Authors:
Mohammed Al-Obeidallah
1
;
Luca Piras
2
;
Onyinye Iloanugo
3
;
Haralambos Mouratidis
4
;
Duaa Alkubaisy
5
and
Daniele Dellagiacoma
6
Affiliations:
1
Department of Software Engineering, Al Ain University, Abu Dhabi, U.A.E.
;
2
School of Computing, Middlesex University, London, U. K.
;
3
School of Computing, Robert Gordon University, Aberdeen, U. K.
;
4
Institute for Analytics and Data Science, University of Essex, Colchester, U. K.
;
5
College of Applied Studies and Community Service, Imam Abdulrahman Bin Faisal University, Dammam, Saudi Arabia
;
6
Centre for Secure, Intelligent and Usable Systems, University of Brighton, Brighton, U. K.
Keyword(s):
Requirements Modeling, Requirements Engineering, Privacy-by-Design, Goal Modeling, GDPR, Design Patterns.
Abstract:
The introduction of the European General Data Protection Regulation (GDPR) has imposed obligations on organisations collecting data in the EU. This has been beneficial to citizens due to rights reinforcement achieved as data subjects. However, obligations heavily affected organisations, and their privacy requirements analysts, having issues with interpreting and implementing GDPR principles. This paper proposes visual GDPR Patterns supporting analysts through Privacy-by- Design (PbD) and GDPR compliance analysis. In order to achieve that, we extended a requirements modeling tool, SecTro, which is used to assist analysts in creating visual requirements models. Specifically, we extended SecTro with novel visual GDPR patterns representing GDPR principles. We evaluated the patterns in a healthcare case study. The evaluation results suggest that the GDPR patterns can help analysts in PbD modeling analysis, by representing GDPR principles and considering relevant ready-to-use alternatives,
towards achieving GDPR compliance.
(More)