{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,11]],"date-time":"2026-02-11T17:59:21Z","timestamp":1770832761269,"version":"3.50.1"},"publisher-location":"Cham","reference-count":37,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030959463","type":"print"},{"value":"9783030959470","type":"electronic"}],"license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022]]},"DOI":"10.1007\/978-3-030-95947-0_36","type":"book-chapter","created":{"date-parts":[[2022,2,15]],"date-time":"2022-02-15T13:11:21Z","timestamp":1644930681000},"page":"505-514","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["GDPR-Compliant Data Processing: Practical Considerations"],"prefix":"10.1007","author":[{"given":"Jo\u00e3o","family":"Almeida","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2701-5248","authenticated-orcid":false,"given":"Paulo Rupino","family":"da Cunha","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4356-9195","authenticated-orcid":false,"given":"Alexandre Dias","family":"Pereira","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2022,2,16]]},"reference":[{"key":"36_CR1","unstructured":"AIDE - Advanced Intrusion Detection Environment, available on-line at https:\/\/github.com\/aide\/aide. Accessed 7 July 2020"},{"key":"36_CR2","doi-asserted-by":"publisher","DOI":"10.1002\/9781119644682","volume-title":"Security engineering: A Guide to Building Dependable Distributed Systems","author":"R Anderson","year":"2020","unstructured":"Anderson, R.: Security engineering: A Guide to Building Dependable Distributed Systems, 3rd edn. Wiley, Indianapolis, Indiana (2020)","edition":"3"},{"issue":"2","key":"36_CR3","doi-asserted-by":"publisher","first-page":"66","DOI":"10.1109\/MC.2011.259","volume":"45","author":"N Antunes","year":"2012","unstructured":"Antunes, N., Vieira, M.: Defending against web application vulnerabilities. Computer 45(2), 66\u201372 (2012)","journal-title":"Computer"},{"key":"36_CR4","unstructured":"Article 29 Data Protection Working Party. Guidelines on the application and setting of administrative fines for the purposes of the Regulation 2016\/679. http:\/\/ec.europa.eu\/newsroom\/just\/document.cfm?doc_id=47889. Accessed 7 July 2020"},{"key":"36_CR5","unstructured":"Article 29 working party. guidelines on consent under regulation 2016\/679 (wp259rev.01). https:\/\/ec.europa.eu\/newsroom\/article29\/document.cfm?action=display&doc_id=51030. Accessed 7 July 2020"},{"issue":"4","key":"36_CR6","doi-asserted-by":"publisher","first-page":"96","DOI":"10.1109\/MSP.2006.101","volume":"4","author":"SM Bellovin","year":"2006","unstructured":"Bellovin, S.M.: On the brittleness of software and the infeasibility of security metrics. IEEE Secur. Priv. 4(4), 96 (2006)","journal-title":"IEEE Secur. Priv."},{"key":"36_CR7","first-page":"87","volume-title":"Privacy in Online Social Networks","author":"M Beye","year":"2012","unstructured":"Beye, M., Jeckmans, A., Erkin, Z., Hartel, P.H., Lagendijk, R., Tang, Q.: Privacy in Online Social Networks, pp. 87\u2013113. Computational Social Networks. Springer, London (2012)"},{"key":"36_CR8","unstructured":"Boavida, F., Bernardes, M.: Introdu\u00e7\u00e3o \u00e0 Criptografia, FCA\u2013Editora de Inform\u00e1tica (2019)"},{"key":"36_CR9","doi-asserted-by":"crossref","unstructured":"Degeling, M., Utz, C., Lentzsch, C., Hosseini, H., Schaub, F., Holz, T.: We value your privacy. Now take some cookies: measuring the GDPR\u2019s impact on web privacy (2018). arXiv preprint arXiv:1808.05096","DOI":"10.14722\/ndss.2019.23378"},{"key":"36_CR10","unstructured":"Directive 95\/46\/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data). https:\/\/eur-lex.europa.eu\/legal-content\/en\/TXT\/?uri=CELEX%3A31995L0046. Accessed 7 July 2020"},{"key":"36_CR11","doi-asserted-by":"crossref","unstructured":"Engels, B.: Data portability among online platforms. Internet Policy Rev. 5(2) (2016)","DOI":"10.14763\/2016.2.408"},{"issue":"1","key":"36_CR12","doi-asserted-by":"publisher","first-page":"7","DOI":"10.1007\/s00766-009-0092-x","volume":"15","author":"B Fabian","year":"2010","unstructured":"Fabian, B., G\u00fcrses, S., Heisel, M., Santen, T., Schmidt, H.: A comparison of security requirements engineering methods. Requirements Eng. 15(1), 7\u201340 (2010)","journal-title":"Requirements Eng."