Paper published in a book (Scientific congresses, symposiums and conference proceedings)
CompAi: A Tool for GDPR Completeness Checking of Privacy Policies using Artificial Intelligence
AMARAL CEJAS, Orlando; ABUALHAIJA, Sallam; Briand, Lionel
2024In 39th IEEE/ACM International Conference on Automated Software Engineering (ASE 2024)
Peer reviewed
 

Files


Full Text
2024-ASE-AAB.pdf
Author postprint (2.38 MB) Creative Commons License - Attribution
Download

All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
Requirements Engineering (RE); Regulatory Compliance; Privacy; the General Data Protection Regulation (GDPR); Artificial Intelligence (AI); Natural Language Processing (NLP); Machine Learning (ML)
Abstract :
[en] We introduceπΆπ‘œπ‘šπ‘π΄πœ„ – a tool for checking the completeness of privacy policies against the general data protection regulation (GDPR). πΆπ‘œπ‘šπ‘π΄πœ„ facilitates the analysis of privacy policies to check their compliance to GDPR requirements. Since privacy policies serve as an agreement between a software system and its prospective users, the policy must fully capture such requirements to ensure that collected personal data of individuals (or users) remains protected as specified by the GDPR. For a given privacy policy, πΆπ‘œπ‘šπ‘π΄πœ„ semantically analyzes its textual content against a comprehensive conceptual model which captures all information types that might appear in any policy. Based on this analysis, alongside some input from the end user, πΆπ‘œπ‘šπ‘π΄πœ„ can determine the potential incompleteness violations in the input policy with an accuracy of β‰ˆ96%. πΆπ‘œπ‘šπ‘π΄πœ„ generates a detailed report that can be easily reviewed and validated by experts. The source code ofπΆπ‘œπ‘šπ‘π΄πœ„ is publicly available on https://figshare.com/articles/online_resource/CompAI/23676069, and a demo of the tool is available on https://youtu.be/zwa_tM3fXHU.
Research center :
Interdisciplinary Centre for Security, Reliability and Trust (SnT) > SVV - Software Verification and Validation
NCER-FT - FinTech National Centre of Excellence in Research
Disciplines :
Computer science
Author, co-author :
AMARAL CEJAS, Orlando  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > SVV
ABUALHAIJA, Sallam  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > SVV
Briand, Lionel;  Lero SFI centre for Software Research and University of Limerick, Ireland ; School of EECS, University of Ottawa, Canada
External co-authors :
yes
Language :
English
Title :
CompAi: A Tool for GDPR Completeness Checking of Privacy Policies using Artificial Intelligence
Publication date :
2024
Event name :
IEEE/ACM International Conference on Automated Software Engineering
Event date :
from October 27 to November 1 2024
Main work title :
39th IEEE/ACM International Conference on Automated Software Engineering (ASE 2024)
Publisher :
Association for Computing Machinery
Peer reviewed :
Peer reviewed
FnR Project :
FNR16570468 - 2021 (01/07/2022-30/06/2030) - Yves Le Traon
Name of the research project :
R-AGR-3718 - BRIDGES/19/IS/13759068/ARTAGO - part UL - SABETZADEH Mehrdad
U-AGR-7511 - NCER22/NCER-FT_RegCheck_UL - KLEIN Jacques
Funders :
FNR - Luxembourg National Research Fund
Funding number :
NCER22/IS/16570468/NCER-FT; BRIDGES/19/IS/13759068/ARTAGO
Available on ORBilu :
since 13 September 2024

Statistics


Number of views
251 (20 by Unilu)
Number of downloads
308 (3 by Unilu)

OpenCitations
 
0
OpenAlex citations
 
2

Bibliography


Similar publications



Contact ORBilu