论文标题
倾斜:与GDPR一致的透明度信息语言和工具包用于实用隐私工程
TILT: A GDPR-Aligned Transparency Information Language and Toolkit for Practical Privacy Engineering
论文作者
论文摘要
在本文中,我们介绍了透明度信息语言和工具包明确设计的透明度信息语言和工具包,旨在根据GDPR的要求表示和处理透明度信息,并允许比确定的法律数据保护政策更自动化和自适应使用此类信息。 我们对GDPR的透明度义务进行了详细的分析,以确定旨在满足各自法律要求的正式透明语言所需的表现力。此外,我们确定了一组进一步的非功能要求,需要满足以促进现实世界(Web)信息系统工程中的实际采用。在此基础上,我们指定了我们的形式语言,并围绕它提供了一个各自实现的工具包。然后,我们评估语言和工具包的实际适用能力,并通过两种不同的用例证明其解锁的其他前景:a)对个人数据相关实践的组织间分析,允许例如,可以根据明确宣布的透明信息信息发现数据共享网络,并通过明确宣布的透明信息,并通过新的近距离信息进行了跨越的临时信息,并具有更全面的数据,并介绍了更全面的信息,并将其介绍,并全面地介绍,并将其介绍,以及更多的信息。受试者对与数据相关的实践的实际知情,因此是他们的主权。 总的来说,我们的透明度信息语言和工具包与以前的工作不同 - 表达透明度信息根据现代(Web)信息系统工程的实际法律要求和实践一致,从而为在实践中增强透明度和用户主权的多种新颖可能性铺平了道路。
In this paper, we present TILT, a transparency information language and toolkit explicitly designed to represent and process transparency information in line with the requirements of the GDPR and allowing for a more automated and adaptive use of such information than established, legalese data protection policies do. We provide a detailed analysis of transparency obligations from the GDPR to identify the expressiveness required for a formal transparency language intended to meet respective legal requirements. In addition, we identify a set of further, non-functional requirements that need to be met to foster practical adoption in real-world (web) information systems engineering. On this basis, we specify our formal language and present a respective, fully implemented toolkit around it. We then evaluate the practical applicability of our language and toolkit and demonstrate the additional prospects it unlocks through two different use cases: a) the inter-organizational analysis of personal data-related practices allowing, for instance, to uncover data sharing networks based on explicitly announced transparency information and b) the presentation of formally represented transparency information to users through novel, more comprehensible, and potentially adaptive user interfaces, heightening data subjects' actual informedness about data-related practices and, thus, their sovereignty. Altogether, our transparency information language and toolkit allow - differently from previous work - to express transparency information in line with actual legal requirements and practices of modern (web) information systems engineering and thereby pave the way for a multitude of novel possibilities to heighten transparency and user sovereignty in practice.