},{"key":"36_CR13","doi-asserted-by":"crossref","unstructured":"Fryer, H., Simperl, E.: Web science challenges in researching bug bounties. In: Proceedings of the 2017 ACM on Web Science Conference, pp. 273\u2013277 (2017)","DOI":"10.1145\/3091478.3091517"},{"key":"36_CR14","unstructured":"GDPR Enforcement Tracker. https:\/\/www.enforcementtracker.com. Accessed 7 July 2020"},{"key":"36_CR15","unstructured":"Intersoft Consulting. General Data Protection Regulation \u2013 Official Legal Text. https:\/\/gdpr-info.eu. Accessed 1 June 2020"},{"key":"36_CR16","unstructured":"Janal, R.: Data portability-a tale of two concepts. J. Intell. Property, Inf. Technol. E-Commer. Law, 8(1), 59\u201369 (2017)"},{"key":"36_CR17","unstructured":"Flora, J.: Trusted execution environments. CSAM 6 Jan 2020"},{"key":"36_CR18","doi-asserted-by":"crossref","unstructured":"Liu, C., White, R.W., Dumais, S.: Understanding web browsing behaviors through Weibull analysis of dwell time. In: Proceedings of the 33rd International ACM SIGIR Conference on Research and Development in Information Retrieval, pp. 379\u2013386 (2010)","DOI":"10.1145\/1835449.1835513"},{"key":"36_CR19","doi-asserted-by":"crossref","unstructured":"Malandrino, D., Petta, A., Scarano, V., Serra, L., Spinelli, R., Krishnamurthy, B.: Privacy awareness about information leakage: who knows what about me? In: Proceedings of the 12th ACM workshop on Workshop on privacy in the electronic society, pp. 279\u2013284 (2013)","DOI":"10.1145\/2517840.2517868"},{"key":"36_CR20","doi-asserted-by":"publisher","first-page":"10562","DOI":"10.1109\/ACCESS.2017.2706947","volume":"5","author":"R Mendes","year":"2017","unstructured":"Mendes, R., Vilela, J.P.: Privacy-preserving data mining: methods, metrics, and applications. IEEE Access 5, 10562\u201310582 (2017)","journal-title":"IEEE Access"},{"key":"36_CR21","doi-asserted-by":"crossref","unstructured":"Naehrig, M., Lauter, K., Vaikuntanathan, V.: Can homomorphic encryption be practical? In: Proceedings of the 3rd ACM Workshop on Cloud Computing Security Workshop, pp. 113\u2013124 (2011)","DOI":"10.1145\/2046660.2046682"},{"key":"36_CR22","unstructured":"Narayanan, A., Shmatikov, V.: How to break anonymity of the Netflix Prize dataset, arXiv e-print. http:\/\/arxiv.org\/abs\/cs\/0610105. Accessed 8 July 2020"},{"key":"36_CR23","first-page":"123","volume":"2009","author":"AA Neto","year":"2009","unstructured":"Neto, A.A., Vieira, M.: Untrustworthiness: a trustbased security metric. Fourth Int. Conf. Risks Secur. Internet Syst. 2009, 123\u2013126 (2009)","journal-title":"Fourth Int. Conf. Risks Secur. Internet Syst."},{"key":"36_CR24","doi-asserted-by":"crossref","unstructured":"Omoronyia, I.: The case for privacy awareness requirements. In: Censorship, Surveillance, and Privacy: Concepts, Methodologies, Tools, and Applications, pp. 697\u2013716. IGI Global (2019)","DOI":"10.4018\/978-1-5225-7113-1.ch037"},{"key":"36_CR25","unstructured":"Open Web Application Security Project (OWASP) Secure Coding Practices - Quick Reference Guide. https:\/\/owasp.org\/www-pdf-archive\/OWASP_SCP_Quick_Reference_Guide_v2.pdf. Accessed 8 July 2020"},{"key":"36_CR26","doi-asserted-by":"crossref","unstructured":"Politou, E., Alepis, E., Patsakis, C.: Forgetting personal data and revoking consent under the GDPR: Challenges and proposed solutions. J. Cybersecurity, 4(1), tyy001 (2018)","DOI":"10.1093\/cybsec\/tyy001"},{"key":"36_CR27","unstructured":"Prasser, F., Kohlmayer, F., Lautenschlaeger, R., Kuhn, K.A.: Arx-a comprehensive tool for anonymizing biomedical data. In: Proceedings of the AMIA Annual Symposium, pp. 984\u2013993 (2014)"},{"key":"36_CR28","unstructured":"Publications Office of the European Union, 2.2. Preamble (citations and recitals). https:\/\/publications.europa.eu\/code\/en\/en-120200.htm. Accessed 8 July 2020"},{"key":"36_CR29","unstructured":"Regulation (EU) (2016\/679) (2016). https:\/\/eur-lex.europa.eu\/eli\/reg\/2016\/679\/oj. Accessed 8 July 2020"},{"key":"36_CR30","unstructured":"Saltis, S.: GDPR explained in 5 minutes: everything you need to know. https:\/\/www.coredna.com\/blogs\/general-data-protection-regulation. Accessed 1 June 2020"},{"issue":"05","key":"36_CR31","doi-asserted-by":"publisher","first-page":"557","DOI":"10.1142\/S0218488502001648","volume":"10","author":"L Sweeney","year":"2002","unstructured":"Sweeney, L.: K-anonymity: a model for protecting privacy. Internat. J. Uncertain. Fuzziness Knowl.