Show simple item record

dc.contributor.authorPandit, Harshvardhanen
dc.contributor.authorBrennan, Roben
dc.date.accessioned2022-05-11T08:02:30Z
dc.date.available2022-05-11T08:02:30Z
dc.date.issued2022en
dc.date.submitted2022en
dc.identifier.citationPaul Ryan, Rob Brennan, Harshvardhan J. Pandit, DPCat: Specification for an Interoperable and Machine-Readable Data Processing Catalogue Based on GDPR, Information, 13, 5, 2022en
dc.identifier.otherYen
dc.descriptionPUBLISHEDen
dc.description.abstractThe GDPR requires Data Controllers and Data Protection Officers (DPO) to maintain a Register of Processing Activities (ROPA) as part of overseeing the organisation’s compliance processes. The ROPA must include information from heterogeneous sources such as (internal) departments with varying IT systems and (external) data processors. Current practices use spreadsheets or proprietary systems that lack machine-readability and interoperability, presenting barriers to automation. We propose the Data Processing Catalogue (DPCat) for the representation, collection and transfer of ROPA information, as catalogues in a machine-readable and interoperable manner. DPCat is based on the Data Catalog Vocabulary (DCAT) and its extension DCAT Application Profile for data portals in Europe (DCAT-AP), and the Data Privacy Vocabulary (DPV). It represents a comprehensive semantic model developed from GDPR’s Article and an analysis of the 17 ROPA templates from EU Data Protection Authorities (DPA). To demonstrate the practicality and feasibility of DPCat, we present the European Data Protection Supervisor’s (EDPS) ROPA documents using DPCat, verify them with SHACL to ensure the correctness of information based on legal and contextual requirements, and produce reports and ROPA documents based on DPA templates using SPARQL. DPCat supports a data governance process for data processing compliance to harmonise inputs from heterogeneous sources to produce dynamic documentation that can accommodate differences in regulatory approaches across DPAs and ease investigative burdens toward efficient enforcement.en
dc.language.isoenen
dc.relation.ispartofseriesInformationen
dc.relation.ispartofseries13en
dc.relation.ispartofseries5en
dc.rightsYen
dc.subjectGDPRen
dc.subjectData governanceen
dc.subjectSemantic-weben
dc.titleDPCat: Specification for an Interoperable and Machine-Readable Data Processing Catalogue Based on GDPRen
dc.typeJournal Articleen
dc.type.supercollectionscholarly_publicationsen
dc.type.supercollectionrefereed_publicationsen
dc.identifier.peoplefinderurlhttp://people.tcd.ie/pandithjen
dc.identifier.peoplefinderurlhttp://people.tcd.ie/rbrennaen
dc.identifier.rssinternalid242893en
dc.identifier.doihttp://dx.doi.org/10.3390/info13050244en
dc.identifier.doihttp://dx.doi.org/10.5281/zenodo.6448787en
dc.rights.ecaccessrightsopenAccess
dc.subject.TCDTagDCATen
dc.subject.TCDTagGDPRen
dc.subject.TCDTagRDFen
dc.subject.TCDTagROPAen
dc.subject.TCDTagSEMANTIC WEBen
dc.identifier.rssurihttps://harshp.com/research/publications/052-DPCat-ROPA-specen
dc.identifier.rssurihttps://w3id.org/dpcaten
dc.contributor.sponsorIrish Research Council (IRC)en
dc.contributor.sponsorGrantNumberGOIPD/2020/790en
dc.contributor.sponsorScience Foundation Ireland (SFI)en
dc.contributor.sponsorGrantNumber13/RC/2106_P2en
dc.identifier.urihttp://hdl.handle.net/2262/98569


Files in this item

Thumbnail
Thumbnail

This item appears in the following Collection(s)

Show simple item record