Skip to main content

Research Repository

Advanced Search

Automating GDPR Compliance Verification for Cloud-hosted Services

Barati, Masoud; Rana, Omer; Theodorakopoulos, George

Authors

Masoud Barati

Omer Rana

George Theodorakopoulos



Abstract

Cloud-hosted business processes require access to customer data to complete a transaction, to improve a customer's on-line experience or provide useful product recommendations. However, privacy concerns associated with the use of this data have led to legal regulations that impose restrictions on how such data is requested or processed by an on-line service, with large penalties for violating these restrictions, e.g. the European General Data Protection Regulation (GDPR). We propose a framework for helping cloud-hosted services automate GDPR compliance checking. The framework comprises three steps: represent data flow in business processes with an appropriate abstraction (timed transition systems), formalise GDPR rules and obligations and incorporate them into the same abstraction, and implement the abstraction in a model checking tool (Uppaal) in order to automatically verify compliance of business process activities with GDPR. We demonstrate the approach using a cloud-based purchase order system.

Citation

Barati, M., Rana, O., & Theodorakopoulos, G. (2020, October). Automating GDPR Compliance Verification for Cloud-hosted Services. Presented at 2020 International Symposium on Networks, Computers and Communications (ISNCC), Montreal, QC, Canada

Presentation Conference Type Conference Paper (published)
Conference Name 2020 International Symposium on Networks, Computers and Communications (ISNCC)
Start Date Oct 20, 2020
End Date Oct 22, 2020
Online Publication Date Dec 25, 2020
Publication Date 2020
Deposit Date May 4, 2021
Publisher Institute of Electrical and Electronics Engineers
Book Title 2020 International Symposium on Networks, Computers and Communications (ISNCC)
ISBN 9781728156286
DOI https://doi.org/10.1109/isncc49221.2020.9297309
Keywords timed automaton, business process models, verification, data privacy
Public URL http://researchrepository.napier.ac.uk/Output/2767122