-Based Syst. 10(05), 557\u2013570 (2002)","journal-title":"Internat. J. Uncertain. Fuzziness Knowl.-Based Syst."},{"issue":"4","key":"36_CR32","doi-asserted-by":"publisher","first-page":"402","DOI":"10.1108\/DPRG-01-2019-0007","volume":"21","author":"GA Teixeira","year":"2019","unstructured":"Teixeira, G.A., Silva, M.M., Pereira, R.: The critical success factors of GDPR implementation: a systematic literature review. Digit. Policy, Regul. Governance. 21(4), 402\u2013418 (2019)","journal-title":"Digit. Policy, Regul. Governance."},{"key":"36_CR33","doi-asserted-by":"crossref","unstructured":"Utz, C., Degeling, M., Fahl, S., Schaub, F., Holz, T.: (Un) informed consent: studying GDPR consent notices in the field. In: Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, pp. 973\u2013990 (2019)","DOI":"10.1145\/3319535.3354212"},{"key":"36_CR34","doi-asserted-by":"crossref","unstructured":"Vieira, M., Antunes, N.: Introduction to software security concepts. In: Cotroneo, D. (eds.) Innovative Technologies for Dependable OTS-Based Critical Systems. Springer, Milano (2013)","DOI":"10.1007\/978-88-470-2772-5_3"},{"issue":"2","key":"36_CR35","doi-asserted-by":"publisher","first-page":"304","DOI":"10.1016\/j.clsr.2017.08.007","volume":"34","author":"EF Villaronga","year":"2018","unstructured":"Villaronga, E.F., Kieseberg, P., Li, T.: Humans forget, machines remember: artificial intelligence and the right to be forgotten. Comput. Law Secur. Rev. 34(2), 304\u2013313 (2018)","journal-title":"Comput. Law Secur. Rev."},{"key":"36_CR36","unstructured":"Warren, T.: Zoom announces 90-day feature freeze to fix privacy and security issues. https:\/\/www.theverge.com\/2020\/4\/2\/21204018\/zoom-security-privacy-feature-freeze-200-million-daily-users. Accessed 1 June 2020"},{"issue":"4","key":"36_CR37","doi-asserted-by":"publisher","first-page":"44","DOI":"10.1109\/MITP.2012.24","volume":"15","author":"KS Wilson","year":"2012","unstructured":"Wilson, K.S.: Conflicts among the pillars of information assurance. IT Professional 15(4), 44\u201349 (2012)","journal-title":"IT Professional"}],"container-title":["Lecture Notes in Business Information Processing","Information Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-95947-0_36","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,2,15]],"date-time":"2022-02-15T13:32:41Z","timestamp":1644931961000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-95947-0_36"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"ISBN":["9783030959463","9783030959470"],"references-count":37,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-95947-0_36","relation":{},"ISSN":["1865-1348","1865-1356"],"issn-type":[{"value":"1865-1348","type":"print"},{"value":"1865-1356","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022]]},"assertion":[{"value":"16 February 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"EMCIS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European, Mediterranean, and Middle Eastern Conference on Information Systems","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2021","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"8 December 2021","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"9 December 2021","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"emcis2021","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/emcis.eu\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"155","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"54","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"35% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"2","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"2.5","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}