Published paper "A Policy Language to Capture Compliance of Data Protection Requirements" in June 2022

The following paper in the field of privacy protection and data protection is published:

Baramashetru CP, Tapia Tarifa SL, Owe O, Gruschka N. "A policy language to capture compliance of data protection requirements." In Integrated Formal Methods: 17th International Conference, IFM 2022, Lugano, Switzerland, June 7–10, 2022, Proceedings 2022 Jun 1 (pp. 289-309). Cham: Springer International Publishing. DOI: 10.1007/978-3-031-07727-2_16

Abstract

From the very outset of the digital era, the protection of personal data against unauthorized usage and distribution has been one of the most significant challenges in distributed services. For this reason, new regulations such as the European Union’s the General Data Protection Regulation grant users tight control over their data that is handled by service providers. Compliance with such regulations can take expensive refitting of the existing systems and manual work. We propose a formal language that can define properties like informed consent, data subject rights, and the lawfulness to capture data protection requirements. The language is designed to abstract ownership information to make data dependencies explicit. We formalise a notion of policy compliance. This can be useful in service architecture with various actors who necessarily do not trust each other and may have conflicting interests.

Published Mar. 24, 2023 1:01 PM - Last modified Sep. 8, 2023 2:21 PM