2018
DOI: 10.1007/978-3-030-02547-2_8
|View full text |Cite
|
Sign up to set email alerts
|

Legislative Compliance Assessment: Framework, Model and GDPR Instantiation

Abstract: Legislative compliance assessment tools are commonly used by companies to help them to understand their legal obligations. One of the primary limitations of existing tools is that they tend to consider each regulation in isolation. In this paper, we propose a flexible and modular compliance assessment framework that can support multiple legislations. Additionally, we describe our extension of the Open Digital Rights Language (ODRL) so that it can be used not only to represent digital rights but also legislativ… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
27
0

Year Published

2019
2019
2020
2020

Publication Types

Select...
5
1

Relationship

2
4

Authors

Journals

citations
Cited by 32 publications
(27 citation statements)
references
References 19 publications
0
27
0
Order By: Relevance
“…However, as mentioned earlier, the test-based approach can also be used with existing representations by adding semantics to the test results and reports to link them with relevant information such as the articles in GDPR. This is also applicable towards persisting outputs of reports generated from tools [1] and conformity assessments (CAP) [6].…”
Section: Discussionmentioning
confidence: 99%
See 2 more Smart Citations
“…However, as mentioned earlier, the test-based approach can also be used with existing representations by adding semantics to the test results and reports to link them with relevant information such as the articles in GDPR. This is also applicable towards persisting outputs of reports generated from tools [1] and conformity assessments (CAP) [6].…”
Section: Discussionmentioning
confidence: 99%
“…Subset of Constraints and Assumptions regarding Given Consent are involved. For example, informed consent requires the request to be clear and unambiguous -which needs to be evaluated manually 1 .…”
Section: Generating Constraints From Requirementsmentioning
confidence: 99%
See 1 more Smart Citation
“…[30]), has demonstrated its potential as a general policy language. For instance, researchers have hinted as it how it could be used to express: access policies [33]; requests, data offers and agreements [32]; and basic regulatory policies [1]. While, Fornara and Colombetti [12] consider how to add obligations to (an earlier version) of ODRL and subsequently in Fornara et al [13] how to reason over such ODRL extensions, using additional ontologies and semantic rules.…”
Section: Related Workmentioning
confidence: 99%
“…From a GDPR compliance perspective, there exist several compliance tools (cf. [17], [18], [19], [20]) that enable companies to assess the compliance of their applications and business processes via predefined questionnaires. Additionally, there is a body of work that focuses on modelling the text of the GDPR in a manner that supports legal reasoning and compliance checking [21], [22], [23], [24], [25].…”
Section: Related Workmentioning
confidence: 99%