{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T17:30:42Z","timestamp":1783791042223,"version":"3.55.0"},"reference-count":61,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2018,11,21]],"date-time":"2018-11-21T00:00:00Z","timestamp":1542758400000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Requirements Eng"],"published-print":{"date-parts":[[2019,3]]},"DOI":"10.1007\/s00766-018-0305-2","type":"journal-article","created":{"date-parts":[[2018,11,21]],"date-time":"2018-11-21T05:03:20Z","timestamp":1542776600000},"page":"1-26","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":32,"title":["RSL-IL4Privacy: a domain-specific language for the rigorous specification of privacy policies"],"prefix":"10.1007","volume":"24","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5689-1020","authenticated-orcid":false,"given":"Jo\u00e3o","family":"Caramujo","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Alberto","family":"Rodrigues da Silva","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shaghayegh","family":"Monfared","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Andr\u00e9","family":"Ribeiro","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"P\u00e1vel","family":"Calado","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Travis","family":"Breaux","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2018,11,21]]},"reference":[{"key":"305_CR1","unstructured":"Regulation 2016\/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) (2016). https:\/\/www.eugdpr.org\/ . Accessed 14 Nov 2018"},{"key":"305_CR2","unstructured":"United States Department of Health and Human Service (2006) HIPAA administrative simplification: enforcement. Fed Regist\/Rules Regul 71(32):2006. https:\/\/www.federalregister.gov\/documents\/2009\/10\/30\/E9-26203\/hipaa-administrative-simplification-enforcement . Accessed 14 Nov 2018"},{"key":"305_CR3","unstructured":"Government of Canad\u00e1 (2018) Personal information protection and electronic documents act (PIPEDA). last updated in 2018. http:\/\/laws-lois.justice.gc.ca\/eng\/acts\/P-8.6\/FullText.html"},{"key":"305_CR4","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-12578-2","volume-title":"Requirements engineering: fundamentals, principles and techniques","author":"K Pohl","year":"2010","unstructured":"Pohl K (2010) Requirements engineering: fundamentals, principles and techniques. Springer, New York"},{"key":"305_CR5","unstructured":"Kovitz B (1998) Practical software requirements: manual of content and style, Manning 1998"},{"issue":"1","key":"305_CR6","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/s00766-010-0115-7","volume":"16","author":"M Deng","year":"2011","unstructured":"Deng M, Wuyts K, Scandariato R, Preneel B, Joosen W (2011) A privacy threat analysis framework: supporting the elicitation and fulfillment of privacy requirements. Requir Eng 16(1):3\u201332","journal-title":"Requir Eng"},{"key":"305_CR7","unstructured":"The STRIDE Threat Model. msdn.microsoft.com\/en-us\/library\/ee823878(v\u2009=\u2009cs.20).aspx"},{"key":"305_CR8","doi-asserted-by":"crossref","unstructured":"Caramujo J, Silva AR (2015) Analyzing privacy policies based on a privacy-aware profile: the Facebook and LinkedIn case studies. In: IEEE 17th conference on business informatics (CBI), July 2015","DOI":"10.1109\/CBI.2015.44"},{"key":"305_CR9","unstructured":"Silva AR, Caramujo J, Monfared S, Calado P, Breaux T (2016) Improving the specification and analysis of privacy policies: the RSLingo4Privacy approach. In: International conference on enterprise information systems, SCITEPRESS"},{"key":"305_CR10","volume-title":"Implementing domain-specific languages with Xtext and Xtend","author":"L Bettini","year":"2013","unstructured":"Bettini L (2013) Implementing domain-specific languages with Xtext and Xtend. Packt Publishing Ltd, Birmingham"},{"issue":"3","key":"305_CR11","doi-asserted-by":"publisher","first-page":"281","DOI":"10.1007\/s00766-013-0190-7","volume":"19","author":"TD Breaux","year":"2014","unstructured":"Breaux TD, Hibshi H, Rao A (2014) Eddy, a formal language for specifying and analyzing data flow specifications for conflicting privacy requirements. Requir Eng 19(3):281\u2013307","journal-title":"Requir Eng"},{"issue":"6","key":"305_CR12","doi-asserted-by":"publisher","first-page":"26","DOI":"10.1145\/352029.352035","volume":"35","author":"A Deursen Van","year":"2000","unstructured":"Van Deursen A, Klint