arXiv:2503.07172cs.AIcs.LO2025-03

用法律规则自动验证数据处理是否合规,确保跨国数据共享安全透明。

Lawful and Accountable Personal Data Processing with GDPR-based Access and Usage Control in Distributed Systems

  • 结合专家判断与形式化逻辑,自动生成符合GDPR的数据处理合法性论证。
  • 在分布式系统中实现可审计的访问与使用控制,支持跨组织数据协作。
  • 适合需要合规审计的跨境数据平台、隐私保护系统开发者。

遵守GDPR隐私法规对组织处理个人数据带来巨大负担,尤其在跨组织边界的数据处理场景中更为突出。本文提出一种通用方法,通过自动化规范推理生成数据处理合法性的法律论证,基于隐私专家提供的具体法律认定,实现人机协同。该系统利用形式化本体与语义模型,基于GDPR的目的限制原则构建逻辑框架,并在eFLINT领域特定语言中实现。同时扩展了XACML架构标准,支持访问与使用控制,使基于GDPR的规范推理可嵌入现有或新型分布式数据处理系统。系统设计依据GDPR要求进行关键评估,具备可解释性、可追溯性与适应性,提升数据处理的透明度与问责能力。

原文摘要 · Abstract (English)

Compliance with the GDPR privacy regulation places a significant burden on organisations regarding the handling of personal data. The perceived efforts and risks of complying with the GDPR further increase when data processing activities span across organisational boundaries, as is the case in both small-scale data sharing settings and in large-scale international data spaces. This paper addresses these concerns by proposing a case-generic method for automated normative reasoning that establishes legal arguments for the lawfulness of data processing activities. The arguments are established on the basis of case-specific legal qualifications made by privacy experts, bringing the human in the loop. The obtained expert system promotes transparency and accountability, remains adaptable to extended or altered interpretations of the GDPR, and integrates into novel or existing distributed data processing systems. This result is achieved by defining a formal ontology and semantics for automated normative reasoning based on an analysis of the purpose-limitation principle of the GDPR. The ontology and semantics are implemented in eFLINT, a domain-specific language for specifying and reasoning with norms. The XACML architecture standard, applicable to both access and usage control, is extended, demonstrating how GDPR-based normative reasoning can integrate into (existing, distributed) systems for data processing. The resulting system is designed and critically assessed in reference to requirements extracted from the GPDR.

数据合规GDPR访问控制分布式系统

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。