Design principles for the General Data Protection Regulation (GDPR): A formal concept analysis and its evaluation

被引:55
|
作者
Tamburri, Damian A. [1 ]
机构
[1] Tech Univ Eindhoven, Eindhoven, Netherlands
关键词
Privacy-by-design; GDPR; Formal-concept analysis; PRIVACY; CONSTRAINTS;
D O I
10.1016/j.is.2019.101469
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Data and software are nowadays one and the same: for this very reason, the European Union (EU) and other governments introduce frameworks for data protection - a key example being the General Data Protection Regulation (GDPR). However, GDPR compliance is not straightforward: its text is not written by software or information engineers but rather, by lawyers and policy-makers. As a design aid to information engineers aiming for GDPR compliance, as well as an aid to software users' understanding of the regulation, this article offers a systematic synthesis and discussion of it, distilled by the mathematical analysis method known as Formal Concept Analysis (FCA). By its principles, GDPR is synthesised as a concept lattice, that is, a formal summary of the regulation, featuring 144372 records - its uses are manifold. For example, the lattice captures so-called attribute implications, the implicit logical relations across the regulation, and their intensity. These results can be used as drivers during systems and services (re-)design, development, operation, or information systems' refactoring towards more GDPR consistency. (C) 2019 The Author( s). Published by Elsevier Ltd.
引用
收藏
页数:14
相关论文
共 50 条
  • [1] GENERAL DATA PROTECTION REGULATION (GDPR): THE CHALLENGE OF ITS IMPLEMENTATION FOR HEALTH
    Hawryliszyn, Larissa Oliveira
    Campos Coelho, Natalia Gavioli Souza
    Barja, Paulo Roxo
    [J]. REVISTA UNIVAP, 2021, 27 (54)
  • [2] The European Union's General Data Protection Regulation (GDPR) and its Implications for South African Data Privacy Law: An Evaluation of Selected 'Content Principles'
    Roos, Anneliese
    [J]. COMPARATIVE AND INTERNATIONAL LAW JOURNAL OF SOUTHERN AFRICA-CILSA, 2020, 53 (03):
  • [3] GENERAL DATA PROTECTION REGULATION (GDPR) AND DISTANCE LEARNING
    Hruby, Miroslav
    [J]. EFFECTIVE DEVELOPMENT OF TEACHERS' SKILLS IN THE AREA OF ICT AND E-LEARNING, 2017, 9 : 209 - 217
  • [4] From supercomputers to General Data Protection Regulation (GDPR)
    Bode, Arndt
    Pagel, Peter
    [J]. Informatik-Spektrum, 2018, 41 (05)
  • [5] General Data Protection Regulation (GDPR) and implications for research
    Cornock, Marc
    [J]. MATURITAS, 2018, 111 : A1 - A2
  • [6] OpenEHR and General Data Protection Regulation: Evaluation of Principles and Requirements
    Goncalves-Ferreira, Duarte
    Sousa, Mariana
    Bacelar-Silva, Gustavo
    Frade, Samuel
    Antunes, Luis
    Beale, Thomas
    Cruz-Correia, Ricardo
    [J]. JMIR MEDICAL INFORMATICS, 2019, 7 (01)
  • [7] Recovery of claims in the GDPR (General Data Protection Regulation) era
    Manescu, Dragos
    [J]. JURIDICAL TRIBUNE-TRIBUNA JURIDICA, 2018, 8 (03): : 789 - 800
  • [8] Preparing Students for the Era of the General Data Protection Regulation (GDPR)
    Markovic, Maja Gligora
    Debeljak, Sandra
    Kadoic, Nikola
    [J]. TEM JOURNAL-TECHNOLOGY EDUCATION MANAGEMENT INFORMATICS, 2019, 8 (01): : 150 - 156
  • [9] The practice of external data protection officers under the General Data Protection Regulation (GDPR)
    Kremer, Sascha
    [J]. Informatik-Spektrum, 2020, 43 (05) : 332 - 333
  • [10] OpenEHR Based Systems and the General Data Protection Regulation (GDPR)
    Sousa, Mariana
    Ferreira, Duarte
    Santos-Pereira, Catia
    Bacelar, Gustavo
    Frade, Samuel
    Pestana, Olivia
    Cruz-Correia, Ricardo
    [J]. BUILDING CONTINENTS OF KNOWLEDGE IN OCEANS OF DATA: THE FUTURE OF CO-CREATED EHEALTH, 2018, 247 : 91 - 95