@inproceedings{125a4469e97d4aebabd05adaeef5e59c,
title = "The grace period has ended: An approach to operationalize GDPR requirements",
abstract = "The General Data Protection Regulation (GDPR) aims to protect personal data of EU residents and can impose severe sanctions for non-compliance. Organizations are currently implementing various measures to ensure their software systems fulfill GDPR obligations such as identifying a legal basis for data processing or enforcing data anonymization. However, as regulations are formulated vaguely, it is difficult for practitioners to extract and operationalize legal requirements from the GDPR. This paper aims to help organizations understand the data protection obligations imposed by the GDPR and identify measures to ensure compliance. To achieve this goal, we propose GuideMe, a 6-step systematic approach that supports elicitation of solution requirements that link GDPR data protection obligations with the privacy controls that fulfill these obligations and that should be implemented in an organization's software system. We illustrate and evaluate our approach using an example of a university information system. Our results demonstrate that the solution requirements elicited using our approach are aligned with the recommendations of privacy experts and are expressed correctly.",
keywords = "Compliance, GDPR, Privacy, Requirements",
author = "Vanessa Ayala-Rivera and Liliana Pasquale",
note = "Publisher Copyright: {\textcopyright} 2018 IEEE.; 26th IEEE International Requirements Engineering Conference, RE 2018 ; Conference date: 20-08-2018 Through 24-08-2018",
year = "2018",
month = oct,
day = "12",
doi = "10.1109/RE.2018.00023",
language = "English",
series = "Proceedings - 2018 IEEE 26th International Requirements Engineering Conference, RE 2018",
publisher = "Institute of Electrical and Electronics Engineers Inc.",
pages = "136--146",
editor = "Daniel Amyot and Walid Maalej and Guenther Ruhe",
booktitle = "Proceedings - 2018 IEEE 26th International Requirements Engineering Conference, RE 2018",
address = "United States",
}