Authors:
Evangelia Vanezi
;
Georgia Kapitsaki
and
Anna Philippou
Affiliation:
Department of Computer Science, University of Cyprus, Cyprus
Keyword(s):
GDPR Purpose, Privacy by Design, System Requirements, Use Case Diagrams, Sequence Diagrams.
Abstract:
Protecting personal data within software systems is crucial, and as such, several privacy regulations have been enacted, one being the EU’s General Data Protection Regulation (GDPR). While GDPR emphasizes “Purpose Limitation” for rightful personal data handling, the concept of purpose lacks clarity in software development practices. Building on our previous work on DiálogoP, which supports the definition of formal processing purposes, this study introduces purpose-aware system requirements. We present AnálisisP, a methodology for integrating processing purposes into the software engineering requirements analysis phase and visual representations of these enhanced requirements by extending the Unified Modeling Language (UML) Use Case and Sequence diagrams. We show how our approach enables the integration of AnálisisP with DiálogoP towards formal models whose compliance with processing purposes is rigorously validated. Additionally, we showcase how the proposed extended diagrams assist
in addressing further GDPR-related system design queries.
(More)