论文标题

迈向GDPR处理活动登记册的语义模型

Towards a Semantic Model of the GDPR Register of Processing Activities

论文作者

Ryan, Paul, Pandit, Harshvardhan J., Brennan, Rob

论文摘要

GDPR合规性的核心要求是维护处理活动登记册(ROPA)。我们对来自欧盟数据保护调节器的六个ROPA模板的分析表明,ROPA的范围和粒度在不同司法管辖区的指导范围很大。我们根据分析模板的共同概念和关系提出了一个合并的数据模型。然后,我们分析使用数据隐私词汇的程度 - GDPR的词汇规范。我们表明,DPV当前没有提供足够的概念来表示ROPA数据模型,并提出了一个扩展程序来填补此空白。这将使创建一个pan-eu信息管理框架,以实现组织和监管机构之间的互操作性以达到GDPR合规性。

A core requirement for GDPR compliance is the maintenance of a register of processing activities (ROPA). Our analysis of six ROPA templates from EU data protection regulators shows the scope and granularity of a ROPA is subject to widely varying guidance in different jurisdictions. We present a consolidated data model based on common concepts and relationships across analysed templates. We then analyse the extent of using the Data Privacy Vocabulary - a vocabulary specification for GDPR. We show that the DPV currently does not provide sufficient concepts to represent the ROPA data model and propose an extension to fill this gap. This will enable creation of a pan-EU information management framework for interoperability between organisations and regulators for GDPR compliance.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源