Monitoring the GDPR: European Symposium on Research in Computer Security
- Emma Arfelt Kock,
- David Basin,
- Swiss Federal Institute of Technology Zürich,
Research Output:
Conference Article in Proceeding or Book/Report chapter
Article in proceedings
Peer-reviewOpen access
Publication Information
Output type
Research Output:
Conference Article in Proceeding or Book/Report chapter
Article in proceedings
Peer-reviewHost publication Subtitle
European Symposium on Research in Computer SecurityOriginal language
EnglishPages from-to (Number of pages)
Pages 681-699Publication milestones
- Published - 2019
Publication status
Published - 2019
Publisher
Springer, United States, GermanyBook series
- Book series name: Lecture Notes in Computer Science
Volume: 11735
ISSN: 0302-9743
ISBN (Electronic)
978-3-030-29959-0Publication IDs
- Scopus: 85075611770
Host publication title
Computer Security – ESORICS 2019Abstract
The General Data Protection Regulation (GDPR) has substantially strengthened the requirements for data processing systems, requiring audits at scale. We show how and to what extent these audits can be automated. We contribute an analysis of which parts of the GDPR can be monitored, a formalisation of these parts in metric first-order temporal logic, and an application of the MonPoly system to automatically audit these parts. We validate our ideas on a case study using log data from industry, detecting actual violations. Altogether, we demonstrate both in theory and practice how to automate GDPR compliance checking.
Publication metrics
PlumX, opens in new tab
Mentions
1
Captures
45
Citations
39
Access to documents
Accepted author manuscript, 396.68 KB
Related Event
Title
The 24th European Symposium on Research in Computer Security
Event type
ConferenceDegree of recognition
International eventDate
23/09/2019 - 27/09/2019Location
LuxembourgLuxembourgLuxembourg
