Abstract
The processing of personal data is becoming a key business factor, especially for high-tech system industries such as automotive and healthcare service providers. To protect such data, the European Union (EU) has introduced the General Data Protection Regulation (GDPR), with the aim to standardize and strengthen data protection policies across EU countries. The GDPR defines stringent requirements on the collection and processing of personal data and imposes severe fines and penalties on data controllers and processors for non-compliance. Although the GDPR is enforce since 2018, many public and private organizations are still struggling to fully comply with the regulation. A main reason for this is the lack of usable methodologies that can support developers in designing of GDPR-complaint high-tech systems. This paper examines the growing literature on methodologies for the design of privacy-aware systems, and identifies the main challenges to be addressed in order to facilitate developers in the design of such systems. In particular, we investigate to what extent existing methodologies (i) cover GDPR and privacy-by-design principles, (ii) address different levels of system design concerns, and (iii) have demonstrated their suitability for the purpose. Our literature study shows that the domain landscape appears to be heterogeneous and disconnected, as existing methodologies often focus only on subsets of the GDPR principles and/or on specific angles of system design. Based on our findings, we provide recommendations on the definition of comprehensive methodologies tailored to designing GDPR-compliant high-tech systems.
| Original language | English |
|---|---|
| Title of host publication | Proceedings of the 15th International Conference on Availability, Reliability and Security, ARES 2020 |
| Publisher | Association for Computing Machinery, Inc. |
| ISBN (Electronic) | 9781450388337 |
| DOIs | |
| Publication status | Published - 25 Aug 2020 |
| Event | 15th International Conference on Availability, Reliability and Security, ARES 2020 - Virtual, Online, Ireland Duration: 25 Aug 2020 → 28 Aug 2020 |
Conference
| Conference | 15th International Conference on Availability, Reliability and Security, ARES 2020 |
|---|---|
| Country/Territory | Ireland |
| City | Virtual, Online |
| Period | 25/08/20 → 28/08/20 |
Funding
This work is supported by the H2020-ECSEL programme of the European Commission through the SECREDAS project (grant no. 783119).
| Funders | Funder number |
|---|---|
| European Union's Horizon 2020 - Research and Innovation Framework Programme | |
| European Commission | 783119 |
Keywords
- GDPR
- Privacy-by-design
- System engineering
- Systematic literature review
Fingerprint
Dive into the research topics of 'SoK: Engineering privacy-aware high-tech systems'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver