yielded specific and relevant scores that can be used
to drive corrective actions. The use of data driven
inputs from heterogeneous sources and the mapping
of business processes into the evaluation tool using
agreed semantic standards would remove qualitative
user inputs and would improve inputs to the
evaluation tool. This would remove subjectivity and
improve the quality of the outputs.
7 CONCLUSIONS
Organisations are accountable for the demonstration
of their compliance with the GDPR regulation. We
have seen that the available compliance tools go some
way to achieving this goal, but each have their
shortcomings. A RegTech approach to GDPR
compliance has shown that the use of technology to
improve compliance monitoring and reporting can be
achieved when flexible, agile, cost effective,
extensible and informative tools are combined. The
opportunities to further develop GDPR compliance
tools exists if agreed semantic standards (Butler,
2019) are developed to automate processes and
remove subjectivity from data inputs. We conducted
a proof of concept to demonstrate the application of
some of these RegTech approaches to GDPR
Compliance. A GDPR compliance tool was
developed to monitor and analyse organisational
compliance that yielded a GDPR compliance output
for an organisation. The compliance report that was
generated from the evaluation tool can be used to
identify GDPR areas where the organisation is not
compliant, to trend their progress towards GDPR
compliance over time and to benchmark performance
versus other organisations. The DPO can use the
results to direct resources to areas of non-compliance
and improve their score, thus reducing the risk of
GDPR fines. We have shown that a RegTech
approach to GDPR can enable an organisation to meet
its obligations to comply with the accountability
principle.
ACKNOWLEDGEMENTS
This work is partially supported by Uniphar PLC.,
and the ADAPT Centre for Digital Content
Technology which is funded under the SFI Research
Centres Programme (Grant 13/RC/2106) and is co-
funded under the European Regional Development
Fund.
REFERENCES
Arner, D., Barberis, J., Buckley, R., 2016 FinTech,
RegTech, and the Reconceptualization of Financial
Regulation
Article 29 Data Protection Working Party 2010 Opinion
3/2010 on the principle of accountability
Article 8 Charter of Fundamental Rights of The European
Union, 2012, Official Journal of European Union
Bamberger, K. A. 2009. Technologies of compliance: Risk
and regulation in a digital age. Texas Law Review.
Bamberger, K., Mulligan, D., 2015, Privacy on the Ground:
Driving Corporate Behaviour in United States and
Europe
Boven’s, M, 2007 Analysing and Assessing
Accountability: A Conceptual Framework,
Butler, T., O’Brien, L., 2019 Understanding RegTech for
Digital Regulatory Compliance, Disrupting Finance,
Buttarelli, G, 2016. The EU GDPR as a Clarion Call for a
New Global Digital Gold Standard’ International Data
Privacy Law, 77–78
Centre for Information Policy Leadership, 2018, The Case
for Accountability: How it Enables Effective Data
Protection and Trust in the Digital Society
Colaert, V., 2017 RegTech as a response to regulatory
expansion in the financial sector,
Craig, D., 2019. The augmented compliance office (The
RegTech Book)
Cyganiak, 2014 https://www.w3.org/TR/vocab-data-cube/
Da Conceicao Freitas. M., Silva M., 2018. GDPR
compliance in SME’s: There is much to be done,
Journal of Information Systems Engineering and
Management
Data Protection Commission (2018)
https://www.dataprotection.ie/en/organisations/self-
assessment-checklist
Deloitte, 2016, Compliance modernization is no longer
optional
Drewer, D., Miladinova, V., (2018) The canary in the data
mine, Computer Law and Security Review 34, 806-815
Eckerson, W., 2010 Performance Dashboards: Measuring,
Monitoring, and Managing Your Business, 2nd edition,
Felici, M., Koulouris, T., Pearson, S., 2013, Accountability
for Data Governance in Cloud Ecosystems,
Heimes, R., 2016 Top 10 operational impacts of the GDPR:
Part 2 – The mandatory DPO
Humphrey, W. S. 2002. Three process perspectives:
Organizations, teams, and people. Annals of Software
Engineering 4:39-72.
IAPP 2018 Privacy tech vendor report,
https://iapp.org/resources/article/
2018-privacy-tech-vendor-report/
IAPP 2019 The GDPR Maturity Framework
<https://iapp.org/resources/article/the-gdpr-maturity-
framework/>
Johansson, E., Sutinen, K., Lassila, J., Lang, V., Eds.
Martikainen M., Lehner, OM., 2019. RegTech- A
Necessary Tool to Keep up with Compliance and
Regulatory Changes?
ICEIS 2020 - 22nd International Conference on Enterprise Information Systems
794