arrow
Return

A practical solution for modelling GDPR-compliance based on defeasible logic reasoning

delete2025-06-01
delete0
PRE
AI
N
Naila Azam
A
Alex Chak
A
Anna Lito Michala
S
Shuja Ansari
N
Nguyen B. Truong *
DOI:10.1016/j.eswa.2025.127140delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
The General Data Protection Regulation (GDPR), the EU/UK data protection legislation, has necessitated a critical need for compliance modelling to meet its strict and sophisticated requirements. Traditional techniques for modelling security and privacy-related threats fall short of addressing and mitigating the threats of noncompliance. This paper introduces a practical solution to modelling GDPR-compliance based on Defeasible Logic Programming (DeLP), which enhances the robustness and reasoning capabilities of compliance models in real-world scenarios. Furthermore, to overcome the challenges of UNDECIDED query outputs in logical reasoning, we incorporate explicit priorities for conflicting rules and suggest related knowledge for a query in an incomplete knowledge base. To finalize the compliance modelling system, we develop the threat mitigation mechanism that specifies the reasons in case there is a non-compliance threat, along with the suggested actions to mitigate the threats. The application of our approach is demonstrated through a case study on Fitbit, health tracking devices, focusing on non-compliance threats and resolving UNDECIDED query results. Our findings show that the inference engine efficiently identifies non-compliance threats, handles UNDECIDED query results, and suggests appropriate threat mitigation measures.
Keywords:
Data privacy
Data protection
Defeasible logic programming (DeLP)
General data protection regulation (GDPR)
GDPR compliance
Threat modelling

Journal

Expert Systems with Applications cover
Expert Systems with Applications
IF:
7.5
Papers:
2.9W
Citations:
10.2W

Organization

U
univ glasgow
Scholars:
1.4K
Papers: 862
Citations: 432