2019
DOI: 10.1007/978-3-030-22312-0_24
|View full text |Cite
|
Sign up to set email alerts
|

Automatically Proving Purpose Limitation in Software Architectures

Abstract: The principle of purpose limitation is one of the corner stones in the European General Data Protection Regulation. Automatically verifying whether a software architecture is capable of collecting, storing, or otherwise processing data without a predefined, precise, and valid purpose, and more importantly, whether the software architecture allows for re-purposing the data, greatly helps designers, makers, auditors, and customers of software. In our case study, we model the architecture of an existing medical r… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1

Citation Types

0
3
0
1

Year Published

2020
2020
2023
2023

Publication Types

Select...
3
2
1

Relationship

3
3

Authors

Journals

citations
Cited by 6 publications
(4 citation statements)
references
References 15 publications
0
3
0
1
Order By: Relevance
“…The study was approved by the ethical committee at the medical association in Hamburg, Germany (PV5691) as well as 18 additional ethical committees in Germany. The European Union (EU) General Data Protection Regulation (GDPR) compliant GermanVasc registry platform was developed to follow the principles of privacy by design while collecting the personal and medical data relevant for the current study [ 23 , 24 , 25 ]. Results were reported using the STrengthening the Reporting of OBservational studies in Epidemiology (STROBE) statement [ 26 ].…”
Section: Methodsmentioning
confidence: 99%
“…The study was approved by the ethical committee at the medical association in Hamburg, Germany (PV5691) as well as 18 additional ethical committees in Germany. The European Union (EU) General Data Protection Regulation (GDPR) compliant GermanVasc registry platform was developed to follow the principles of privacy by design while collecting the personal and medical data relevant for the current study [ 23 , 24 , 25 ]. Results were reported using the STrengthening the Reporting of OBservational studies in Epidemiology (STROBE) statement [ 26 ].…”
Section: Methodsmentioning
confidence: 99%
“…A total of 18 ethical committees in affected German federal states confirmed the initial approval by the leading ethical committee at the medical association in Hamburg, Germany (PV5691). The European Union (EU) General Data Protection Regulation (GDPR) compliant GermanVasc registry platform was developed to follow the principles of privacy by design while collecting the personal and medical data relevant for the current study [11,15,16]. Results were reported using the STrengthening the Reporting of OBservational studies in Epidemiology (STROBE) statement [17].…”
Section: Methodsmentioning
confidence: 99%
“…Fasst man die Entwicklungen der letzten zwei Jahrzehnte zusammen, ergibt sich eine große Chance, aber auch Herausforderung für wissenschaftsorientierte Registerinitiativen: die datenschutzkonforme und privatsphärefreundliche Sammlung von unverzerrten sowie validen Langzeitdaten zur Medizinprodukteevaluation [12][13][14][15]. Dabei sind über die beiden Reformen hinaus weitere Anpassungen des EU-Rechts zu berücksichtigen, die sich teilweise erst in den nächsten Jahren auswirken werden.…”
unclassified