Consent verification monitoring
Marco Robol, Travis D. Breaux, Elda Paja, Paolo Giorgini

TL;DR
This paper introduces a formal consent framework and scripting language to monitor and verify compliance with evolving privacy policies, ensuring GDPR adherence in real-time data practices.
Contribution
It presents a novel formal framework and scripting language for modeling and verifying consent evolution and policy compliance in data management.
Findings
Framework effectively models consent scenarios
Verifies unauthorized data access prevention
Scalable for real-time monitoring
Abstract
Advances in service personalization are driven by low-cost data collection and processing, in addition to the wide variety of third-party frameworks for authentication, storage, and marketing. New privacy regulations, such as the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), increasingly require organizations to explicitly state their data practices in privacy policies. When data practices change, a new version of the policy is released. This can occur a few times a year, when data collection or processing requirements are rapidly changing. Consent evolution raises specific challenges to ensuring GDPR compliance. We propose a formal consent framework to support organizations, data users and data subjects in their understanding of policy evolution under a consent regime that supports both the retroactive and non-retroactive granting and…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsPrivacy, Security, and Data Protection · Privacy-Preserving Technologies in Data · Access Control and Trust
