Retrofitting GDPR Compliance onto Legacy Databases
Archita Agarwal, Marilyn George, Aaron R. Jeyaraj, Malte Schwarzkopf
Abstract
New privacy laws like the European Union's General Data Protection Regulation (GDPR) require database administrators (DBAs) to identify all information related to an individual on request, e.g. , to return or delete it. This requires time-consuming manual labor today, particularly for legacy schemas and applications.
In this paper, we investigate what it takes to provide mostly-automated tools that assist DBAs in GDPR-compliant data extraction for legacy databases. We find that a combination of techniques is needed to realize a tool that works for the databases of real-world applications, such as web applications, which may violate strict normal forms or encode data relationships in bespoke ways. Our tool, GDPRizer, relies on foreign keys, query logs that identify implied relationships, data-driven methods, and coarse-grained annotations provided by the DBA to extract an individual's data. In a case study with three popular web applications, GDPRizer achieves 100% precision and 96--100% recall. GDPRizer saves work compared to hand-written queries, and while manual verification of its outputs is required, GDPRizer simplifies privacy compliance.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5f818120-026d-44df-b0bb-deaf738b68dcCited by top-tier papers6
- SoK: Technical Implementation and Human Impact of Internet Privacy RegulationsEleanor Birrell, Jay Rodolitz, Angel Ding, Jenna Lee et al.S&P 2024 · 11 citations
- K9db: Privacy-Compliant Storage For Web Applications By ConstructionKinan Dak Albab, Ishan Sharma, Justus Adam, Benjamin Kilimnik et al.OSDI 2023 · 7 citations
- General Data Protection Runtime: Enforcing Transparent GDPR Compliance for Existing ApplicationsDavid Klein, Benny Rolle, Thomas Barber, Manuel Karl et al.CCS 2023 · 5 citations
- Meaningful Data Erasure in the Presence of DependenciesVishal Chakraborty, Youri Kaminsky, Sharad Mehrotra, Felix Naumann et al.VLDB 2025
- Growlithe: A Developer-Centric Compliance Tool for Serverless ApplicationsPraveen Gupta, Arshia Moghimi, Devam Sisodraker, Mohammad Shahrad et al.S&P 2025
Builds on2
- Understanding and Benchmarking the Impact of GDPR on Database SystemsSupreeth Shastri, Vinay Banakar, Melissa Wasserman, Arun Kumar et al.VLDB 2020 · 82 citations
- Software-Defined Data Protection: Low Overhead Policy Compliance at the Storage Layer is Within Reach!Zsolt István, Soujanya Ponnapalli, Vijay ChidambaramVLDB 2021 · 19 citations
Related papers
- GDPRuler: A Trusted GDPR Monitor for Cloud Data SystemsDimitrios Stavrakakis, Masanori Misono, Julian Pritzi, Harshavardhan Unnibhavi et al.CCS 2026
- Automated Expansion of Privacy Data Taxonomy for Compliant Data Breach NotificationYue Qin, Yue Xiao, Xiaojing LiaoNDSS 2025
- RuleKeeper: GDPR-Aware Personal Data Compliance for Web FrameworksMafalda Ferreira, Tiago Brito, José Fragoso Santos, Nuno SantosS&P 2023
- Automating Cookie Consent and GDPR Violation DetectionDino Bollinger, Karel Kubicek, Carlos Cotrini, David A. BasinUSENIX Security 2022
- PolicyChecker: Analyzing the GDPR Completeness of Mobile Apps' Privacy PoliciesAnhao Xiang, Weiping Pei, Chuan YueCCS 2023 · 24 citations
