Requirements Engineering· 2026Q2
PAM: a domain-specific language for specifying privacy requirements from regulation to runtime
- 0citations
- Q2SCImago
- 2026year
Short summary
PAM, a new domain-specific language, translates GDPR privacy regulations into executable specifications for runtime enforcement, covering data, purpose, retention, and consent.
AI-generated from the title and abstract; the full text is not read.
Key points
- PAM is a domain-specific language (DSL) for specifying privacy requirements derived from GDPR.
- It includes constructs for PII sensitivity, processing purposes, retention policies, and consent.
- PAM specifications are executable, allowing runtime validation and enforcement of data handling policies.
- PAM expressed 90% of ICO GDPR technical checklist requirements for a case study in ~70 lines of specification.
AI-generated from the title and abstract; the full text is not read.
Abstract
Abstract Privacy regulations such as the General Data Protection Regulation (GDPR) require organizations to specify what personal data they collect, for which purpose, how long they retain it, and under what consent conditions—yet practitioners struggle to translate these legal requirements into specifications that can be validated and enforced. We present Privacy Attribute Matrix (PAM), a domain-specific language that bridges this gap. PAM provides four constructs, derived directly from GDPR articles, for specifying personally identifiable information (PII) fields with sensitivity classifications, processing purposes with legal bases, retention policies with deletion strategies, and consent requirements with expiration semantics. Its scope is deliberately bounded to the technical data-handling obligations GDPR imposes—which data, for which purpose, for how long, under what consent—rather than organizational duties such as staff training or breach notification. Unlike annotation-based approaches that document but cannot enforce, PAM specifications are executable: the runtime validates data access against declared policies, detects violations, and applies configurable erasure strategies (hard deletion, anonymization). We evaluate PAM through a case study on a university payment system, replicated on the open-source Solidus e-commerce platform. The , , and constructs are exercised directly by the production system, whose legal basis is contract and legal obligation rather than consent; the construct is validated end-to-end through an extension that adds an optional consent-gated purpose. PAM expressed 90% of the Information Commissioner’s Office (ICO) GDPR technical checklist requirements for the evaluated system in about 70 lines of specification. The work advances requirements engineering by showing how regulatory requirements can be specified in a DSL that is both human-readable for compliance auditors and machine-enforceable at runtime.
The authors' abstract, as published at the source. Requirements Engineering, 2026 · DOI ↗
Continue with a free account
Ask the paper: 3 free questions a day about this paper; save it, get its citation, new summaries every day for your field. Takeaways are Premium.
Continue free on the webSign in with Google or Apple; no card needed. You come back to this paper.
On your phone:
Field: Software
SoftwareComputer Science