RuleKeeper: GDPR-Aware Personal Data Compliance for Web Frameworks
Mafalda Ferreira, Tiago Brito, José Fragoso Santos, Nuno Santos
Abstract
Pressured by existing regulations such as the EU GDPR, online services must advertise a personal data protection policy declaring the types and purposes of collected personal data, which must then be strictly enforced as per the consent decisions made by the users. However, due to the lack of system-level support, obtaining strong guarantees of policy enforcement is hard, leaving the door open for software bugs and vulnerabilities to cause GDPR-compliance violations.We present RuleKeeper, a GDPR-aware personal data policy compliance system for web development frameworks. Currently ported for the MERN framework, RuleKeeper allows web developers to specify a GDPR manifest from which the data protection policy of the web application is automatically generated and is transparently enforced through static code analysis and runtime access control mechanisms. GDPR compliance is checked in a cross-cutting manner requiring few changes to the application code. We used our prototype implementation to evaluate RuleKeeper with four real-world applications. Our system can model realistic GDPR data protection requirements, adds modest performance overheads to the web application, and can detect GDPR violation bugs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bff3e7d3-49df-4f24-ba96-db57531ec543Cited by top-tier papers12
- Efficient Static Vulnerability Analysis for JavaScript with Multiversion Dependency GraphsMafalda Ferreira, Miguel Monteiro, Tiago Brito, Miguel E. Coimbra et al.PLDI 2024 · 13 citations
- SoK: Technical Implementation and Human Impact of Internet Privacy RegulationsEleanor Birrell, Jay Rodolitz, Angel Ding, Jenna Lee et al.S&P 2024 · 11 citations
- Data Subjects' Reactions to Exercising Their Right of AccessArthur Borem, Elleen Pan, Olufunmilola Obielodan, Aurelie Roubinowitz et al.USENIX Security 2024 · 7 citations
- Automated Exploit Generation for Node.js PackagesFilipe Marques, Mafalda Ferreira, André Nascimento, Miguel E. Coimbra et al.PLDI 2025 · 5 citations
- Paralegal: Practical Static Analysis for Privacy BugsJustus Adam, Carolyn Zech, Livia Zhu, Sreshtaa Rajesh et al.OSDI 2025 · 2 citations
Builds on22
- Dark Patterns after the GDPR: Scraping Consent Pop-ups and Demonstrating their InfluenceMidas Nouwens, Ilaria Liccardi, Michael Veale, David R. Karger et al.CHI 2020 · 491 citations
- (Un)informed Consent: Studying GDPR Consent Notices in the FieldChristine Utz, Martin Degeling, Sascha Fahl, Florian Schaub et al.CCS 2019 · 429 citations
- Do Cookie Banners Respect my Choice? : Measuring Legal Compliance of Banners from IAB Europe's Transparency and Consent FrameworkCélestin Matte, Nataliia Bielova, Cristiana Teixeira SantosS&P 2020 · 212 citations
- User Tracking in the Post-cookie Era: How Websites Bypass GDPR Consent to Track UsersEmmanouil Papadogiannakis, Panagiotis Papadopoulos, Nicolas Kourtellis, Evangelos P. MarkatosWWW 2021 · 99 citations
- Understanding Privacy-Related Questions on Stack OverflowMohammad Tahaei, Kami Vaniea, Naomi SaphraCHI 2020 · 93 citations
Related papers
- PolicyChecker: Analyzing the GDPR Completeness of Mobile Apps' Privacy PoliciesAnhao Xiang, Weiping Pei, Chuan YueCCS 2023 · 24 citations
- GDPRuler: A Trusted GDPR Monitor for Cloud Data SystemsDimitrios Stavrakakis, Masanori Misono, Julian Pritzi, Harshavardhan Unnibhavi et al.CCS 2026
- Automating Cookie Consent and GDPR Violation DetectionDino Bollinger, Karel Kubicek, Carlos Cotrini, David A. BasinUSENIX Security 2022
- Sesame: Practical End-to-End Privacy Compliance with Policy Containers and Privacy RegionsKinan Dak Albab, Artem Agvanian, Allen Aby, Corinn Tiffany et al.SOSP 2024 · 2 citations
- Beast in the Cage: A Fine-grained and Object-oriented Permission System to Confine JavaScript Operations on the WebRui ZhaoWWW 2025 · 2 citations
