Communication publiée dans un ouvrage (Colloques, congrès, conférences scientifiques et actes)
A Model-based Conceptualization of Requirements for Compliance Checking of Data Processing against GDPR
AMARAL CEJAS, Orlando; ABUALHAIJA, Sallam; SABETZADEH, Mehrdad et al.
2021In Proceedings of the 2021 IEEE 29th International Requirements Engineering Conference Workshops (REW)
Peer reviewed
 

Documents


Texte intégral
MoDRE21-AASB.pdf
Postprint Auteur (444.18 kB)
Télécharger

Tous les documents dans ORBilu sont protégés par une licence d'utilisation.

Envoyer vers



Détails



Mots-clés :
Conceptual Modeling; Qualitative Research; Regulatory Compliance; Data Processing Agreements; , General Data Protection Regulation (GDPR)
Résumé :
[en] The General Data Protection Regulation (GDPR) has been recently introduced to harmonize the different data privacy laws across Europe. Whether inside the EU or outside, organizations have to comply with the GDPR as long as they handle personal data of EU residents. The organizations with whom personal data is shared are referred to as data controllers. When controllers subcontract certain services that involve processing personal data to service providers (also known as data processors), then a data processing agreement (DPA) has to be issued. This agreement regulates the relationship between the controllers and processors and also ensures the protection of individuals’ personal data. Compliance with the GDPR is challenging for organizations since it is large and relies on complex legal concepts. In this paper, we draw on model-driven engineering to build a machine-analyzable conceptual model that characterizes DPA-related requirements in the GDPR. Further, we create a set of criteria for checking the compliance of a given DPA against the GDPR and discuss how our work in this paper can be adapted to develop an automated compliance checking solution.
Centre de recherche :
Interdisciplinary Centre for Security, Reliability and Trust (SnT) > SVV - Software Verification and Validation
Disciplines :
Sciences informatiques
Auteur, co-auteur :
AMARAL CEJAS, Orlando  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > SVV
ABUALHAIJA, Sallam  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > SVV
SABETZADEH, Mehrdad ;  School of Electrical Engineering and Computer Science > University of Ottawa
BRIAND, Lionel ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > SVV
Co-auteurs externes :
yes
Langue du document :
Anglais
Titre :
A Model-based Conceptualization of Requirements for Compliance Checking of Data Processing against GDPR
Date de publication/diffusion :
septembre 2021
Nom de la manifestation :
11th Model-Driven Requirements Engineering (MoDRE) Workshop
Date de la manifestation :
20-09-2021
Titre de l'ouvrage principal :
Proceedings of the 2021 IEEE 29th International Requirements Engineering Conference Workshops (REW)
Maison d'édition :
IEEE
Peer reviewed :
Peer reviewed
Projet FnR :
FNR13759068 - Artificial Intelligence-enabled Automation For Gdpr Compliance, 2019 (01/01/2020-31/12/2022) - Lionel Briand
Organisme subsidiant :
FNR - Fonds National de la Recherche
Disponible sur ORBilu :
depuis le 19 octobre 2021

Statistiques


Nombre de vues
401 (dont 51 Unilu)
Nombre de téléchargements
454 (dont 28 Unilu)

OpenCitations
 
2
citations OpenAlex
 
16

Bibliographie


Publications similaires



Contacter ORBilu