Authors:
Mário Fernandes
1
;
Alberto Rodrigues Silva
1
and
António Gonçalves
2
Affiliations:
1
Universidade de Lisboa, Portugal
;
2
Universidade de Lisboa, Escola Superior de Tecnologia de Setúbal and Instituto Politécnico de Setúbal, Portugal
Keyword(s):
Personal Data Protection, Requirements Specification, Rslingo, Regulation (EU) 2016/679, GDPR.
Related
Ontology
Subjects/Areas/Topics:
Enterprise Information Systems
;
Information Systems Analysis and Specification
;
Requirements Analysis And Management
Abstract:
The European Union establishes in the Regulation 2016/679, or GDPR (General Data Protection Regulation), a set of legal dispositions to achieve the protection of natural persons in what personal data processing and the free movement of such data is concerned. When those dispositions are considered in the development of information systems, the later become attainable for legal approval within that scope. This paper presents the methodology we are following to elaborate a reusable catalogue of personal data protection requirements aligned with the GDPR. Following a separation-of-concerns approach, the catalogue shall serve the purpose of constructing information systems able to communicate with those that process individuals’ personal data, to materialize the regulatory data protection capabilities disposed in the GDPR. In that context, the elicitation of system requirements demands for the interpretation of a legal document by business analysts, which consists of a scientifically rel
evant challenge. This research is contextualized by the RSLingo initiative, a model-driven requirements engineering approach for the rigorous specification of system requirements. In particular this paper discusses the GDPR’s requirements defined as a catalogue of both business goals and system goals.
(More)