A Methodology to Validate Compliance to the GDPR

dc.contributor.authorEkdahl, Axel
dc.contributor.authorNyman, Lídia
dc.contributor.departmentChalmers tekniska högskola / Institutionen för data och informationstekniksv
dc.contributor.examinerSteghöfer, Jan-Philipp
dc.contributor.supervisorScandariato, Riccardo
dc.date.accessioned2019-11-19T09:38:53Z
dc.date.available2019-11-19T09:38:53Z
dc.date.issued2018sv
dc.date.submitted2019
dc.description.abstractThis study analyses two state-of-the-art methodologies for eliciting privacy threats in software contexts, LINDDUN and PIA. A first goal is to understand the limitations of these methodologies in terms of compliance to the provisions of the robust General Data Protection Regulation (GDPR). A second goal is to improve the first methodology by addressing its limitations and proving a more complete coverage with regards to the regulation. The study is divided into two phases; an analysis of the current coverage of the two methodologies and the development of an extended version of LINDDUN. The extended LINDDUN includes a privacy-aware Data Flow Diagram and extensions of the Content Unawareness and Policy and Noncompliance threat trees, as well as developed rules for defining where in a software design a privacy threat commonly exists. It was observed that PIA was considered more effective than LINDDUN in identifying design issues related to GDPR. While the extended version of LINDDUN showed to provide a more complete coverage than the original LINDDUN.sv
dc.identifier.coursecodeDATX05sv
dc.identifier.urihttps://hdl.handle.net/20.500.12380/300549
dc.language.isoengsv
dc.setspec.uppsokTechnology
dc.subjectPrivacysv
dc.subjectPrivacy Threat Modelingsv
dc.subjectGDPRsv
dc.subjectLINDDUNsv
dc.subjectPIAsv
dc.subjectGDPR compliancesv
dc.subjectPrivacy Impact Assessmentsv
dc.titleA Methodology to Validate Compliance to the GDPRsv
dc.type.degreeExamensarbete för masterexamensv
dc.type.uppsokH

Ladda ner

Original bundle

Visar 1 - 1 av 1
Hämtar...
Bild (thumbnail)
Namn:
CSE 18-78 CPL GUPEA 62557 Nyman_Ekdahl.pdf
Storlek:
2.04 MB
Format:
Adobe Portable Document Format
Beskrivning:
A Methodology to Validate Compliance to the GDPR

License bundle

Visar 1 - 1 av 1
Hämtar...
Bild (thumbnail)
Namn:
license.txt
Storlek:
1.14 KB
Format:
Item-specific license agreed upon to submission
Beskrivning: