Item type:Journal Article,

Machine Understandable Policies and GDPR Compliance Checking

Loading...
Thumbnail Image

Fulltext URI

Document type

Text/Journal Article

Additional Information

Date

Journal Title

Journal ISSN

Volume Title

Publisher

Springer

Abstract

The European General Data Protection Regulation (GDPR) calls for technical and organizational measures to support its implementation. Towards this end, the SPECIAL H2020 project aims to provide a set of tools that can be used by data controllers and processors to automatically check if personal data processing and sharing complies with the obligations set forth in the GDPR. The primary contributions of the project include: (i) a policy language that can be used to express consent, business policies, and regulatory obligations; and (ii) two different approaches to automated compliance checking that can be used to demonstrate that data processing performed by data controllers/processors complies with consent provided by data subjects, and business processes comply with regulatory obligations set forth in the GDPR.

Description

Bonatti, Piero A.; Kirrane, Sabrina; Petrova, Iliana M.; Sauro, Luigi (2020): Machine Understandable Policies and GDPR Compliance Checking. KI - Künstliche Intelligenz: Vol. 34, No. 3. DOI: 10.1007/s13218-020-00677-4. Springer. PISSN: 1610-1987. pp. 303-315

Keywords

Compliance checking, GDPR, Policies

Citation

URI

Endorsement

Review

Supplemented By

Referenced By


Number of citations to item: 36

  • Davide Basile, Claudio Di Ciccio, Valerio Goretti, Sabrina Kirrane (2023): Blockchain based resource governance for decentralized web environments, In: Frontiers in Blockchain, doi:10.3389/fbloc.2023.1141909
  • Costas Davarakis, Eva Blomqvist, Marco Tiemann, Pompeu Casanovas (2021): SPIRIT: Semantic and Systemic Interoperability for Identity Resolution in Intelligence Analysis, In: Lecture Notes in Computer Science, doi:10.1007/978-3-030-89811-3_17
  • Marco Robol, Travis D. Breaux, Elda Paja, Paolo Giorgini (2023): Consent Verification Monitoring, In: ACM Transactions on Software Engineering and Methodology 1(32), doi:10.1145/3490754
  • Yousef Taheri, Gauvain Bourgne, Jean-Gabriel Ganascia (2023): A Compliance Mechanism for Planning in Privacy Domain Using Policies, In: Lecture Notes in Computer Science, doi:10.1007/978-3-031-36190-6_6
  • Chen Zhou, Masoud Barati, Omair Shafiq (2023): A compliance-based architecture for supporting GDPR accountability in cloud computing, In: Future Generation Computer Systems, doi:10.1016/j.future.2023.03.021
  • Clement Guitton, Aurelia Tamò-Larrieux, Simon Mayer, Gijs van Dijck (2024): The challenge of open-texture in law, In: Artificial Intelligence and Law, doi:10.1007/s10506-024-09390-1
  • Ángel Jesús Varela-Vaca, María Teresa Gómez-López, Yolanda Morales Zamora, Rafael M. Gasca (2024): Business process models and simulation to enable GDPR compliance, In: International Journal of Information Security 1(24), doi:10.1007/s10207-024-00952-7
  • Kalle Hjerppe, Jukka Ruohonen, Ville Leppanen (2020): Extracting Layered Privacy Language Purposes from Web Services, In: 2020 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW), doi:10.1109/eurospw51379.2020.00050
  • Eleanor Birrell, Jay Rodolitz, Angel Ding, Jenna Lee, Emily McReynolds, Jevan Hutson, Ada Lerner (2024): SoK: Technical Implementation and Human Impact of Internet Privacy Regulations, In: 2024 IEEE Symposium on Security and Privacy (SP), doi:10.1109/sp54263.2024.00206
