The grace period has ended: An approach to operationalize GDPR requirements

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

The General Data Protection Regulation (GDPR) aims to protect personal data of EU residents and can impose severe sanctions for non-compliance. Organizations are currently implementing various measures to ensure their software systems fulfill GDPR obligations such as identifying a legal basis for data processing or enforcing data anonymization. However, as regulations are formulated vaguely, it is difficult for practitioners to extract and operationalize legal requirements from the GDPR. This paper aims to help organizations understand the data protection obligations imposed by the GDPR and identify measures to ensure compliance. To achieve this goal, we propose GuideMe, a 6-step systematic approach that supports elicitation of solution requirements that link GDPR data protection obligations with the privacy controls that fulfill these obligations and that should be implemented in an organization's software system. We illustrate and evaluate our approach using an example of a university information system. Our results demonstrate that the solution requirements elicited using our approach are aligned with the recommendations of privacy experts and are expressed correctly.

Original languageEnglish
Title of host publicationProceedings - 2018 IEEE 26th International Requirements Engineering Conference, RE 2018
EditorsDaniel Amyot, Walid Maalej, Guenther Ruhe
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages136-146
Number of pages11
ISBN (Electronic)9781538674185
DOIs
Publication statusPublished - 12 Oct 2018
Externally publishedYes
Event26th IEEE International Requirements Engineering Conference, RE 2018 - Banff, Canada
Duration: 20 Aug 201824 Aug 2018

Publication series

NameProceedings - 2018 IEEE 26th International Requirements Engineering Conference, RE 2018

Conference

Conference26th IEEE International Requirements Engineering Conference, RE 2018
Country/TerritoryCanada
CityBanff
Period20/08/1824/08/18

Keywords

  • Compliance
  • GDPR
  • Privacy
  • Requirements

Fingerprint

Dive into the research topics of 'The grace period has ended: An approach to operationalize GDPR requirements'. Together they form a unique fingerprint.

Cite this