Skip to search boxSkip to navigationSkip to main content

Consent under control with ProPrivacy: Business process compliance verification for GDPR-consent requirements

  • Marco Robol
    ,
  • Mattia Salnitri
    ,
  • ,
  • Paolo Giorgini
Research Output:
Journal Article or Conference Article in Journal
Journal article
Peer-review

Open access

Publication Information

Output type

Research Output:
Journal Article or Conference Article in Journal
Journal article
Peer-review

Original language

English

Journal (Volume, Issue Number)

Information and Software Technology (Volume 196)

Publication milestones

  • Published - 08/2026

Publication status

Published - 08/2026

ISSN

0950-5849

Publication IDs

  • ORCID: /0000-0002-8346-2467/work/213368188
  • Scopus: 105037058861

Abstract

Context: Since its enforcement in 2018, the General Data Protection Regulation (GDPR) has continued to shape how organizations, in the European Economic Area, design and operate their data-driven services. Consent management, in particular, remains a cornerstone of compliance, but it has also become increasingly complex with the rise of data-intensive business models, digital health platforms, and AI-powered services. Despite the availability of technical and organizational tools, many companies still struggle to adapt legacy and large-scale processes to meet GDPR’s consent requirements. Knowledge about these processes is often fragmented across organizational silos, and documentation is incomplete, making re-engineering activities both tedious and error-prone.

Objectives: Companies relies on experts for the re-engineering and validation of their processes, while a comprehensive method is still missing to support them in verifying the compliance of their processes with consent. To address these challenges, this paper proposes a model-based approach that supports business and privacy experts in aligning operational processes with GDPR consent principles.

Methods.: Rather than introducing a new language that would require analysts modeling processes from scratch, our framework, ProPrivacy, builds on the widely adopted Business Process Model and Notation 2.0 (BPMN 2.0) modeling language, allowing analysts to enrich existing models with consent requirements. To mitigate verification errors and reduce the effort in analyzing complex models, ProPrivacy then automatically verifies compliance with key GDPR principles related to specific and freely given consent and data minimization. We demonstrate the applicability and scalability of our approach on realistic processes from the healthcare domain, where the management of sensitive data continues to present critical privacy challenges.

Conclusions: The results suggest that automated verification of business processes can not only support organizations in achieving compliance with GDPR but also serve as a foundation for certifying accountable and transparent business processes.

Publication metrics

PlumX, opens in new tab

Captures
9
Mentions
1

Funding Details

The authors declare the following financial interests/personal relationships which may be considered as potential competing interests: Mattia Salnitri reports financial support was provided by ERICS (PE00000014) under the NRRP MUR program funded by the EU - NGEU. If there are other authors, they declare that they have no known competing financial interests or personal relationships that could have appeared to influence the work reported in this paper.
FundersFunding numbers
European Research Infrastructure Consortium
PE00000014