论文标题
机器可理解的政策和GDPR合规性检查
Machine Understandable Policies and GDPR Compliance Checking
论文作者
论文摘要
欧洲一般数据保护法规(GDPR)要求采取技术和组织措施来支持其实施。为此,特殊的H2020项目旨在提供一组工具,这些工具可以由数据控制器和处理器使用,以自动检查个人数据处理和共享是否符合GDPR中规定的义务。该项目的主要贡献包括:(i)可用于表达同意,商业政策和监管义务的政策语言; (ii)可以使用两种不同的合规性检查方法来证明数据控制器 /处理器执行的数据处理符合数据主体提供的同意,以及符合GDPR中规定的监管义务的业务流程。
The European General Data Protection Regulation (GDPR) calls for technical and organizational measures to support its implementation. Towards this end, the SPECIAL H2020 project aims to provide a set of tools that can be used by data controllers and processors to automatically check if personal data processing and sharing complies with the obligations set forth in the GDPR. The primary contributions of the project include: (i) a policy language that can be used to express consent, business policies, and regulatory obligations; and (ii) two different approaches to automated compliance checking that can be used to demonstrate that data processing performed by data controllers / processors complies with consent provided by data subjects, and business processes comply with regulatory obligations set forth in the GDPR.