The increasing complexity of software systems and the multidisciplinary nature of data protection obligations pose significant challenges to the effective conduction of Data Protection Impact Assessments (DPIAs). Despite regulatory mandates such as the GDPR, current DPIA practices often lack structured methods for integrating legal, technical, organizational, and privacy-related perspectives. This research addresses the gap by introducing a viewpoint-based model for DPIAs that systematically captures and interrelates stakeholder concerns. The objective is to enhance the transparency, traceability, and completeness of DPIAs across the lifecycle of data processing activities. Grounded in the ISO 42010:2022 standard and principles of Model-Driven Engineering, we developed a conceptual model comprising found interlinked viewpoints: legal, engineering, application, and privacy. Each viewpoint is formalized using UML-based model kinds and is mapped to corresponding stakeholder roles and concerns identified through literature and regulatory analysis. Our findings demonstrate that a viewpoint-based approach can improve interdisciplinary communication, clarify responsibilities, and support more structured and accountable DPIA processes. This model offers a foundation for future tool integration, empirical validation, and automated risk analysis. Ultimately, it contributes to a more robust, stakeholder-inclusive approach to privacy-by-design and regulatory compliance in software engineering.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Viewpoint-Based Model of Data Protection Impact Assessments

  • Andreas Diepenbrock,
  • Sabine Sachweh

摘要

The increasing complexity of software systems and the multidisciplinary nature of data protection obligations pose significant challenges to the effective conduction of Data Protection Impact Assessments (DPIAs). Despite regulatory mandates such as the GDPR, current DPIA practices often lack structured methods for integrating legal, technical, organizational, and privacy-related perspectives. This research addresses the gap by introducing a viewpoint-based model for DPIAs that systematically captures and interrelates stakeholder concerns. The objective is to enhance the transparency, traceability, and completeness of DPIAs across the lifecycle of data processing activities. Grounded in the ISO 42010:2022 standard and principles of Model-Driven Engineering, we developed a conceptual model comprising found interlinked viewpoints: legal, engineering, application, and privacy. Each viewpoint is formalized using UML-based model kinds and is mapped to corresponding stakeholder roles and concerns identified through literature and regulatory analysis. Our findings demonstrate that a viewpoint-based approach can improve interdisciplinary communication, clarify responsibilities, and support more structured and accountable DPIA processes. This model offers a foundation for future tool integration, empirical validation, and automated risk analysis. Ultimately, it contributes to a more robust, stakeholder-inclusive approach to privacy-by-design and regulatory compliance in software engineering.