Title
Authorising Contract Based Access to Personal Data in the Cloud
Abstract
The emerging new EU data protection regulation requires that regardless of the location of the data centers a cloud service provider will have to comply with the EU data protection regulation if it provides services to EU citizens. Handling personal data in a legally compliant way is a very important factor for ensuring the trustworthiness of a cloud service provider. In this paper we present a software component called Contract Validation Service (ConVS) that validates digital contracts and helps to automate contract-based access to personal data. The paper then shows how an authorisation system can use the ConVS to automate legally compliant authorisation decisions from XACML format-ted EU Data Protection Derivative rules. Such automation in determining contract-based access decisions offers the potential to significantly reduce the effort of ensuring legal compliance of the cloud service providers.
Year
DOI
Venue
2015
10.1109/UCC.2015.99
2015 IEEE/ACM 8th International Conference on Utility and Cloud Computing (UCC)
Keywords
Field
DocType
Contract validation,XACML,EU Data Protection Directive (EU DPD),authorisation systems,Policy Enforcement Point (PEP),Policy Decision Point (PDP)
Internet privacy,Computer security,Data Protection Directive,XACML,Automation,Service provider,Component-based software engineering,Data Protection Act 1998,General Data Protection Regulation,Business,Cloud computing
Conference
ISSN
Citations 
PageRank 
2373-6860
0
0.34
References 
Authors
12
5
Name
Order
Citations
PageRank
Kaniz Fatema111310.47
Dave Lewis230.75
Declan O'Sullivan347169.07
John P. Morrison426245.28
Abdullah-Al Mazed500.34