A BERT Based Approach to Measure Web Services Policies Compliance With GDPR

Data confidentiality is an issue of increasing importance. Several authorities and regulatory bodies are creating new laws that control how web services data is handled and shared. With the rapid increase of such regulations, web service providers face challenges in complying with these evolving reg...

Full description

Bibliographic Details
Main Authors: Lavanya Elluri, Sai Sree Laya Chukkapalli, Karuna Pande Joshi, Tim Finin, Anupam Joshi
Format: Article
Language:English
Published: IEEE 2021-01-01
Series:IEEE Access
Subjects:
Online Access:https://ieeexplore.ieee.org/document/9592800/
_version_ 1818424599525720064
author Lavanya Elluri
Sai Sree Laya Chukkapalli
Karuna Pande Joshi
Tim Finin
Anupam Joshi
author_facet Lavanya Elluri
Sai Sree Laya Chukkapalli
Karuna Pande Joshi
Tim Finin
Anupam Joshi
author_sort Lavanya Elluri
collection DOAJ
description Data confidentiality is an issue of increasing importance. Several authorities and regulatory bodies are creating new laws that control how web services data is handled and shared. With the rapid increase of such regulations, web service providers face challenges in complying with these evolving regulations across jurisdictions. Providers must update their service policies regularly to address the new regulations. The challenge is that regulatory documents are large text documents and require substantial human effort to comprehend and enforce. On the other hand, web service provider privacy policies are relatively short compared to the regulatory texts, so it is hard to determine if an organization’s policy document addresses the regulation’s essential elements. We have developed a framework to automatically compare web service policies with regulatory policies to measure how closely the web service provider complies with a regulation. In this paper, we present our framework’s details along with the results of analyzing a corpus of 3,000 privacy policies against GDPR. Our framework uses BiLSTM multi-class classification and a BERT extractive summarizer. We evaluate the framework’s efficacy by checking the context similarity score between summarized GDPR and web service provider privacy policies.
first_indexed 2024-12-14T14:00:36Z
format Article
id doaj.art-2cf991d11c1c49d6bd7239f20a910a33
institution Directory Open Access Journal
issn 2169-3536
language English
last_indexed 2024-12-14T14:00:36Z
publishDate 2021-01-01
publisher IEEE
record_format Article
series IEEE Access
spelling doaj.art-2cf991d11c1c49d6bd7239f20a910a332022-12-21T22:58:43ZengIEEEIEEE Access2169-35362021-01-01914800414801610.1109/ACCESS.2021.31239509592800A BERT Based Approach to Measure Web Services Policies Compliance With GDPRLavanya Elluri0https://orcid.org/0000-0002-8881-3369Sai Sree Laya Chukkapalli1https://orcid.org/0000-0002-3663-9231Karuna Pande Joshi2https://orcid.org/0000-0002-6354-1686Tim Finin3https://orcid.org/0000-0002-6593-1792Anupam Joshi4Department of Information Systems, University of Maryland at Baltimore County (UMBC), Baltimore, MD, USADepartment of Computer Science, University of Maryland at Baltimore County (UMBC), Baltimore, MD, USADepartment of Information Systems, University of Maryland at Baltimore County (UMBC), Baltimore, MD, USADepartment of Computer Science, University of Maryland at Baltimore County (UMBC), Baltimore, MD, USADepartment of Computer Science, University of Maryland at Baltimore County (UMBC), Baltimore, MD, USAData confidentiality is an issue of increasing importance. Several authorities and regulatory bodies are creating new laws that control how web services data is handled and shared. With the rapid increase of such regulations, web service providers face challenges in complying with these evolving regulations across jurisdictions. Providers must update their service policies regularly to address the new regulations. The challenge is that regulatory documents are large text documents and require substantial human effort to comprehend and enforce. On the other hand, web service provider privacy policies are relatively short compared to the regulatory texts, so it is hard to determine if an organization’s policy document addresses the regulation’s essential elements. We have developed a framework to automatically compare web service policies with regulatory policies to measure how closely the web service provider complies with a regulation. In this paper, we present our framework’s details along with the results of analyzing a corpus of 3,000 privacy policies against GDPR. Our framework uses BiLSTM multi-class classification and a BERT extractive summarizer. We evaluate the framework’s efficacy by checking the context similarity score between summarized GDPR and web service provider privacy policies.https://ieeexplore.ieee.org/document/9592800/Web service privacy policiesdeep learningcontext extractionBERT summarizationknowledge discovery
spellingShingle Lavanya Elluri
Sai Sree Laya Chukkapalli
Karuna Pande Joshi
Tim Finin
Anupam Joshi
A BERT Based Approach to Measure Web Services Policies Compliance With GDPR
IEEE Access
Web service privacy policies
deep learning
context extraction
BERT summarization
knowledge discovery
title A BERT Based Approach to Measure Web Services Policies Compliance With GDPR
title_full A BERT Based Approach to Measure Web Services Policies Compliance With GDPR
title_fullStr A BERT Based Approach to Measure Web Services Policies Compliance With GDPR
title_full_unstemmed A BERT Based Approach to Measure Web Services Policies Compliance With GDPR
title_short A BERT Based Approach to Measure Web Services Policies Compliance With GDPR
title_sort bert based approach to measure web services policies compliance with gdpr
topic Web service privacy policies
deep learning
context extraction
BERT summarization
knowledge discovery
url https://ieeexplore.ieee.org/document/9592800/
work_keys_str_mv AT lavanyaelluri abertbasedapproachtomeasurewebservicespoliciescompliancewithgdpr
AT saisreelayachukkapalli abertbasedapproachtomeasurewebservicespoliciescompliancewithgdpr
AT karunapandejoshi abertbasedapproachtomeasurewebservicespoliciescompliancewithgdpr
AT timfinin abertbasedapproachtomeasurewebservicespoliciescompliancewithgdpr
AT anupamjoshi abertbasedapproachtomeasurewebservicespoliciescompliancewithgdpr
AT lavanyaelluri bertbasedapproachtomeasurewebservicespoliciescompliancewithgdpr
AT saisreelayachukkapalli bertbasedapproachtomeasurewebservicespoliciescompliancewithgdpr
AT karunapandejoshi bertbasedapproachtomeasurewebservicespoliciescompliancewithgdpr
AT timfinin bertbasedapproachtomeasurewebservicespoliciescompliancewithgdpr
AT anupamjoshi bertbasedapproachtomeasurewebservicespoliciescompliancewithgdpr