetzadeh, Mehrdad ;  School of Electrical Engineering and Computer Science > University of Ottawa
Briand, Lionel ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > SVV
External co-authors :
yes
Language :
English
Title :
A Model-based Conceptualization of Requirements for Compliance Checking of Data Processing against GDPR
Publication date :
September 2021
Event name :
11th Model-Driven Requirements Engineering (MoDRE) Workshop
Event date :
20-09-2021
Main work title :
Proceedings of the 2021 IEEE 29th International Requirements Engineering Conference Workshops (REW)
Publisher :
IEEE
Peer reviewed :
Peer reviewed
FnR Project :
FNR13759068 - Artificial Intelligence-enabled Automation For Gdpr Compliance, 2019 (01/01/2020-31/12/2022) - Lionel Briand
Funders :
FNR - Fonds National de la Recherche [LU]
Available on ORBilu :
since 19 October 2021

Statistics


Number of views
266 (51 by Unilu)
Number of downloads
253 (27 by Unilu)

OpenCitations
 
2

Bibliography


Similar publications



Contact ORBilu