Model Driven Engineering for Data Protection and Privacy: Application\n and Experience with GDPR
In Europe and indeed worldwide, the General Data Protection Regulation (GDPR)\nprovides protection to individuals regarding their personal data in the face of\nnew technological developments. GDPR is widely viewed as the benchmark for data\nprotection and privacy regulations that harmonizes data privacy laws across\nEurope. Although the GDPR is highly beneficial to individuals, it presents\nsignificant challenges for organizations monitoring or storing personal\ninformation. Since there is currently no automated solution with broad\nindustrial applicability, organizations have no choice but to carry out\nexpensive manual audits to ensure GDPR compliance. In this paper, we present a\ncomplete GDPR UML model as a first step towards designing automated methods for\nchecking GDPR compliance. Given that the practical application of the GDPR is\ninfluenced by national laws of the EU Member States, we suggest a two-tiered\ndescription of the GDPR, generic and specialized. In this paper, we provide (1)\nthe GDPR conceptual model we developed with complete traceability from its\nclasses to the GDPR, (2) a glossary to help understand the model, (3) the\nplain-English description of 35 compliance rules derived from GDPR along with\ntheir encoding in OCL, and (4) the set of 20 variations points derived from\nGDPR to specialize the generic model. We further present the challenges we\nfaced in our modeling endeavor, the lessons we learned from it, and future\ndirections for research.\n