A comparison of system description models for data protection by design

14Citations
Citations of this article
37Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Since the General Data Protection Regulation (GDPR) entered into force, every actor involved in the processing of personal data must comply with Data Protection by Design (DPbD). Doing so requires assessing the risks to data subjects' rights and freedoms and implementing appropriate countermeasures. While legal experts traditionally apply Data Protection Impact Assessments (DPIA), software engineers rely on threat modeling for their assessment. Despite significant differences, both approaches nonetheless revolve around (i) a description of the system and (ii) the identification, assessment and mitigation of specific risks. In practice, however, DPIAs and threat modeling are usually performed in complete isolation, following their own, unharmonized lexicon and abstractions. Such as disconnect lowers the quality of the assessment and of the conceptual and architectural trade-offs In this paper, we present (i) an overview of the legal and architectural modeling requirements and (ii) incentives and recommendations for aligning both modeling paradigms in order to support data protection by design from both a legal and a technical perspective.

Cite

CITATION STYLE

APA

Dewitte, P., Emanuilov, I., Valcke, P., Wuyts, K., Sion, L., Van Landuyt, D., & Joosen, W. (2019). A comparison of system description models for data protection by design. In Proceedings of the ACM Symposium on Applied Computing (pp. 1512–1515). Association for Computing Machinery. https://doi.org/10.1145/3297280.3297595

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free