首页> 外文期刊>Information management & computer security >Privacy, security, legal and technology acceptance elicited and consolidated requirements for a GDPR compliance platform
【24h】

Privacy, security, legal and technology acceptance elicited and consolidated requirements for a GDPR compliance platform

机译:隐私,安全,法律和技术验收引发和合并要求对GDPR合规平台的要求

获取原文
获取原文并翻译 | 示例

摘要

Purpose - General data protection regulation (GDPR) entered into force in May 2018 for enhancing personal data protection. Even though GDPR leads toward many advantages for the data subjects it turned out to be a significant challenge. Organizations need to implement long and complex changes to become GDPR compliant. Data subjects are empowered with new rights, which, however, they need to become aware of. GDPR compliance is a challenging matter for the relevant stakeholders calls for a software platform that can support their needs. The aim of data governance for supporting GDPR (DEFeND) EU project is to deliver such a platform. The purpose of this paper is to describe the process, within the DEFeND EU project, for eliciting and analyzing requirements for such a complex platform. Design/methodology/approach - The platform needs to satisfy legal and privacy requirements and provide functionalities that data controllers request for supporting GDPR compliance. Further, it needs to satisfy acceptance requirements, for assuring that its users will embrace and use the platform. In this paper, the authors describe the methodology for eliciting and analyzing requirements for such a complex platform, by analyzing data attained by stakeholders from different sectors. Findings - The findings provide the process for the DEFeND platform requirements' elicitation and an indicative sample of those. The authors also describe the implementation of a secondary process for consolidating the elicited requirements into a consistent set of platform requirements. Practical implications - The proposed software engineering methodology and data collection tools (i.e. questionnaires) are expected to have a significant impact for software engineers in academia and industry. Social implications - It is reported repeatedly that data controllers face difficulties in complying with the GDPR. The study aims to offer mechanisms and tools that can assist organizations to comply with the GDPR, thus, offering a significant boost toward the European personal data protection objectives. Originality/value - This is the first paper, according to the best of the authors' knowledge, to provide software requirements for a GDPR compliance platform, including multiple perspectives.
机译:目的 - 2018年5月在2018年5月生效的一般数据保护条例以提高个人数据保护。尽管GDPR导致数据受试者的许多优势,但事实证明这是一个重大挑战。组织需要实现长期和复杂的更改,以成为符合GDPR的。数据受试者赋予新权利,但是,他们需要了解。 GDPR合规是相关利益相关者呼吁支持其需求的软件平台的具有挑战性。支持GDPR(捍卫)欧盟项目的数据治理的目的是提供这样的平台。本文的目的是描述捍卫欧盟项目中的过程,以诱因和分析这一复杂平台的要求。设计/方法/方法 - 平台需要满足法律和隐私要求,并提供数据控制器请求支持GDPR合规性的功能。此外,它需要满足验收要求,以确保其用户将拥抱和使用平台。在本文中,作者描述了通过分析来自不同部门的利益攸关方获得的数据来描述对这种复杂平台的要求的诱因和分析要求的方法。调查结果 - 调查结果提供了防守平台要求的诱导和指示性样本的过程。作者还描述了实施次要进程,以将引发要求巩固到一致的平台要求集中。实际意义 - 建议的软件工程方法和数据收集工具(即问卷调查)预计对学术界和工业的软件工程师产生重大影响。社会影响 - 据符合数据控制器在遵守GDPR方面面临困难。该研究旨在提供能够协助组织遵守GDPR的机制和工具,从而提供朝向欧洲个人数据保护目标的显着提升。原创性/值 - 这是第一个纸张,根据作者的知识,为GDPR合规平台提供软件要求,包括多个观点。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号