Towards a Semantic Specification for GDPR Data Breach Reporting

被引:1
|
作者
Pandit, Harshvardhan J. [1 ,2 ]
Ryan, Paul [1 ,2 ,3 ,5 ]
Krog, Georg Philip [4 ]
Crane, Martin [2 ]
Brennan, Rob [1 ,3 ]
机构
[1] ADAPT SFI Res Ctr, Dublin, Ireland
[2] Dublin City Univ, Dublin, Ireland
[3] Univ Coll Dublin, Dublin, Ireland
[4] Signatu AS, Oslo, Norway
[5] Uniphar PLC, Dublin, Ireland
来源
基金
爱尔兰科学基金会;
关键词
GDPR; data breach; cybersecurity; semantics;
D O I
10.3233/FAIA230956
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Data breaches and other security incidents are an emerging challenge in the digital era. The General Data Protection Regulation (GDPR) requires conducting an impact assessment to understand the effects of the breach, and to then notify authorities and affected individuals in certain cases. Communication of this information typically takes place via conventional mediums such as emails and forms on the websites of authorities, and is a manual process. To assist in developing tools to support data breach investigations, and to enable automated systems for assisting with breach assessments and GDPR compliance, we present a machine-readable specification for the representation and documentation of information related to data breaches and their communications. The specification uses current requirements from the GDPR obligations and authoritative guidelines. To represent information, it extends the Data Privacy Vocabulary (DPV) by introducing new concepts required for data breach relevant information.
引用
收藏
页码:131 / 136
页数:6
相关论文
共 50 条
  • [41] Mental data protection and the GDPR
    Ienca, Marcello
    Malgieri, Gianclaudio
    JOURNAL OF LAW AND THE BIOSCIENCES, 2022, 9 (01):
  • [42] Semantic Techniques for Validation of GDPR Compliance of Business Processes
    Di Martino, Beniamino
    Mastroianni, Michele
    Campaiola, Massimo
    Morelli, Giuseppe
    Sparaco, Ernesto
    COMPLEX, INTELLIGENT, AND SOFTWARE INTENSIVE SYSTEMS (CISIS 2019), 2020, 993 : 847 - 855
  • [43] The right to data portability in the GDPR: Towards user-centric interoperability of digital services
    De Hert, Paul
    Papakonstantinou, Vagelis
    Malgieri, Gianclaudio
    Beslay, Laurent
    Sanchez, Ignacio
    COMPUTER LAW & SECURITY REVIEW, 2018, 34 (02) : 193 - 203
  • [44] Breach reporting: Some difficult issues to consider
    Eastwood, Andrew
    COMPANY AND SECURITIES LAW JOURNAL, 2014, 32 (04): : 251 - 263
  • [45] A framework for the evaluation of state breach reporting laws
    Brooker, Benjamin J.
    Crawford, Jonathan
    Horowitz, Barry M.
    2007 IEEE SYSTEMS AND INFORMATION ENGINEERING DESIGN SYMPOSIUM, 2007, : 263 - 269
  • [46] The economics of mandatory security breach reporting to authorities
    Laube, Stefan
    Boehme, Rainer
    JOURNAL OF CYBERSECURITY, 2016, 2 (01): : 29 - 41
  • [47] Short-Term Semantic Consensus: Towards Agile Ontology Specification for Collaborative Networks
    Pereira, Carla
    Sousa, Cristovao
    Soares, Antonio Lucas
    LEVERAGING KNOWLEDGE FOR INNOVATION IN COLLABORATIVE NETWORKS, 2009, 307 : 301 - 310
  • [48] Towards Agile Integration: Specification-based Data Alignment
    Giossi, Chris
    Maier, David
    Tufte, Kristin
    Gall, Elliot
    Barnes, Melissa
    2020 IEEE 21ST INTERNATIONAL CONFERENCE ON INFORMATION REUSE AND INTEGRATION FOR DATA SCIENCE (IRI 2020), 2020, : 333 - 340
  • [49] Towards a GDPR-compliant cloud architecture with data privacy controlled through sticky policies
    Cambronero, M. Emilia
    Martinez, Miguel A.
    Llana, Luis
    Rodriguez, Ricardo J.
    Russo, Alejandro
    PEERJ COMPUTER SCIENCE, 2024, 10
  • [50] A semantic reference specification for SSADM
    不详
    FORMAL FOUNDATIONS FOR SOFTWARE ENGINEERING METHODS, 1997, 1322 : 61 - 74