Business process models and simulation to enable GDPR compliance
摘要
The general data protection regulation (GDPR) provides European individuals with a regulatory framework for personal data protection and privacy. Compliance with this regulation represents an essential challenge for organisations that store, transmit, and process personal data. Millionaire fines are imposed by European protection authorities due to non-compliance. Currently, non-automated solutions are applied in organisations to carry out regulatory compliance, and therefore expensive manual implementation and audits are necessary to ensure GDPR compliance. To avoid these drawbacks, this paper presents a data model and a business process model as a first step towards designing automated mechanisms for implementing the GDPR. Furthermore, the proposed models are employed to support business process simulation (BPS), which includes aspects of performance, cost, and scalability, for evaluating the resource human impact and the execution time that our proposal can have in organisations. These factors would facilitate informed decision-making by the data controller regarding the resources and the degree of GDPR compliance, supporting data controller decisions regarding determining the necessary types of resources to achieve a suitable level of compliance and to obtain the degree of GDPR compliance. Given the large number of legal articles on the GDPR and owing to space limitation herein, we focus on Articles 33 and 34 regarding notification and communication of a personal data breach.