Projects per year
Abstract
The European General Data Protection Regulation (GDPR) brings
new challenges for companies, who must demonstrate that their
systems and business processes comply with usage constraints
specified by data subjects. However, due to the lack of standards,
tools, and best practices, many organizations struggle to adapt their
infrastructure and processes to ensure and demonstrate that all
data processing is in compliance with users' given consent. The
SPECIAL EU H2020 project has developed vocabularies that can
formally describe data subjects' given consent as well as methods
that use this description to automatically determine whether
processing of the data according to a given policy is compliant
with the given consent. Whereas this makes it possible to determine
whether processing was compliant or not, integration of the
approach into existing line of business applications and ex-ante
compliance checking remains an open challenge. In this short paper,
we demonstrate how the SPECIAL consent and compliance framework
can be integrated into Linked Widgets, a mashup platform, in
order to support privacy-aware ad-hoc integration of personal data.
The resulting environment makes it possible to create data integration
and processing workflows out of components that inherently
respect usage policies of the data that is being processed and are
able to demonstrate compliance. We provide an overview of the
necessary meta data and orchestration towards a privacy-aware
linked data mashup platform that automatically respects subjects'
given consents. The evaluation results show the potential of our
approach for ex-ante usage policy compliance checking within the
Linked Widgets Platforms and beyond.
new challenges for companies, who must demonstrate that their
systems and business processes comply with usage constraints
specified by data subjects. However, due to the lack of standards,
tools, and best practices, many organizations struggle to adapt their
infrastructure and processes to ensure and demonstrate that all
data processing is in compliance with users' given consent. The
SPECIAL EU H2020 project has developed vocabularies that can
formally describe data subjects' given consent as well as methods
that use this description to automatically determine whether
processing of the data according to a given policy is compliant
with the given consent. Whereas this makes it possible to determine
whether processing was compliant or not, integration of the
approach into existing line of business applications and ex-ante
compliance checking remains an open challenge. In this short paper,
we demonstrate how the SPECIAL consent and compliance framework
can be integrated into Linked Widgets, a mashup platform, in
order to support privacy-aware ad-hoc integration of personal data.
The resulting environment makes it possible to create data integration
and processing workflows out of components that inherently
respect usage policies of the data that is being processed and are
able to demonstrate compliance. We provide an overview of the
necessary meta data and orchestration towards a privacy-aware
linked data mashup platform that automatically respects subjects'
given consents. The evaluation results show the potential of our
approach for ex-ante usage policy compliance checking within the
Linked Widgets Platforms and beyond.
Original language | English |
---|---|
Title of host publication | WWW '19 |
Subtitle of host publication | Companion Proceedings of the World Wide Web Conference |
Editors | Ling Liu, Ryen White |
Place of Publication | New York |
Publisher | Association for Computing Machinery |
Pages | 508-514 |
ISBN (Electronic) | 978-1-4503-6675-5 |
DOIs | |
Publication status | Published - 2019 |
Austrian Classification of Fields of Science and Technology (ÖFOS)
- 102
- 102001 Artificial intelligence
- 502050 Business informatics
- 102015 Information systems
Projects
- 2 Finished
-
Cyber-Physical Social Systems for City-wide Infrastructures
Cecconi, A. (Researcher), Di Ciccio, C. (Researcher), Fernandez Garcia, J. D. (Researcher), Mendling, J. (Researcher) & Polleres, A. (Researcher)
1/10/17 → 31/03/20
Project: Research funding
-
SPECIAL - Scalable Policy-awarE linked data arChitecture for prIvacy, trAnsparency and compLiance
Kirrane, S. (PI - Project head), Drozd, O. (Researcher), Fernandez Garcia, J. D. (Researcher), Havur, G. (Researcher), Polleres, A. (Researcher) & Spiekermann-Hoff, S. (Researcher)
1/01/17 → 31/12/19
Project: Research funding