Skip to main content
Top

2021 | OriginalPaper | Chapter

CompLicy: Evaluating the GDPR Alignment of Privacy Policies - A Study on Web Platforms

Authors : Evangelia Vanezi, George Zampa, Christos Mettouris, Alexandros Yeratziotis, George A. Papadopoulos

Published in: Research Challenges in Information Science

Publisher: Springer International Publishing

Activate our intelligent search to find suitable subject content or patents.

search-config
loading …

Abstract

The European Union General Data Protection Regulation (GDPR) came into effect on May 25, 2018, imposing new rights and obligations for the collection and processing of EU citizens personal data. Inevitably, privacy policies of systems handling such data are required to be adapted accordingly. Specific rights and provisions are now required to be communicated to the users, as specified in GDPR Articles 12-14. This work aims to provide insights on whether privacy policies are aligned to the GDPR in this regard, i.e., including the needed information, formulated in sets of terms, by studying the paradigm of web platforms. We present: (1) a defined set of 89 terms, in 7 groups that need to be included within a systems’ privacy policy, resulting from a study of the GDPR and from an examination and analysis of real-life web platforms privacy policies; (2) the CompLicy tool, which as a first step crawls a given web platform, to infer whether a privacy policy page exists and, if it does, subsequently parses it, identifying GDPR terms and groups within, and finally, providing results for the inclusion of the necessary GDPR information within the aforementioned policy; (3) the evaluation of 148 existing web platforms, from 5 different sectors: (i) banking, (ii) e-commerce, (iii) education, (iv) travelling, and (v) social media, presenting the results .

Dont have a licence yet? Then find out more about our products and how to get one now:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literature
2.
go back to reference Contissa, G., et al.: CLAUDETTE meets GDPR: Automating the evaluation of privacy policies using artificial intelligence. SSRN 3208596 (2018) Contissa, G., et al.: CLAUDETTE meets GDPR: Automating the evaluation of privacy policies using artificial intelligence. SSRN 3208596 (2018)
3.
go back to reference European Parliament and Council of the European Union: Charter of fundamental rights of the European union. Official Journal of the European Union (2012) European Parliament and Council of the European Union: Charter of fundamental rights of the European union. Official Journal of the European Union (2012)
4.
go back to reference European Parliament and Council of the European Union: General data protection regulation. Official Journal of the European Union (2015) European Parliament and Council of the European Union: General data protection regulation. Official Journal of the European Union (2015)
5.
go back to reference Hadar, I., et al.: Privacy by designers: software developers’ privacy mindset. Empirical Softw. Eng. 23(1), 259–289 (2018)CrossRef Hadar, I., et al.: Privacy by designers: software developers’ privacy mindset. Empirical Softw. Eng. 23(1), 259–289 (2018)CrossRef
7.
go back to reference Linden, T., Khandelwal, R., Harkous, H., Fawaz, K.: The privacy policy landscape after the GDPR. Priv. Enhanc. Technol. 2020(1), 47–64 (2020)CrossRef Linden, T., Khandelwal, R., Harkous, H., Fawaz, K.: The privacy policy landscape after the GDPR. Priv. Enhanc. Technol. 2020(1), 47–64 (2020)CrossRef
9.
go back to reference Renaud, K., Shepherd, L.A.: How to make privacy policies both GDPR-compliant and usable. In: International Conference on Cyber Situational Awareness, Data Analytics and Assessment, pp. 1–8. IEEE (2018) Renaud, K., Shepherd, L.A.: How to make privacy policies both GDPR-compliant and usable. In: International Conference on Cyber Situational Awareness, Data Analytics and Assessment, pp. 1–8. IEEE (2018)
10.
go back to reference Tesfay, W.B., Hofmann, P., Nakamura, T., Kiyomoto, S., Serna, J.: I read but don’t agree: Privacy policy benchmarking using machine learning and the EU GDPR. In: The Web Conference, pp. 163–166 (2018) Tesfay, W.B., Hofmann, P., Nakamura, T., Kiyomoto, S., Serna, J.: I read but don’t agree: Privacy policy benchmarking using machine learning and the EU GDPR. In: The Web Conference, pp. 163–166 (2018)
11.
go back to reference Tesfay, W.B., Hofmann, P., Nakamura, T., Kiyomoto, S., Serna, J.: PrivacyGuide: towards an implementation of the EU GDPR on internet privacy policy evaluation. In: International Workshop on Security and Privacy Analytics. pp. 15–21 (2018) Tesfay, W.B., Hofmann, P., Nakamura, T., Kiyomoto, S., Serna, J.: PrivacyGuide: towards an implementation of the EU GDPR on internet privacy policy evaluation. In: International Workshop on Security and Privacy Analytics. pp. 15–21 (2018)
12.
go back to reference Torre, D., Abualhaija, S., Sabetzadeh, M., Briand, L., Baetens, K., Goes, P., Forastier, S.: An AI-assisted approach for checking the completeness of privacy policies against GDPR. In: International Requirements Engineering Conference, pp. 136–146. IEEE (2020) Torre, D., Abualhaija, S., Sabetzadeh, M., Briand, L., Baetens, K., Goes, P., Forastier, S.: An AI-assisted approach for checking the completeness of privacy policies against GDPR. In: International Requirements Engineering Conference, pp. 136–146. IEEE (2020)
13.
go back to reference Vanezi, E., et al.: GDPR Compliance in the Design of the INFORM e-learning platform: a case study. In: International Conference on Research Challenges in Information Science, pp. 1–12. IEEE (2019) Vanezi, E., et al.: GDPR Compliance in the Design of the INFORM e-learning platform: a case study. In: International Conference on Research Challenges in Information Science, pp. 1–12. IEEE (2019)
Metadata
Title
CompLicy: Evaluating the GDPR Alignment of Privacy Policies - A Study on Web Platforms
Authors
Evangelia Vanezi
George Zampa
Christos Mettouris
Alexandros Yeratziotis
George A. Papadopoulos
Copyright Year
2021
DOI
https://doi.org/10.1007/978-3-030-75018-3_10

Premium Partner