Modeling ecosystems of reference frameworks for assurance: a case on privacy impact assessment regulation and guidelines

Alejandra Ruiz, Yod Samuel Martin, Jabier Martinez*, Jacobo Quintans, Guillaume Mockly, Amelie Gyrard, Tommaso Crepax

*Corresponding author for this work

Research output: Contribution to journalArticlepeer-review

Abstract

To assure certain critical quality properties (e.g., safety, security, or privacy), supervisory authorities and industrial associations provide reference frameworks such as standards or guidelines that in some cases are enforced (e.g., regulations). Given the pace at which both technical advancements and risks appear, there is an increase in the number of reference frameworks. As several frameworks might apply for same systems, certain overlaps appear (e.g., regulations for different countries where the system will operate, or generic standards in conjunction with more concrete standards for a given industrial sector or system type). We propose the use of modelling for alleviating the complexity of these reference frameworks ecosystems, and we provide a tool-supported method to create them for the benefit of different stakeholders. The case study is based on privacy data protection, and more concretely on privacy impact assessment processes. The European GDPR regulates the movement and processing of personal data, and, contrary to available software engineering privacy guidelines, articles in legal texts are usually difficult to translate to the underlying processes, artefacts and roles that they refer to. To facilitate the mutual comprehension of legal experts and engineers, in this work we investigate how mappings can be created between these two domains of expertise. Notably, we rely on modelling as a central point. We modelled the legal requirements of the GDPR on data protection impact assessments, and then, we selected the ISO/IEC 29134, a mainstream engineering guideline for privacy impact assessment, and, taking a concrete sector as example, the EU Smart Grid Data Protection Impact Assessment template. The OpenCert tool was used for providing technical support to both the modelling and the creation of the mapping models in a systematic way. We provide a qualitative evaluation from legal experts and privacy engineering practitioners to report on the benefits and limitations of this approach.

Original languageEnglish
Pages (from-to)1175-1196
Number of pages22
JournalSoftware and Systems Modeling
Volume22
Issue number4
DOIs
Publication statusPublished - Aug 2023

Keywords

  • GDPR
  • ISO 29134
  • Modelling
  • OpenCert
  • Privacy
  • Privacy impact assessment
  • Reference frameworks
  • Smart grid

Fingerprint

Dive into the research topics of 'Modeling ecosystems of reference frameworks for assurance: a case on privacy impact assessment regulation and guidelines'. Together they form a unique fingerprint.

Cite this