A Viewpoint-Based Model of Data Protection Impact Assessments
摘要
The increasing complexity of software systems and the multidisciplinary nature of data protection obligations pose significant challenges to the effective conduction of Data Protection Impact Assessments (DPIAs). Despite regulatory mandates such as the GDPR, current DPIA practices often lack structured methods for integrating legal, technical, organizational, and privacy-related perspectives. This research addresses the gap by introducing a viewpoint-based model for DPIAs that systematically captures and interrelates stakeholder concerns. The objective is to enhance the transparency, traceability, and completeness of DPIAs across the lifecycle of data processing activities. Grounded in the ISO 42010:2022 standard and principles of Model-Driven Engineering, we developed a conceptual model comprising found interlinked viewpoints: legal, engineering, application, and privacy. Each viewpoint is formalized using UML-based model kinds and is mapped to corresponding stakeholder roles and concerns identified through literature and regulatory analysis. Our findings demonstrate that a viewpoint-based approach can improve interdisciplinary communication, clarify responsibilities, and support more structured and accountable DPIA processes. This model offers a foundation for future tool integration, empirical validation, and automated risk analysis. Ultimately, it contributes to a more robust, stakeholder-inclusive approach to privacy-by-design and regulatory compliance in software engineering.