Explaining the Compliance of Security Policies for GDPR in Business Processes
摘要
Achieving compliance with the General Data Protection Regulation (GDPR) presents significant challenges to organisations, requiring substantial adaptations to business processes and the implementation of robust technical measures. This paper addresses the critical need to integrate security policies into business process management systems to enhance data protection. We propose an innovative architecture for access and usage control, aligned with GDPR’s technical measures. This architecture integrates a business process management system, security policy modelling, a Complex Event Processing (CEP) engine, and Large Language Models (LLMs). This integration enables real-time detection of security policy violations, a capability that is crucial to maintaining compliance and mitigating risks. LLMs help bridge the gap between security policy definitions and the explainability of policy violations. They identify the reasons behind compliance breaches and suggest potential solutions. By leveraging their capabilities, we aim to simplify complex violation diagnoses into accessible insights. Thereby, this approach improves transparency and accountability, facilitating GDPR compliance.