错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Assuring GDPR Conformance Through Language-Based Compliance

  • Chinmayi Prabhu Baramashetru,
  • Silvia Lizeth Tapia Tarifa,
  • Olaf Owe

摘要

Existing legal regulations, such as the GDPR in the European Union, exert significant pressure on businesses to embed legal principles into their information systems. These legislative provisions, expertly crafted in natural language, have raised technical challenges to be GDPR compliant. In particular, formal reasoning about compliance at the level of programming code is challenging. Available alternatives, such as manual auditing, have demonstrated limited scalability, and the absence of system-level support has led to substantial penalties for businesses and a loss of control over their personal data for users. Hence, we develop an approach that intends to reconcile the existing challenges in software implications with GDPR through programming language support. We build on earlier work introducing a privacy-aware active object language and operational semantics. To demonstrate the practicality, we here present a prototype implementation within the Maude formalism, which validates our semantics and model-checks GDPR compliance properties within any given configuration. Our work is limited to certain key concepts of the GDPR that can be interpreted at the programming level. We focus on processing rights based on user consent.