Automated Expansion of Privacy Data Taxonomy for Compliant Data Breach Notification
Yue Qin, Yue Xiao, Xiaojing Liao
Abstract
—In privacy compliance research, a significant challenge lies in comparing specific data items in actual data usage practices with the privacy data defined in laws, regulations, or policies. This task is complex due to the diversity of data items used by various applications, as well as the different interpretations of privacy data across jurisdictions. To address this challenge, privacy data taxonomies have been constructed to capture relationships between privacy data types and granularity levels, facilitating privacy compliance analysis. However, existing taxonomy construction approaches are limited by manual efforts or heuristic rules, hindering their ability to incorporate new terms from diverse domains. In this paper, we present the design of G RASP , a scalable and efficient methodology for automatically constructing and expanding privacy data taxonomies. G RASP incorporates a novel hypernym prediction model based on granularity-aware semantic projection, which outperforms existing state-of-the-art hypernym prediction methods. Additionally, we design and implement Tracy , a privacy professional assistant to recognize and interpret private data in incident reports for GDPR-compliant data breach notification. We evaluate Tracy in a usability study with 15 privacy professionals, yielding high-level usability and satisfaction.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on11
- PolicyLint: Investigating Internal Privacy Policy Contradictions on Google PlayBenjamin Andow, Samin Yaseer Mahmud, Wenyu Wang, Justin Whitaker et al.USENIX Security 2019 · 185 citations
- "It's stressful having all these phones": Investigating Sex Workers' Safety Goals, Risks, and Practices OnlineAllison McDonald, Catherine Barwulor, Michelle L. Mazurek, Florian Schaub et al.USENIX Security 2021 · 75 citations
- The Battle for New York: A Case Study of Applied Digital Threat Modeling at the Enterprise LevelRock Stevens, Daniel Votipka, Elissa M. Redmiles, Colin Ahern et al.USENIX Security 2018 · 51 citations
- Understanding Malicious Cross-library Data Harvesting on AndroidJice Wang, Yue Xiao, Xueqiang Wang, Yuhong Nan et al.USENIX Security 2021 · 41 citations
- HackEd: A Pedagogical Analysis of Online Vulnerability Discovery ExercisesDaniel Votipka, Eric Zhang, Michelle L. MazurekS&P 2021 · 22 citations
Related papers
- Understanding Legal Professionals' Practices and Expectations in Data Breach Incident ReportingEce Gumusel, Yue Xiao, Yue Qin, Jiaxin Qin et al.CCS 2024
- Retrofitting GDPR Compliance onto Legacy DatabasesArchita Agarwal, Marilyn George, Aaron R. Jeyaraj, Malte SchwarzkopfVLDB 2022 · 16 citations
- Have You been Properly Notified? Automatic Compliance Analysis of Privacy Policy Text with GDPR Article 13Shuang Liu, Baiyang Zhao, Renjie Guo, Guozhu Meng et al.WWW 2021 · 68 citations
- Understanding and Benchmarking the Impact of GDPR on Database SystemsSupreeth Shastri, Vinay Banakar, Melissa Wasserman, Arun Kumar et al.VLDB 2020 · 82 citations
- A Design Space for Privacy Choices: Towards Meaningful Privacy Control in the Internet of ThingsYuanyuan Feng, Yaxing Yao, Norman M. SadehCHI 2021 · 114 citations