  • Pompeu Casanovas, Louis de Koker, Mustafa Hashmi (2022): Law, Socio-Legal Governance, the Internet of Things, and Industry 4.0: A Middle-Out/Inside-Out Approach, In: J 1(5), doi:10.3390/j5010005
  • Davit Marikyan, Jose Llanos, Masoud Barati, Gagangeet Aujla, Yinhao Li, Kwabena Adu-Duodu, Sabeen Tahir, Omer Rana, Savvas Papagiannidis, Rajiv Ranjan, Madeline Carr (2021): Privacy & Cloud Services: Are We There Yet?, In: 2021 IEEE International Conference on Service-Oriented System Engineering (SOSE), doi:10.1109/sose52839.2021.00006
  • Timotheus Kampik, Adnane Mansour, Olivier Boissier, Sabrina Kirrane, Julian Padget, Terry R. Payne, Munindar P. Singh, Valentina Tamma, Antoine Zimmermann (2022): Governance of Autonomous Agents on the Web: Challenges and Opportunities, In: ACM Transactions on Internet Technology 4(22), doi:10.1145/3507910
  • Paul Ryan, Rob Brennan (2022): Support for Enhanced GDPR Accountability with the Common Semantic Model for ROPA (CSM-ROPA), In: SN Computer Science 3(3), doi:10.1007/s42979-022-01099-9
  • Brian J. Stucky, Rob Guralnick, John Deck, Ellen G. Denny, Kjell Bolmgren, Ramona Walls (2018): The Plant Phenology Ontology: A New Informatics Resource for Large-Scale Integration of Plant Phenology Data, In: Frontiers in Plant Science, doi:10.3389/fpls.2018.00517
  • Kalle Hjerppe, Jukka Ruohonen, Ville Leppänen (2022): Extracting LPL privacy policy purposes from annotated web service source code, In: Software and Systems Modeling 1(22), doi:10.1007/s10270-022-00998-y
  • Ozioma Okonicha, Andrey Sadovykh (2025): Enhancing GDPR Compliance Through NLP: Automated Policy Evaluation and Legal Document Analysis, In: Lecture Notes in Networks and Systems, doi:10.1007/978-3-031-94770-4_34
  • Luke Slater, Georgios V. Gkoutos, Paul N. Schofield, Robert Hoehndorf (2016): Using AberOWL for fast and scalable reasoning over BioPortal ontologies, In: Journal of Biomedical Semantics 1(7), doi:10.1186/s13326-016-0090-0
  • John Licato (2024): Automated ethical reasoners must be interpretation-capable, In: Trolley Crash, doi:10.1016/b978-0-44-315991-6.00010-8
  • Tek Raj Chhetri, Anelia Kurteva, Rance J. DeLong, Rainer Hilscher, Kai Korte, Anna Fensel (2022): Data Protection by Design Tool for Automated GDPR Compliance Verification Based on Semantically Modeled Informed Consent, In: Sensors 7(22), doi:10.3390/s22072763
  • Vitor Jesus, Harshvardhan J. Pandit (2022): Consent Receipts for a Usable and Auditable Web of Personal Data, In: IEEE Access, doi:10.1109/access.2022.3157850
  • Paul Ryan, Rob Brennan, Harshvardhan J. Pandit (2022): DPCat: Specification for an Interoperable and Machine-Readable Data Processing Catalogue Based on GDPR, In: Information 5(13), doi:10.3390/info13050244
  • Orlando Amaral Cejas, Muhammad Ilyas Azeem, Sallam Abualhaija, Lionel C. Briand (2023): NLP-Based Automated Compliance Checking of Data Processing Agreements Against GDPR, In: IEEE Transactions on Software Engineering 9(49), doi:10.1109/tse.2023.3288901
  • Clement Guitton, Simon Mayer, Aurelia Tamò-Larrieux, Kimberly Garcia, Nicoletta Fornara (2024): A Proxy for Assessing the Automatic Encodability of Regulation, In: Proceedings of the Symposium on Computer Science and Law, doi:10.1145/3614407.3643697
