Authors:
André Ribeiro
1
and
Alberto Rodrigues da Silva
2
Affiliations:
1
INESC-ID and Instituto Superior Técnico, Portugal
;
2
Universidade de Lisboa, Portugal
Keyword(s):
Privacy Policy, Requirements Specification, Domain Specific Language, Software Tool.
Related
Ontology
Subjects/Areas/Topics:
Enterprise Information Systems
;
Information Systems Analysis and Specification
;
Requirements Analysis And Management
Abstract:
Popular software applications collect and retain a lot of users’ information, part of which is personal and sensitive. To assure that only the desired information is made public, these applications have to define and publish privacy policies that describe how they manage and disclose this information. Problems arise when privacy policies are misinterpreted, for instance because they contain ambiguous and inconsistent statements, what results in a defective application of the policy enforcement mechanisms. The RSLingo4Privacy approach aims to improve the specification and analysis of such policies. This paper presents and discusses its companion tool, the RSLingo4Privacy Studio, which materializes this approach by providing the technological support for users being able to specify, analyze and publish policies based on the RSL-IL4Privacy domain specific language. We validated its feasibility using popular websites policies such as Dropbox, Facebook, IMDB, LinkedIn, Twitter and Zynga.
We conclude this paper with a discussion of the related work, namely a comparative analysis of pros and cons of RSLingo4Privacy Studio with other previous proposals.
(More)