Repository logo
  • Log In
    New user? Click here to register.Have you forgotten your password?
University College Dublin
    Colleges & Schools
    Statistics
    All of DSpace
  • Log In
    New user? Click here to register.Have you forgotten your password?
  1. Home
  2. College of Science
  3. School of Computer Science
  4. Computer Science Research Collection
  5. "The Grace Period Has Ended": An Approach to Operationalize GDPR Requirements
 
  • Details
Options

"The Grace Period Has Ended": An Approach to Operationalize GDPR Requirements

Author(s)
Ayala-Rivera, Vanessa  
Pasquale, Liliana  
Uri
http://hdl.handle.net/10197/10526
Date Issued
2018-08-24
Date Available
2019-05-20T10:16:25Z
Abstract
The General Data Protection Regulation (GDPR) aims to protect personal data of EU residents and can impose severe sanctions for non-compliance. Organizations are currently implementing various measures to ensure their software systems fulfill GDPR obligations such as identifying a legal basis for data processing or enforcing data anonymization. However, as regulations are formulated vaguely, it is difficult for practitioners to extract and operationalize legal requirements from the GDPR. This paper aims to help organizations understand the data protection obligations imposed by the GDPR and identify measures to ensure compliance. To achieve this goal, we propose GuideMe, a 6-step systematic approach that supports elicitation of solution requirements that link GDPR data protection obligations with the privacy controls that fulfill these obligations and that should be implemented in an organization's software system. We illustrate and evaluate our approach using an example of a university information system. Our results demonstrate that the solution requirements elicited using our approach are aligned with the recommendations of privacy experts and are expressed correctly.
Sponsorship
European Research Council
Science Foundation Ireland
Type of Material
Conference Publication
Publisher
IEEE
Copyright (Published Version)
2018 IEEE
Subjects

GDPR

Compliance

Privacy

Requirements

DOI
10.1109/RE.2018.00023
Web versions
https://ieeexplore-ieee-org.ucd.idm.oclc.org/abstract/document/8491130
Language
English
Status of Item
Peer reviewed
Journal
2018 IEEE 26th International Requirements Engineering Conference (RE)
Conference Details
IEEE 26th International Requirements Engineering Conference (RE), Banff, Canada, 20-24 August 2018
ISSN
2332-6441
This item is made available under a Creative Commons License
https://creativecommons.org/licenses/by-nc-nd/3.0/ie/
File(s)
No Thumbnail Available
Name

RE18pre_AyalaRivera.pdf

Size

1.24 MB

Format

Adobe PDF

Checksum (MD5)

131e9af92a28afe79467f6e6e4234e31

Owning collection
Computer Science Research Collection

Item descriptive metadata is released under a CC-0 (public domain) license: https://creativecommons.org/public-domain/cc0/.
All other content is subject to copyright.

For all queries please contact research.repository@ucd.ie.

Built with DSpace-CRIS software - Extension maintained and optimized by 4Science

  • Cookie settings
  • Privacy policy
  • End User Agreement