Extending Business Process Management for Regulatory Transparency
Jannis Kiesel, Elias Gr\"unewald

TL;DR
This paper introduces a process-oriented approach to enhance business process management with regulatory transparency features, enabling modeling, discovery, and checking of personal data flows in cloud-native systems to meet GDPR requirements.
Contribution
It proposes a novel extension to BPMN for regulatory transparency, utilizing event logs and process mining to ensure compliance with data protection laws.
Findings
Extended BPMN with transparency information
Effective discovery of personal data flows
Conformance checking for regulatory compliance
Abstract
Ever-increasingly complex business processes are enabled by loosely coupled cloud-native systems. In such fast-paced development environments, data controllers face the challenge of capturing and updating all personal data processing activities due to considerable communication overhead between development teams and data protection staff. To date, established business process management methods generate valuable insights about systems, however, they do not account for all regulatory transparency obligations. For instance, data controllers need to record all information about data categories, legal purpose specifications, third-country transfers, etc. Therefore, we propose to bridge the gap between business processes and application systems by providing three contributions that assist in modeling, discovering, and checking personal data transparency through a process-oriented…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsBusiness Process Modeling and Analysis
