{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,24]],"date-time":"2026-06-24T10:55:17Z","timestamp":1782298517903,"version":"3.54.5"},"publisher-location":"Cham","reference-count":49,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031514753","type":"print"},{"value":"9783031514760","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"DOI":"10.1007\/978-3-031-51476-0_20","type":"book-chapter","created":{"date-parts":[[2024,1,10]],"date-time":"2024-01-10T07:02:29Z","timestamp":1704870149000},"page":"400-422","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":7,"title":["Enforcing the\u00a0GDPR"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5419-3125","authenticated-orcid":false,"given":"Fran\u00e7ois","family":"Hublet","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2952-939X","authenticated-orcid":false,"given":"David","family":"Basin","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8314-2589","authenticated-orcid":false,"given":"Sr\u0111an","family":"Krsti\u0107","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,1,11]]},"reference":[{"key":"20_CR1","doi-asserted-by":"crossref","unstructured":"Amantea, I.A., Robaldo, L., Sulis, E., Boella, G., Governatori, G.: Semi-automated checking for regulatory compliance in e-health. In: EDOCW 2021. IEEE (2021)","DOI":"10.1109\/EDOCW52865.2021.00063"},{"key":"20_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"681","DOI":"10.1007\/978-3-030-29959-0_33","volume-title":"Computer Security \u2013 ESORICS 2019","author":"E Arfelt","year":"2019","unstructured":"Arfelt, E., Basin, D., Debois, S.: Monitoring the GDPR. In: Sako, K., Schneider, S., Ryan, P.Y.A. (eds.) ESORICS 2019. LNCS, vol. 11735, pp. 681\u2013699. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-29959-0_33"},{"key":"20_CR3","doi-asserted-by":"publisher","unstructured":"Baramashetru, C.P., Tapia Tarifa, S.L., Owe, O., Gruschka, N.: A policy language to capture compliance of data protection requirements. In: IFM 2022. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-07727-2_16","DOI":"10.1007\/978-3-031-07727-2_16"},{"key":"20_CR4","doi-asserted-by":"crossref","unstructured":"Barati, M., Rana, O., Petri, I., Theodorakopoulos, G.: GDPR compliance verification in Internet of Things. IEEE Access 8 (2020)","DOI":"10.1109\/ACCESS.2020.3005509"},{"key":"20_CR5","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-75632-5_1","volume-title":"Introduction to runtime verification","author":"E Bartocci","year":"2018","unstructured":"Bartocci, E., Falcone, Y., Francalanza, A., Reger, G.: Introduction to runtime verification. Introductory and Advanced Topics, Lectures on Runtime Verification (2018)"},{"key":"20_CR6","doi-asserted-by":"crossref","unstructured":"Bartolini, C., Lenzini, G., Santos, C.: A legal validation of a formal representation of GDPR articles. In: JURIX 2018 (2018)","DOI":"10.1007\/978-3-030-31605-1_13"},{"key":"20_CR7","doi-asserted-by":"publisher","unstructured":"Basin, D., Debois, S., Hildebrandt, T.: On purpose and by necessity: compliance under the GDPR. In: Meiklejohn, S., Sako, K. (eds.) FC 2018. LNCS, vol. 10957, pp. 20\u201337. Springer, Heidelberg (2018). https:\/\/doi.org\/10.1007\/978-3-662-58387-6_2","DOI":"10.1007\/978-3-662-58387-6_2"},{"key":"20_CR8","doi-asserted-by":"crossref","unstructured":"Basin, D., Klaedtke, F., M\u00fcller, S., Z\u0103linescu, E.: Monitoring metric first-order temporal properties. JACM 62(2) (2015)","DOI":"10.1145\/2699444"},{"key":"20_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"135","DOI":"10.1007\/978-3-319-44760-5_9","volume-title":"Privacy Technologies and Policy","author":"C Bier","year":"2016","unstructured":"Bier, C., K\u00fchne, K., Beyerer, J.: PrivacyInsight: the next generation privacy dashboard. In: Schiffner, S., Serna, J., Ikonomou, D., Rannenberg, K. (eds.) APF 2016. LNCS, vol. 9857, pp. 135\u2013152. Springer, Cham (2016). https:\/\/doi.org\/10.1007\/978-3-319-44760-5_9"},{"key":"20_CR10","doi-asserted-by":"crossref","unstructured":"Bollinger, D., Kubicek, K., Cotrini, C., Basin, D.: