Automated Expansion of Privacy Data Taxonomy for Compliant Data Breach Notification
Yue Qin, Yue Xiao, Xiaojing Liao
摘要
—In privacy compliance research, a significant challenge lies in comparing specific data items in actual data usage practices with the privacy data defined in laws, regulations, or policies. This task is complex due to the diversity of data items used by various applications, as well as the different interpretations of privacy data across jurisdictions. To address this challenge, privacy data taxonomies have been constructed to capture relationships between privacy data types and granularity levels, facilitating privacy compliance analysis. However, existing taxonomy construction approaches are limited by manual efforts or heuristic rules, hindering their ability to incorporate new terms from diverse domains. In this paper, we present the design of G RASP , a scalable and efficient methodology for automatically constructing and expanding privacy data taxonomies. G RASP incorporates a novel hypernym prediction model based on granularity-aware semantic projection, which outperforms existing state-of-the-art hypernym prediction methods. Additionally, we design and implement Tracy , a privacy professional assistant to recognize and interpret private data in incident reports for GDPR-compliant data breach notification. We evaluate Tracy in a usability study with 15 privacy professionals, yielding high-level usability and satisfaction.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper11
- PolicyLint: Investigating Internal Privacy Policy Contradictions on Google PlayBenjamin Andow, Samin Yaseer Mahmud, Wenyu Wang, Justin Whitaker 等USENIX Security 2019 · 被引用 185 次
- "It's stressful having all these phones": Investigating Sex Workers' Safety Goals, Risks, and Practices OnlineAllison McDonald, Catherine Barwulor, Michelle L. Mazurek, Florian Schaub 等USENIX Security 2021 · 被引用 75 次
- The Battle for New York: A Case Study of Applied Digital Threat Modeling at the Enterprise LevelRock Stevens, Daniel Votipka, Elissa M. Redmiles, Colin Ahern 等USENIX Security 2018 · 被引用 51 次
- Understanding Malicious Cross-library Data Harvesting on AndroidJice Wang, Yue Xiao, Xueqiang Wang, Yuhong Nan 等USENIX Security 2021 · 被引用 41 次
- HackEd: A Pedagogical Analysis of Online Vulnerability Discovery ExercisesDaniel Votipka, Eric Zhang, Michelle L. MazurekS&P 2021 · 被引用 22 次
相关 Paper
- Understanding Legal Professionals' Practices and Expectations in Data Breach Incident ReportingEce Gumusel, Yue Xiao, Yue Qin, Jiaxin Qin 等CCS 2024
- Retrofitting GDPR Compliance onto Legacy DatabasesArchita Agarwal, Marilyn George, Aaron R. Jeyaraj, Malte SchwarzkopfVLDB 2022 · 被引用 16 次
- Have You been Properly Notified? Automatic Compliance Analysis of Privacy Policy Text with GDPR Article 13Shuang Liu, Baiyang Zhao, Renjie Guo, Guozhu Meng 等WWW 2021 · 被引用 68 次
- Understanding and Benchmarking the Impact of GDPR on Database SystemsSupreeth Shastri, Vinay Banakar, Melissa Wasserman, Arun Kumar 等VLDB 2020 · 被引用 82 次
- A Design Space for Privacy Choices: Towards Meaningful Privacy Control in the Internet of ThingsYuanyuan Feng, Yaxing Yao, Norman M. SadehCHI 2021 · 被引用 114 次
