Conference item icon

Conference item

Run-time monitoring of data-handling violations

Abstract:
Organisations are coming under increasing pressure to respect and protect personal data privacy, especially with the European Union’s General Data Protection Regulation (GDPR) now in effect. As legislation and regulation evolve to incentivise such data-handling protection, so too does the business case for demonstrating compliance both in spirit and to the letter. Compliance will require ongoing checks as modern systems are constantly changing in terms of digital infrastructure services and business offerings, and the interaction between human and machine. Therefore, monitoring for compliance during run-time is likely to be required. There has been limited research into how to monitor how well a system respects consents given, and withheld, pertaining to handling and onward sharing. This paper proposes a finite-state-machine method for detecting violations of preferences (consents and revocations) expressed by Data Subjects regarding use of their personal data, and also violations of any related obligations that might be placed upon data handlers (data controllers and processors). Our approach seeks to enable detection of both accidental and malicious compromises of privacy properties. We also present a concept demonstrator to show the feasibility of our approach and discuss its design and technical implementation.
Publication status:
Published
Peer review status:
Peer reviewed

Actions


Access Document


Files:
Publisher copy:
10.1007/978-3-030-12786-2_13

Authors


More by this author
Institution:
University of Oxford
Division:
MPLS
Department:
Computer Science
Role:
Author
ORCID:
0000-0002-0860-5130
More by this author
Institution:
University of Oxford
Division:
MPLS Division
Department:
Computer Science
Role:
Author
More by this author
Institution:
University of Oxford
Division:
MPLS Division
Department:
Computer Science
Role:
Author


Publisher:
Springer, Cham
Host title:
SECPRE 2018, CyberICPS 2018: Computer Security
Journal:
2nd International Workshop on SECurity and Privacy Requirements Engineering (SECPRE 2018) More from this journal
Series:
Lecture Notes in Computer Science
Publication date:
2019-01-31
Acceptance date:
2018-07-28
DOI:
ISSN:
0302-9743
ISBN:
9783030127855


Keywords:
Pubs id:
pubs:891591
UUID:
uuid:ab443857-1a40-479d-ad72-aa2f6591158d
Local pid:
pubs:891591
Source identifiers:
891591
Deposit date:
2018-09-05

Terms of use



Views and Downloads






If you are the owner of this record, you can report an update to it here: Report update to this record

TO TOP