A Model-based Approach to Realize Privacy and Data Protection by Design

Autor: Guillaume Mockly, Gabriel Pedroza, Victor Muntes-Mulero, Yod Samuel Martín
Přispěvatelé: Laboratoire Exigences et Conformité des Systèmes (LECS), Département Ingénierie Logiciels et Systèmes (DILS), Laboratoire d'Intégration des Systèmes et des Technologies (LIST (CEA)), Direction de Recherche Technologique (CEA) (DRT (CEA)), Commissariat à l'énergie atomique et aux énergies alternatives (CEA)-Commissariat à l'énergie atomique et aux énergies alternatives (CEA)-Direction de Recherche Technologique (CEA) (DRT (CEA)), Commissariat à l'énergie atomique et aux énergies alternatives (CEA)-Commissariat à l'énergie atomique et aux énergies alternatives (CEA)-Université Paris-Saclay-Laboratoire d'Intégration des Systèmes et des Technologies (LIST (CEA)), Commissariat à l'énergie atomique et aux énergies alternatives (CEA)-Commissariat à l'énergie atomique et aux énergies alternatives (CEA)-Université Paris-Saclay, Beawre Digital SL, Universidad Politécnica de Madrid (UPM), Trialog [Paris], European Project: 787034,PDP4E, Laboratoire d'Intégration des Systèmes et des Technologies (LIST), Universitat Politècnica de Catalunya [Barcelona] (UPC)
Jazyk: angličtina
Rok vydání: 2021
Předmět:
MDE
data protection
Privacy by Design
Computer science
Privacy by design
MBSE
[INFO.INFO-CE]Computer Science [cs]/Computational Engineering
Finance
and Science [cs.CE]

[INFO.INFO-DS]Computer Science [cs]/Data Structures and Algorithms [cs.DS]
Context (language use)
[INFO.INFO-IA]Computer Science [cs]/Computer Aided Engineering
Transparency (behavior)
[INFO.INFO-MO]Computer Science [cs]/Modeling and Simulation
ACM: D.: Software/D.2: SOFTWARE ENGINEERING/D.2.10: Design/D.2.10.0: Methodologies
Variety (cybernetics)
Data modeling
ACM: I.: Computing Methodologies/I.6: SIMULATION AND MODELING
Risk analysis (engineering)
ACM: D.: Software/D.2: SOFTWARE ENGINEERING/D.2.2: Design Tools and Techniques/D.2.2.0: Computer-aided software engineering (CASE)
personal data detection
General Data Protection Regulation
model-based
Data Protection Act 1998
GDPR
Engineering design process
DFD
Zdroj: 2021 IEEE European Symposium on Security and Privacy Workshops
IEEE Xplore
2021 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)
2021 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW), Sep 2021, Vienna, Austria. pp.327-334, ⟨10.1109/EuroSPW54576.2021.00042⟩
EuroS&P Workshops
IWPE'21-2021 International Workshop on Privacy Engineering
IWPE'21-2021 International Workshop on Privacy Engineering, Sep 2021, vienne (Virtual conference), Austria
DOI: 10.1109/EuroSPW54576.2021.00042⟩
Popis: International audience; Telecommunications and data are pervasive in almost each aspect of our every-day life and new concerns progressively arise as a result of stakes related to privacy and data protection. Indeed, systems development becomes data-centric leading to an ecosystem where a variety of players intervene (citizens, industry, regulators) and where the policies regarding data usage and utilization are far from consensual. The new General Data Protection Regulation (GDPR) enacted by the European Commission in 2018 has introduced new provisions including principles for lawfulness, fairness, transparency, etc. thus endorsing data subjects with new rights in regards to their personal data. In this context, a growing need for approaches that conceptualize and help engineers to integrate GDPR and privacy provisions at design time becomes paramount. This paper presents a comprehensive approach to support different phases of the design process with special attention to the integration of privacy and data protection principles. Among others, it is a generic model-based approach that can be specialized according to the specifics of different application domains.
Databáze: OpenAIRE