Skip to search boxSkip to navigationSkip to main content

On Purpose and by Necessity: Compliance under the GDPR

Research Output:
Conference Article in Proceeding or Book/Report chapter
Article in proceedings
Peer-review

Open access

Publication Information

Output type

Research Output:
Conference Article in Proceeding or Book/Report chapter
Article in proceedings
Peer-review

Original language

English

Publication milestones

  • Published - 2018

Publication status

Published - 2018

Publisher

Springer, United States, Germany

Book series

  • Book series name: Lecture Notes in Computer Science
    Volume: 10957
    ISSN: 0302-9743
978-3-662-58386-9

ISBN (Electronic)

978-3-662-58387-6

Publication IDs

  • Scopus: 85072871760

Host publication title

Financial Cryptography and Data Security. 22nd International Conference, FC 2018, Nieuwpoort, Curaçao, February 26 – March 2, 2018,

Abstract

The European General Data Protection Regulation (GDPR) gives primacy to purpose: Data may be collected and stored only when (i) end-users have consented, often explicitly, to the purposes for which that data is collected, and (ii) the collected data is actually necessary for achieving these purposes. This development in data protection regulations begets the question: how do we audit a computer system's adherence to a purpose?
We propose an approach that identies a purpose with a business process,
and show how formal models of interprocess communication can be used
to audit or even derive privacy policies. Based on this insight, we propose
a methodology for auditing GDPR compliance. Moreover, we show how
given a simple interprocess data ow model, aspects of GDPR compliance
can be determined algorithmically.

Publication metrics

PlumX

Citations
48
Captures
96

Related Event

Title

Financial Cryptography and Data Security

Event type

Conference

Degree of recognition

International event

Date

26/02/2018

Location

NieuwpoortCuraçao