Automating cookie consent and GDPR violation detection. In: USENIX Security 2022 (2022)","DOI":"10.2478\/popets-2022-0046"},{"key":"20_CR11","doi-asserted-by":"crossref","unstructured":"Bonatti, P.A., Ioffredo, L., Petrova, I.M., Sauro, L., Siahaan, I.R.: Real-time reasoning in OWL2 for GDPR compliance. Artificial Intelligence 289 (2020)","DOI":"10.1016\/j.artint.2020.103389"},{"key":"20_CR12","doi-asserted-by":"crossref","unstructured":"Chhetri, T.R., Kurteva, A., DeLong, R.J., Hilscher, R., Korte, K., Fensel, A.: Data protection by design tool for automated GDPR compliance verification based on semantically modeled informed consent. Sensors 22(7) (2022)","DOI":"10.3390\/s22072763"},{"key":"20_CR13","unstructured":"CMS: GDPR Enforcement Tracker (2023). www.enforcementtracker.com"},{"key":"20_CR14","doi-asserted-by":"crossref","unstructured":"Daud\u00e9n-Esmel, C., Castell\u00e0-Roca, J., Viejo, A., Domingo-Ferrer, J.: Lightweight blockchain-based platform for GDPR-compliant personal data management. In: CSP 2021 (2021)","DOI":"10.1109\/CSP51677.2021.9357602"},{"key":"20_CR15","doi-asserted-by":"crossref","unstructured":"Davari, M., Bertino, E.: Access control model extensions to support data privacy protection based on GDPR. In: BigData 2019. IEEE (2019)","DOI":"10.1109\/BigData47090.2019.9006455"},{"key":"20_CR16","series-title":"IFIP Advances in Information and Communication Technology","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-030-33716-2_1","volume-title":"Trust Management XIII","author":"C de Montety","year":"2019","unstructured":"de Montety, C., Antignac, T., Slim, C.: GDPR modelling for log-based compliance checking. In: Meng, W., Cofta, P., Jensen, C.D., Grandison, T. (eds.) IFIPTM 2019. IAICT, vol. 563, pp. 1\u201318. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-33716-2_1"},{"key":"20_CR17","doi-asserted-by":"crossref","unstructured":"Dwyer, M.B., Avrunin, G.S., Corbett, J.C.: Property specification patterns for finite-state verification. In: FMSP 1998 (1998)","DOI":"10.1145\/298595.298598"},{"key":"20_CR18","unstructured":"Ferrara, P., Spoto, F.: Static analysis for GDPR compliance. In: ITASEC (2018)"},{"key":"20_CR19","doi-asserted-by":"crossref","unstructured":"Ferreira, M., Brito, T., Santos, J.F., Santos, N.: RuleKeeper: GDPR-aware personal data compliance for web frameworks. In: S &P 2023. IEEE (2022)","DOI":"10.1109\/SP46215.2023.10179395"},{"key":"20_CR20","doi-asserted-by":"crossref","unstructured":"Gerl, A., Bennani, N., Kosch, H., Brunie, L.: LPL, towards a GDPR-compliant privacy language: formal definition and usage. Transactions on Large-Scale Data-and Knowledge-Centered Systems XXXVII (2018)","DOI":"10.1007\/978-3-662-57932-9_2"},{"key":"20_CR21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-319-46963-8_1","volume-title":"Current Trends in Web Engineering","author":"H Gjermundr\u00f8d","year":"2016","unstructured":"Gjermundr\u00f8d, H., Dionysiou, I., Costa, K.: privacyTracker: a privacy-by-design GDPR-compliant framework with verifiable data traceability controls. In: Casteleyn, S., Dolog, P., Pautasso, C. (eds.) ICWE 2016. LNCS, vol. 9881, pp. 3\u201315. Springer, Cham (2016). https:\/\/doi.org\/10.1007\/978-3-319-46963-8_1"},{"key":"20_CR22","doi-asserted-by":"crossref","unstructured":"Goguen, J.A., Meseguer, J.: Security policies and security models. In: S &P 1982. IEEE (1982)","DOI":"10.1109\/SP.1982.10014"},{"key":"20_CR23","doi-asserted-by":"crossref","unstructured":"Havelund, K., Rosu, G. (eds.): Runtime Verification, ENTCS, vol. 55. Elsevier (2001)","DOI":"10.1016\/S1571-0661(05)00258-6"},{"key":"20_CR24","doi-asserted-by":"publisher","unstructured":"Hublet, F., Basin, D., Krsti\u0107, S.: Real-time policy enforcement with metric first-order temporal logic. In: ESORICS 2022. vol. II. