PofoliaPofolia ile paylaşıldı

Requirements Engineering· 2026Q2

PAM: Gizlilik Gereksinimlerini Belirlemek İçin Alan Özelinde Bir Dil

PAM: a domain-specific language for specifying privacy requirements from regulation to runtime

Michail Pantelelis, Christos Kalloniatis

Kısa özet

Yeni bir alan özelinde dil olan PAM, GDPR gizlilik düzenlemelerini çalışma zamanı uygulaması için yürütülebilir spesifikasyonlara dönüştürür; veri, amaç, saklama ve rıza konularını kapsar.

Yapay zekâ ile başlık ve abstract'tan üretildi; tam metin okunmaz.

Ana noktalar

  • PAM, GDPR'dan türetilen gizlilik gereksinimlerini belirtmek için alan özelinde bir dildir (DSL).
  • PII hassasiyeti, işlem amaçları, saklama politikaları ve rıza için yapılar içerir.
  • PAM spesifikasyonları yürütülebilirdir, bu da veri işleme politikalarının çalışma zamanında doğrulanmasına ve uygulanmasına olanak tanır.
  • PAM, incelenen bir vaka çalışması için ICO GDPR teknik kontrol listesi gereksinimlerinin %90'ını yaklaşık 70 satır kod ile ifade etmiştir.

Yapay zekâ ile başlık ve abstract'tan üretildi; tam metin okunmaz.

Özet (abstract)

Abstract Privacy regulations such as the General Data Protection Regulation (GDPR) require organizations to specify what personal data they collect, for which purpose, how long they retain it, and under what consent conditions—yet practitioners struggle to translate these legal requirements into specifications that can be validated and enforced. We present Privacy Attribute Matrix (PAM), a domain-specific language that bridges this gap. PAM provides four constructs, derived directly from GDPR articles, for specifying personally identifiable information (PII) fields with sensitivity classifications, processing purposes with legal bases, retention policies with deletion strategies, and consent requirements with expiration semantics. Its scope is deliberately bounded to the technical data-handling obligations GDPR imposes—which data, for which purpose, for how long, under what consent—rather than organizational duties such as staff training or breach notification. Unlike annotation-based approaches that document but cannot enforce, PAM specifications are executable: the runtime validates data access against declared policies, detects violations, and applies configurable erasure strategies (hard deletion, anonymization). We evaluate PAM through a case study on a university payment system, replicated on the open-source Solidus e-commerce platform. The , , and constructs are exercised directly by the production system, whose legal basis is contract and legal obligation rather than consent; the construct is validated end-to-end through an extension that adds an optional consent-gated purpose. PAM expressed 90% of the Information Commissioner’s Office (ICO) GDPR technical checklist requirements for the evaluated system in about 70 lines of specification. The work advances requirements engineering by showing how regulatory requirements can be specified in a DSL that is both human-readable for compliance auditors and machine-enforceable at runtime.

Yazarların özeti; kaynağından alınmıştır. Requirements Engineering, 2026 · DOI ↗

ÇıkarımlarPremium
Makaleye SorÜcretsiz hesapla

Ücretsiz hesapla devam et

Makaleye Sor ile bu makaleye günde 3 soru ücretsiz; makaleyi kaydet, kaynakçasını al, ilgi alanına göre her gün yeni özetler. Çıkarımlar Premium.

Web'de ücretsiz devam et

Google ya da Apple hesabınla giriş; kart istemez. Bu makaleye geri dönersin.

Telefonda:

Alan: Yazılım

SoftwareComputer Science