DPMF: A Modeling Framework for Data Protection by Design

Laurens Sion, Pierre Dewitte, D. Landuyt, Kim Wuyts, P. Valcke, W. Joosen
{"title":"DPMF: A Modeling Framework for Data Protection by Design","authors":"Laurens Sion, Pierre Dewitte, D. Landuyt, Kim Wuyts, P. Valcke, W. Joosen","doi":"10.18417/EMISA.15.10","DOIUrl":null,"url":null,"abstract":"Building software-intensive systems that respect the fundamental rights to privacy and data protection requires explicitly addressing data protection issues at the early development stages. Data Protection by Design (DPbD)—as coined by Article 25(1) of the General Data Protection Regulation (GDPR)—therefore calls for an iterative approach based on (i) the notion of risk to data subjects, (ii) a close collaboration between the involved stakeholders and (iii) accountable decision-making. \nIn practice, however, the legal reasoning behind DPbD is often conducted on the basis of informal system descriptions that lack systematicity and reproducibility. This affects the quality of Data Protection Impact Assessments (DPIA)—i.e. the concrete manifestation of DPbD at the organizational level. This is a major stumbling block when it comes to conducting a comprehensive and durable assessment of the risks that takes both the legal and technical complexities into account. In this article, we present DPMF, a data protection modeling framework that allows for a comprehensive and accurate description of the data processing operations in terms of the key concepts used in the GDPR. \nThe proposed modeling approach supports the automation of a number of legal reasonings and compliance assessments (e.g., purpose compatibility) that are commonly addressed in a DPIA exercise and this support is strongly rooted upon the system description models. The DPMF is supported in a prototype modeling tool and its practical applicability is validated in the context of a realistic e-health system for a number of complementary development scenarios.","PeriodicalId":186216,"journal":{"name":"Enterp. Model. Inf. Syst. Archit. Int. J. Concept. Model.","volume":"15 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-11-26","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Enterp. Model. Inf. Syst. Archit. Int. J. Concept. Model.","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.18417/EMISA.15.10","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

Abstract

Building software-intensive systems that respect the fundamental rights to privacy and data protection requires explicitly addressing data protection issues at the early development stages. Data Protection by Design (DPbD)—as coined by Article 25(1) of the General Data Protection Regulation (GDPR)—therefore calls for an iterative approach based on (i) the notion of risk to data subjects, (ii) a close collaboration between the involved stakeholders and (iii) accountable decision-making. In practice, however, the legal reasoning behind DPbD is often conducted on the basis of informal system descriptions that lack systematicity and reproducibility. This affects the quality of Data Protection Impact Assessments (DPIA)—i.e. the concrete manifestation of DPbD at the organizational level. This is a major stumbling block when it comes to conducting a comprehensive and durable assessment of the risks that takes both the legal and technical complexities into account. In this article, we present DPMF, a data protection modeling framework that allows for a comprehensive and accurate description of the data processing operations in terms of the key concepts used in the GDPR. The proposed modeling approach supports the automation of a number of legal reasonings and compliance assessments (e.g., purpose compatibility) that are commonly addressed in a DPIA exercise and this support is strongly rooted upon the system description models. The DPMF is supported in a prototype modeling tool and its practical applicability is validated in the context of a realistic e-health system for a number of complementary development scenarios.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
DPMF:设计数据保护的建模框架
构建尊重隐私权和数据保护基本权利的软件密集型系统需要在早期开发阶段明确解决数据保护问题。因此,《通用数据保护条例》(GDPR)第25(1)条所创造的数据保护设计(DPbD)要求基于(i)数据主体风险的概念,(ii)相关利益相关者之间的密切合作以及(iii)负责任的决策的迭代方法。然而,在实践中,DPbD背后的法律推理往往是在缺乏系统性和可重复性的非正式系统描述的基础上进行的。这会影响数据保护影响评估(DPIA)的质量。DPbD在组织层面的具体表现。当涉及到对风险进行全面和持久的评估,同时考虑到法律和技术的复杂性时,这是一个主要的绊脚石。在本文中,我们介绍了DPMF,这是一个数据保护建模框架,可以根据GDPR中使用的关键概念全面准确地描述数据处理操作。建议的建模方法支持在DPIA实践中通常处理的许多法律推理和遵从性评估(例如,目的兼容性)的自动化,并且这种支持强烈地植根于系统描述模型。DPMF在原型建模工具中得到支持,其实际适用性在许多互补开发方案的现实电子卫生系统中得到验证。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Catchword: Blockchains and Enterprise Modeling Decentralized Business Process Control using Blockchain An experience report from two applications: Food Supply Chain and Car Registration Balancing Patient Care and Paperwork Automatic Task Enactment and Comprehensive Documentation in Treatment Processes Process Modeling in Decentralized Organizations Utilizing Blockchain Consensus Blockchain Technologies in Enterprise Modeling and Enterprise Information Systems
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1