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-17146-8_11","DOI":"10.1007\/978-3-031-17146-8_11"},{"key":"20_CR25","doi-asserted-by":"crossref","unstructured":"Hublet, F., Basin, D., Krsti\u0107, S.: User-controlled Privacy: Taint, Track, and Control. In: Proceedings of Privacy Enforcing Technologies (PoPETS) (2024), to appear","DOI":"10.56553\/popets-2024-0034"},{"key":"20_CR26","unstructured":"Hublet, F., Basin, D., Krsti\u0107, S.: Companion repository for \u201cEnforcing the GDPR\u201c (2023). https:\/\/gitlab.ethz.ch\/fhublet\/enforcing-the-gdpr"},{"key":"20_CR27","doi-asserted-by":"crossref","unstructured":"Janssen, H., Cobbe, J., Norval, C., Singh, J.: Decentralized data processing: personal data stores and the GDPR. International Data Privacy Law 10(4) (2020)","DOI":"10.1093\/idpl\/ipaa016"},{"key":"20_CR28","doi-asserted-by":"crossref","unstructured":"Karami, F., Basin, D., Johnsen, E.B.: DPL: a language for GDPR enforcement. In: CSF 2022. IEEE (2022)","DOI":"10.1109\/CSF54842.2022.9919687"},{"key":"20_CR29","doi-asserted-by":"crossref","unstructured":"Kuty\u0142owski, M., Lauks-Dutka, A., Yung, M.: GDPR-challenges for reconciling legal rules with technical reality. In: ESORICS 2020, vol. I. Springer (2020)","DOI":"10.1007\/978-3-030-58951-6_36"},{"key":"20_CR30","unstructured":"Lehmann, N., et al.: STORM: refinement types for secure web applications. In: OSDI 2021 (2021)"},{"key":"20_CR31","series-title":"Lecture Notes in Computer Science (Lecture Notes in Artificial Intelligence)","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-030-73959-1_1","volume-title":"Trustworthy AI - Integrating Learning, Optimization and Reasoning","author":"T Libal","year":"2021","unstructured":"Libal, T.: Towards automated GDPR compliance checking. In: Heintz, F., Milano, M., O\u2019Sullivan, B. (eds.) TAILOR 2020. LNCS (LNAI), vol. 12641, pp. 3\u201319. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-73959-1_1"},{"key":"20_CR32","unstructured":"Nguyen, T.T., Backes, M., Marnau, N., Stock, B.: Share first, ask later (or never?)-studying violations of GDPR\u2019s explicit consent in android apps. In: USENIX Security (2021)"},{"key":"20_CR33","unstructured":"Palmirani, M., Governatori, G.: Modelling legal knowledge for GDPR Compliance Checking. In: JURIX 2018 (2018)"},{"key":"20_CR34","doi-asserted-by":"crossref","unstructured":"Polikarpova, N., Stefan, D., Yang, J., Itzhaky, S., Hance, T., Solar-Lezama, A.: Liquid information flow control. PACMPL 4(ICFP) (2020)","DOI":"10.1145\/3408987"},{"key":"20_CR35","unstructured":"Puhlmann, N., Wiesmaier, A., Heinemann, A.: Privacy dashboards for citizens and GDPR services for small data holders: a literature review. arXiv (2023)"},{"key":"20_CR36","doi-asserted-by":"crossref","unstructured":"Raschke, P., K\u00fcpper, A., Drozd, O., Kirrane, S.: Designing a GDPR-compliant and usable privacy dashboard. IFIP 2017 (2018)","DOI":"10.1007\/978-3-319-92925-5_14"},{"key":"20_CR37","doi-asserted-by":"crossref","unstructured":"Robaldo, L., Bartolini, C., Palmirani, M., Rossi, A., Martoni, M., Lenzini, G.: Formalizing GDPR provisions in reified I\/O logic: the DAPRECO knowledge base. JLLI 29 (2020)","DOI":"10.1007\/s10849-019-09309-z"},{"key":"20_CR38","doi-asserted-by":"crossref","unstructured":"Robaldo, L., Sun, X.: Reified input\/output logic: combining input\/output logic and reification to represent norms coming from existing legislation. J. Log. Comput. 27(8) (2017)","DOI":"10.1093\/logcom\/exx009"},{"key":"20_CR39","doi-asserted-by":"crossref","unstructured":"Schneider, F.B.: Enforceable security policies. TISSEC 3(1) (2000)","DOI":"10.1145\/353323.353382"},{"key":"20_CR40","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"39","DOI":"10.1007\/978-3-030-33752-0_3","volume-title":"Heterogeneous Data Management, Polystores, and Analytics for Healthcare","author":"M Schwarzkopf","year":"2019","unstructured":"Schwarzkopf, M., Kohler, E., Frans Kaashoek, M., Morris, R.: Position: GDPR compliance by construction. In: Gadepally, V., Mattson, T., Stonebraker, M., Wang, F., Luo, G., Laing, Y., Dubovitskaya, A. (eds.) DMAH\/Poly -2019. LNCS, vol. 11721, pp. 39\u201353. