A model-based approach to support privacy compliance

<strong>Purpose -</strong> Concerns over data-processing activities that may lead to privacy violations or harms have motivated the development of legal frameworks and standards. Further, software engineers are increasingly expected to develop and maintain privacy-aware systems that both...

Full description

Bibliographic Details
Main Authors: Alshammari, M, Simpson, A
Format: Journal article
Published: Emerald Publishing 2018
_version_ 1826263058795724800
author Alshammari, M
Simpson, A
author_facet Alshammari, M
Simpson, A
author_sort Alshammari, M
collection OXFORD
description <strong>Purpose -</strong> Concerns over data-processing activities that may lead to privacy violations or harms have motivated the development of legal frameworks and standards. Further, software engineers are increasingly expected to develop and maintain privacy-aware systems that both comply with such frameworks and standards and meet reasonable expectations of privacy. This paper aims to facilitate reasoning about privacy compliance, from legal frameworks and standards, with a view to providing necessary technical assurances. <strong>Design/methodology/approach -</strong> We show how the standard extension mechanisms of the UML meta-model might be used to specify and represent dataprocessing activities in a way that is amenable to privacy compliance checking and assurance. <strong>Findings -</strong> We demonstrate the usefulness and applicability of the extension mechanisms in specifying key aspects of privacy principles as assumptions and requirements, as well as in providing criteria for the evaluation of these aspects to assess whether the model meets these requirements. <strong>Originality/value -</strong> First, we show how key aspects of abstract privacy principles can be modelled using stereotypes and tagged values as privacy assumptions and requirements. Second, we show how compliance with these principles can be assured via constraints that establish rules for the evaluation of these requirements
first_indexed 2024-03-06T19:45:39Z
format Journal article
id oxford-uuid:22377884-a187-4139-ad16-05c0cbcac100
institution University of Oxford
last_indexed 2024-03-06T19:45:39Z
publishDate 2018
publisher Emerald Publishing
record_format dspace
spelling oxford-uuid:22377884-a187-4139-ad16-05c0cbcac1002022-03-26T11:37:32ZA model-based approach to support privacy complianceJournal articlehttp://purl.org/coar/resource_type/c_dcae04bcuuid:22377884-a187-4139-ad16-05c0cbcac100Symplectic Elements at OxfordEmerald Publishing2018Alshammari, MSimpson, A<strong>Purpose -</strong> Concerns over data-processing activities that may lead to privacy violations or harms have motivated the development of legal frameworks and standards. Further, software engineers are increasingly expected to develop and maintain privacy-aware systems that both comply with such frameworks and standards and meet reasonable expectations of privacy. This paper aims to facilitate reasoning about privacy compliance, from legal frameworks and standards, with a view to providing necessary technical assurances. <strong>Design/methodology/approach -</strong> We show how the standard extension mechanisms of the UML meta-model might be used to specify and represent dataprocessing activities in a way that is amenable to privacy compliance checking and assurance. <strong>Findings -</strong> We demonstrate the usefulness and applicability of the extension mechanisms in specifying key aspects of privacy principles as assumptions and requirements, as well as in providing criteria for the evaluation of these aspects to assess whether the model meets these requirements. <strong>Originality/value -</strong> First, we show how key aspects of abstract privacy principles can be modelled using stereotypes and tagged values as privacy assumptions and requirements. Second, we show how compliance with these principles can be assured via constraints that establish rules for the evaluation of these requirements
spellingShingle Alshammari, M
Simpson, A
A model-based approach to support privacy compliance
title A model-based approach to support privacy compliance
title_full A model-based approach to support privacy compliance
title_fullStr A model-based approach to support privacy compliance
title_full_unstemmed A model-based approach to support privacy compliance
title_short A model-based approach to support privacy compliance
title_sort model based approach to support privacy compliance
work_keys_str_mv AT alshammarim amodelbasedapproachtosupportprivacycompliance
AT simpsona amodelbasedapproachtosupportprivacycompliance
AT alshammarim modelbasedapproachtosupportprivacycompliance
AT simpsona modelbasedapproachtosupportprivacycompliance