论文标题
Special-K个人数据处理透明度和合规平台
The SPECIAL-K Personal Data Processing Transparency and Compliance Platform
论文作者
论文摘要
欧洲一般数据保护法规(GDPR)为必须确保其处理个人数据具有适当法律依据的公司带来新的挑战,并且必须就组织内部和组织之间的个人数据处理和共享提供透明度。此外,当涉及法律依据时,公司需要确保遵守数据主体指定的使用限制。本文介绍了在特殊的欧盟H2020项目中开发的政策语言和支持的本体和词汇,该项目可用于表示数据使用策略以及数据处理和共享事件。我们介绍了一种称为Special-K的具体透明度和合规架构,可自动验证数据处理和共享符合数据主体的同意。我们的评估基于新的合规基准,显示了系统和用户数量越来越多的系统的效率和可扩展性。
The European General Data Protection Regulation (GDPR) brings new challenges for companies who must ensure they have an appropriate legal basis for processing personal data and must provide transparency with respect to personal data processing and sharing within and between organisations. Additionally, when it comes to consent as a legal basis, companies need to ensure that they comply with usage constraints specified by data subjects. This paper presents the policy language and supporting ontologies and vocabularies, developed within the SPECIAL EU H2020 project, which can be used to represent data usage policies and data processing and sharing events. We introduce a concrete transparency and compliance architecture, referred to as SPECIAL-K, that can be used to automatically verify that data processing and sharing complies with the data subjects consent. Our evaluation, based on a new compliance benchmark, shows the efficiency and scalability of the system with increasing number of events and users.