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-33752-0_3"},{"key":"20_CR41","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"169","DOI":"10.1007\/978-3-030-50086-3_10","volume-title":"Formal Techniques for Distributed Objects, Components, and Systems","author":"S Tokas","year":"2020","unstructured":"Tokas, S., Owe, O.: A formal framework for consent management. In: Gotsman, A., Sokolova, A. (eds.) FORTE 2020. LNCS, vol. 12136, pp. 169\u2013186. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-50086-3_10"},{"key":"20_CR42","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-42504-3_10","volume-title":"Language-based mechanisms for privacy-by-design","author":"S Tokas","year":"2020","unstructured":"Tokas, S., Owe, O., Ramezanifarkhani, T.: Language-based mechanisms for privacy-by-design. Privacy and Identity Management, Data for Better Living (2020)"},{"key":"20_CR43","doi-asserted-by":"crossref","unstructured":"Tokas, S., Owe, O., Ramezanifarkhani, T.: Static checking of GDPR-related privacy compliance for object-oriented distributed systems. JLAMP 125 (2022)","DOI":"10.1016\/j.jlamp.2021.100733"},{"key":"20_CR44","doi-asserted-by":"crossref","unstructured":"Torre, D., Soltana, G., Sabetzadeh, M., Briand, L.C., Auffinger, Y., Goes, P.: Using models to enable compliance checking against the GDPR: an experience report. In: MODELS 2019. IEEE (2019)","DOI":"10.1109\/MODELS.2019.00-20"},{"key":"20_CR45","doi-asserted-by":"crossref","unstructured":"Truong, N.B., Sun, K., Lee, G.M., Guo, Y.: GDPR-compliant personal data management: A blockchain-based solution. TIFS 15 (2019)","DOI":"10.1109\/TIFS.2019.2948287"},{"key":"20_CR46","unstructured":"Wang, F., Ko, R., Mickens, J.: Riverbed: Enforcing user-defined privacy constraints in distributed web services. In: NSDI 2019 (2019)"},{"key":"20_CR47","unstructured":"Wang, L., et al.: PrivGuard. Privacy regulation compliance made easier. In: USENIX Security 2022 (2022)"},{"key":"20_CR48","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-030-33752-0_1","volume-title":"Heterogeneous Data Management, Polystores, and Analytics for Healthcare","author":"L Wang","year":"2019","unstructured":"Wang, L., Near, J.P., Somani, N., Gao, P., Low, A., Dao, D., Song, D.: Data capsule: a new paradigm for automatic compliance with data privacy regulations. In: Gadepally, V., Mattson, T., Stonebraker, M., Wang, F., Luo, G., Laing, Y., Dubovitskaya, A. (eds.) DMAH\/Poly -2019. LNCS, vol. 11721, pp. 3\u201323. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-33752-0_1"},{"key":"20_CR49","doi-asserted-by":"crossref","unstructured":"Yang, J., Hance, T., Austin, T.H., Solar-Lezama, A., Flanagan, C., Chong, S.: Precise, dynamic information flow for database-backed applications. In: Krintz, C., Berger, E. (eds.) PLDI 2016 (2016)","DOI":"10.1145\/2908080.2908098"}],"container-title":["Lecture Notes in Computer Science","Computer Security \u2013 ESORICS 2023"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-51476-0_20","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,1,10]],"date-time":"2024-01-10T07:07:07Z","timestamp":1704870427000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-51476-0_20"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9783031514753","9783031514760"],"references-count":49,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-51476-0_20","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"11 January 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"The Hague","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"The Netherlands","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"25 September 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 September 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"28","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/esorics2023.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Easychair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"478","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"93","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"19% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3-4","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"10","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}