General Data Protection Runtime: Enforcing Transparent GDPR Compliance for Existing Applications
David Klein, Benny Rolle, Thomas Barber, Manuel Karl, Martin Johns
摘要
Recent advances in data protection regulations brings privacy benefits for website users, but also comes at a cost for operators. Retrofitting the privacy requirements of laws such as the General Data Protection Regulation (GDPR) onto legacy software requires significant auditing and development effort. In this work we demonstrate that this effort can be minimized by viewing data protection requirements through the lens of information flow tracking. Instead of manual inspections of applications, we propose a lightweight enforcement engine which can reliably prevent unlawful data processing even in the presence of bugs or misconfigured software. Taking GDPR regulations as a starting point, we define twelve software requirements which, if implemented properly, ensure adequate handling of personal data. We go on to show how these requirements can be fulfilled by proposing a metadata structure and enforcement policies for dynamic information flow tracking frameworks. To put this idea into practice, we present Fontus, a Java Virtual Machine (JVM) information flow tracking framework, which can transparently label personal data in existing Java applications in order to aid compliance with data protection regulations. Finally, we demonstrate the applicability of our approach by enforcing data protection polices across 7 large, open source web applications, with no changes required to the applications themselves.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- "Sorry for Bugging you so much." Exploring Developers' Behavior Towards Privacy-Compliant ImplementationStefan Albert Horstmann, Sandy Hong, David Klein, Raphael Serafini 等S&P 2025
- I Can Tell Your Secrets: Inferring Privacy Attributes from Mini-app Interaction History in Super-appsYifeng Cai, Ziqi Zhang, Mengyu Yao, Junlin Liu 等USENIX Security 2025
- Privacy Law Enforcement Under Centralized Governance: A Qualitative Analysis of Four Years' Special Privacy Rectification CampaignsTao Jing, Yao Li, Jingzhou Ye, Jie Wang 等USENIX Security 2025
它引用的顶会 Paper7
- Do Cookie Banners Respect my Choice? : Measuring Legal Compliance of Banners from IAB Europe's Transparency and Consent FrameworkCélestin Matte, Nataliia Bielova, Cristiana Teixeira SantosS&P 2020 · 被引用 212 次
- Understanding and Benchmarking the Impact of GDPR on Database SystemsSupreeth Shastri, Vinay Banakar, Melissa Wasserman, Arun Kumar 等VLDB 2020 · 被引用 82 次
- Qapla: Policy compliance for database-backed systemsAastha Mehta, Eslam Elnikety, Katura Harvey, Deepak Garg 等USENIX Security 2017 · 被引用 46 次
- Retrofitting GDPR Compliance onto Legacy DatabasesArchita Agarwal, Marilyn George, Aaron R. Jeyaraj, Malte SchwarzkopfVLDB 2022 · 被引用 16 次
- Co-Inflow: Coarse-grained Information Flow Control for Java-like LanguagesJian Xiang, Stephen ChongS&P 2021 · 被引用 12 次
相关 Paper
- RuleKeeper: GDPR-Aware Personal Data Compliance for Web FrameworksMafalda Ferreira, Tiago Brito, José Fragoso Santos, Nuno SantosS&P 2023
- GDPRuler: A Trusted GDPR Monitor for Cloud Data SystemsDimitrios Stavrakakis, Masanori Misono, Julian Pritzi, Harshavardhan Unnibhavi 等CCS 2026
- Proactive Real-Time First-Order EnforcementFrançois Hublet, Leonardo Lima, David A. Basin, Srdan Krstic 等CAV 2024 · 被引用 4 次
- Growlithe: A Developer-Centric Compliance Tool for Serverless ApplicationsPraveen Gupta, Arshia Moghimi, Devam Sisodraker, Mohammad Shahrad 等S&P 2025
- We Value Your Privacy ... Now Take Some Cookies: Measuring the GDPR's Impact on Web PrivacyMartin Degeling, Christine Utz, Christopher Lentzsch, Henry Hosseini 等NDSS 2019