  • Jintao Chen, Shengye Pang, Meng Xi, Tiancheng Zhao, Shuiguang Deng, Jianwei Yin (2024): Service Regulation Analysis Framework for Service Design Time: A Case Study of Internet Healthcare Service, In: IEEE Transactions on Services Computing 5(17), doi:10.1109/tsc.2024.3451171
  • Davoud Mougouei, Ahmad Azarnik, Mahdi Fahmideh, Elahe Mougouei, Hoa Khanh Dam, Arif Ali Khan, Saima Rafi, Javed Ali Khan, Aakash Ahmad (2025): A First Look at AI Trends in Value-Aligned Software Engineering Publications: Human-LLM Insights, In: 2025 IEEE/ACM 47th International Conference on Software Engineering: Software Engineering in Society (ICSE-SEIS), doi:10.1109/icse-seis66351.2025.00014
  • Gianpietro Castiglione, Giampaolo Bella, Daniele Francesco Santamaria (2024): Seconto: Ontological Representation of Security Directives, doi:10.2139/ssrn.4862271
  • Tek Raj Chhetri (2025): Data Protection by Design Tool for Automated GDPR Compliance Verification Based on Semantically Modeled Informed Consent, In: Improving Decision Making Using Semantic Web Technologies, doi:10.1007/978-3-658-45877-5_7
  • Wout Slabbinck, Julián Rojas Meléndez, Beatriz Esteves, Pieter Colpaert, Ruben Verborgh (2025): Interoperable Interpretation and Evaluation of ODRL Policies, In: Lecture Notes in Computer Science, doi:10.1007/978-3-031-94578-6_11
  • Harshvardhan J. Pandit, Beatriz Esteves, Georg P. Krog, Paul Ryan, Delaram Golpayegani, Julian Flake (2024): Data Privacy Vocabulary (DPV) – Version 2.0, In: Lecture Notes in Computer Science, doi:10.1007/978-3-031-77847-6_10
  • Ines Akaichi, Sabrina Kirrane (2025): A comprehensive review of usage control frameworks, In: Computer Science Review, doi:10.1016/j.cosrev.2024.100698
  • Yuan Zheng, Xunyang Li, Wei Zhong (2025): An empirical study on machine learning-based future loss prediction for insurance firms: evidence from China’s property and casualty insurance sector, In: Applied Economics, doi:10.1080/00036846.2025.2563913
  • Michael Gebauer, Faraz Maschhur, Nicola Leschke, Elias Grünewald, Frank Pallas (2023): A ‘Human-in-the-Loop’ approach for Information Extraction from Privacy Policies under Data Scarcity, In: 2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW), doi:10.1109/eurospw59978.2023.00014
  • Ella Roubtsova, Rachelle Bosua (2021): Privacy as a Service (PraaS): A Conceptual Model of GDPR to Construct Privacy Services, In: Lecture Notes in Business Information Processing, doi:10.1007/978-3-030-79976-2_10
  • Bijan Parsia, Nicolas Matentzoglu, Rafael S. Gonçalves, Birte Glimm, Andreas Steigmiller (2017): The OWL Reasoner Evaluation (ORE) 2015 Competition Report, In: Journal of Automated Reasoning 4(59), doi:10.1007/s10817-017-9406-8
  • Zhenyang Guo, Jin Cao, Wanying Ma, Qiulan Xu, Ben Niu, Hui Li (2025): LLMQUA:Using LLM Automation to Enhance Risk Quantification in Data Processing for Big Data Platforms, In: 2025 11th IEEE International Conference on Privacy Computing and Data Security (PCDS), doi:10.1109/pcds65695.2025.00054
  • Gianpietro Castiglione, Giampaolo Bella, Daniele Francesco Santamaria (2025): SecOnto: Ontological Representation of Security Directives, In: Computers & Security, doi:10.1016/j.cose.2024.104150
Please note: Providing information about citations is only possible thanks to to the open metadata APIs provided by crossref.org and opencitations.net. These lists may be incomplete due to unavailable citation data.source: opencitations.net, crossref.org