Title
The Grace Period Has Ended: An Approach to Operationalize GDPR Requirements
Abstract
The General Data Protection Regulation (GDPR) aims to protect personal data of EU residents and can impose severe sanctions for non-compliance. Organizations are currently implementing various measures to ensure their software systems fulfill GDPR obligations such as identifying a legal basis for data processing or enforcing data anonymization. However, as regulations are formulated vaguely, it is difficult for practitioners to extract and operationalize legal requirements from the GDPR. This paper aims to help organizations understand the data protection obligations imposed by the GDPR and identify measures to ensure compliance. To achieve this goal, we propose GuideMe, a 6-step systematic approach that supports elicitation of solution requirements that link GDPR data protection obligations with the privacy controls that fulfill these obligations and that should be implemented in an organization's software system. We illustrate and evaluate our approach using an example of a university information system. Our results demonstrate that the solution requirements elicited using our approach are aligned with the recommendations of privacy experts and are expressed correctly.
Year
DOI
Venue
2018
10.1109/RE.2018.00023
2018 IEEE 26th International Requirements Engineering Conference (RE)
Keywords
Field
DocType
GDPR,Compliance,Privacy,Requirements
Information system,Sanctions,Computer science,Grace period,Data anonymization,Risk analysis (engineering),Software system,Operationalization,Data Protection Act 1998,General Data Protection Regulation,Management science
Conference
ISSN
ISBN
Citations 
1090-705X
978-1-5386-7419-2
5
PageRank 
References 
Authors
0.49
9
2
Name
Order
Citations
PageRank
Vanessa Ayala-Rivera1183.96
Liliana Pasquale246830.04