Static Analysis for Android GDPR Compliance Assurance

被引:0
|
作者
Khedkar, Mugdha [1 ]
机构
[1] Paderborn Univ, Heinz Nixdorf Inst, Paderborn, Germany
关键词
static analysis; data protection and privacy; GDPR compliance;
D O I
10.1109/ICSE-COMPANION58688.2023.00054
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Many Android applications collect data from users. When they do, they must protect this collected data according to the current legal frameworks. Such data protection has become even more important since the European Union rolled out the General Data Protection Regulation (GDPR). App developers have limited tool support to reason about data protection throughout their app development process. Although many Android applications state a privacy policy, privacy policy compliance checks are currently manual, expensive, and prone to error. One of the major challenges in privacy audits is the significant gap between legal privacy statements (in English text) and technical measures that Android apps use to protect their user's privacy. In this thesis, we will explore to what extent we can use static analysis to answer important questions regarding data protection. Our main goal is to design a tool based approach that aids app developers and auditors in ensuring data protection in Android applications, based on automated static program analysis.
引用
收藏
页码:197 / 199
页数:3
相关论文
共 50 条
  • [41] Ensuring security of a telemedicine project in compliance with GDPR
    Slaviek, Karel
    Dostal, Otto
    Lieskovan, Tomas
    Hajny, Jan
    [J]. 2019 11TH INTERNATIONAL CONGRESS ON ULTRA MODERN TELECOMMUNICATIONS AND CONTROL SYSTEMS AND WORKSHOPS (ICUMT), 2019,
  • [42] A readiness assessment tool for GDPR compliance certification
    Chatzipoulidis, Aristeidis
    Tsiakis, Theodosios
    Kargidis, Theodoros
    [J]. Computer Fraud and Security, 2019, 2019 (08): : 14 - 19
  • [43] Longitudinal Compliance Analysis of Android Applications with Privacy Policies
    Hashmi, Saad Sajid
    Waheed, Nazar
    Tangari, Gioacchino
    Ikram, Muhammad
    Smith, Stephen
    [J]. MOBILE AND UBIQUITOUS SYSTEMS: COMPUTING, NETWORKING AND SERVICES, 2022, 419 : 280 - 305
  • [44] GDPR and Digital Protectionism in the EU: The Cases of Android and iOS
    Ucar, Muge
    Yalcintas, Altug
    [J]. JOURNAL OF ECONOMIC ISSUES, 2023, 57 (04) : 1079 - 1094
  • [45] A Framework for GDPR Compliance in Big Data Systems
    Rhahla, Mouna
    Allegue, Sahar
    Abdellatif, Takoua
    [J]. RISKS AND SECURITY OF INTERNET AND SYSTEMS (CRISIS 2019), 2020, 12026 : 211 - 226
  • [46] Achieving GDPR Compliance of BPMN Process Models
    Agostinelli, Simone
    Maggi, Fabrizio Maria
    Marrella, Andrea
    Sapio, Francesco
    [J]. INFORMATION SYSTEMS ENGINEERING IN RESPONSIBLE INFORMATION SYSTEMS, CAISE FORUM 2019, 2019, 350 : 10 - 22
  • [47] An AI framework to support decisions on GDPR compliance
    Lore, Filippo
    Basile, Pierpaolo
    Appice, Annalisa
    de Gemmis, Marco
    Malerba, Donato
    Semeraro, Giovanni
    [J]. JOURNAL OF INTELLIGENT INFORMATION SYSTEMS, 2023, 61 (02) : 541 - 568
  • [48] Analyzing GDPR Compliance of Named Data Networking
    Tran, Casey
    Tourani, Reza
    Panwar, Gaurav
    Misra, Satyajayant
    Machacek, Travis
    [J]. PROCEEDINGS OF THE 2021 8TH ACM CONFERENCE ON INFORMATION-CENTRIC NETWORKING (ICN '21), 2021, : 107 - 117
  • [49] Privacy Enforcement at a Large Scale for GDPR Compliance
    Khaitzin, Ety
    Shlomo, Roee
    Anderson, Maya
    [J]. SYSTOR'18: PROCEEDINGS OF THE 11TH ACM INTERNATIONAL SYSTEMS AND STORAGE CONFERENCE, 2018, : 124 - 124
  • [50] Modelling Legal Knowledge for GDPR Compliance Checking
    Palmirani, Monica
    Governatori, Guido
    [J]. LEGAL KNOWLEDGE AND INFORMATION SYSTEMS (JURIX 2018), 2018, 313 : 101 - 110