P, Visser J (2000) Domain-specific languages: an annotated bibliography. ACM SIGPLAN Notices 35(6):26\u201336","journal-title":"ACM SIGPLAN Notices"},{"key":"305_CR13","first-page":"139","volume":"43","author":"AR Silva da","year":"2015","unstructured":"da Silva AR (2015) Model-driven engineering: a survey supported by a unified conceptual model. Comput Lang Syst Struct 43:139\u2013155","journal-title":"Comput Lang Syst Struct"},{"key":"305_CR14","volume-title":"Deontic logic: a concise overview, deontic logic in computer science: normative system specification","author":"J-J Meyer","year":"1993","unstructured":"Meyer J-J (1993) Deontic logic: a concise overview, deontic logic in computer science: normative system specification. Wiley, Hoboken"},{"key":"305_CR15","first-page":"1","volume-title":"Goal-oriented requirements engineering: an extended systematic mapping study, requirements engineering","author":"J Horkoff","year":"2017","unstructured":"Horkoff J, Aydemir FB, Cardoso E, Li T, Mat\u00e9 A, Paja E, Salnitri M, Piras L, Mylopoulos J, Giorgini P (2017) Goal-oriented requirements engineering: an extended systematic mapping study, requirements engineering. Springer, New York, pp 1\u201328"},{"key":"305_CR16","doi-asserted-by":"crossref","unstructured":"Ribeiro A, Silva AR (2017) RSLingo4Privacy studio: a tool to improve the specification and analysis of privacy policies. In: International conference on enterprise information systems, SCITEPRESS","DOI":"10.5220\/0006310400520063"},{"key":"305_CR17","volume-title":"The description logic handbook: theory, implementantion and applications","author":"F Baader","year":"2003","unstructured":"Baader F (2003) The description logic handbook: theory, implementantion and applications. Cambridge University Press, Cambridge"},{"issue":"1","key":"305_CR18","doi-asserted-by":"publisher","first-page":"477","DOI":"10.1016\/j.comnet.2011.09.014","volume":"56","author":"W Han","year":"2012","unstructured":"Han W, Lei C (2012) A survey on policy languages in network and security management. Comput Netw 56(1):477\u2013489","journal-title":"Comput Netw"},{"key":"305_CR19","doi-asserted-by":"crossref","unstructured":"Anthonysamy P, Rashid A, Chitchyan R (2017) Privacy requirements: present and future. In: Proceedings of the 39th international conference on software engineering, IEEE Press","DOI":"10.1109\/ICSE-SEIS.2017.3"},{"key":"305_CR20","doi-asserted-by":"crossref","unstructured":"Kapitsaki G, Venieris I (2008) PCP: privacy-aware context profile towards context-aware application development. In: 10th international conference on information integration and web-based applications & services. pp 104\u2013110","DOI":"10.1145\/1497308.1497332"},{"key":"305_CR21","doi-asserted-by":"crossref","unstructured":"L. Kagal, T. Finin and A. Joshi, \u201cA policy language for a pervasive computing environment\u201d, 4th IEEE International Workshop on Policies for Distributed Systems and Networks, pp. 63\u201474, June 2003","DOI":"10.1109\/POLICY.2003.1206958"},{"key":"305_CR22","doi-asserted-by":"crossref","unstructured":"Karat J, Karat CM, Brodie C, Feng J (2005) Designing natural language and structured entry methods for privacy policy authoring. In: Human\u2013Computer Interaction\u2014INTERACT. Springer, pp 671-684","DOI":"10.1007\/11555261_54"},{"key":"305_CR23","unstructured":"W3C, The platform for privacy preferences (P3P) project: http:\/\/www.w3.org\/P3P\/ . Accessed 14 Nov 2018"},{"key":"305_CR24","unstructured":"eXtensible Access Control Markup Language (XACML) Version 3.0. 22 January 2013. OASIS Standard"},{"key":"305_CR25","unstructured":"Enterprise Policy Authorization Language 1.2 (EPAL) Specification, W3C. https:\/\/www.w3.org\/Submission\/2003\/SUBM-EPAL-20031110 . Accessed 14 Nov 2018"},{"key":"305_CR26","unstructured":"P3P Preference Exchange Language 1.0 (APPEL) Specification, W3C, http:\/\/www.w3.org\/TR\/P3P-preferences . Accessed 14 Nov 2018"},{"key":"305_CR27","doi-asserted-by":"publisher","first-page":"50","DOI":"10.1109\/MSECP.2003.1253568","volume":"6","author":"LF Cranor","year":"2003","unstructured":"Cranor LF (2003) P3P: making privacy policies more useful. IEEE Secur Priv 6:50\u201355","journal-title":"IEEE Secur Priv"},{"key":"305_CR28","doi-asserted-by":"crossref","unstructured":"Backes M, Pfitzmann B, Schunter M (2003) A toolkit for managing enterprise privacy policies, In: European symposium on research in computer security. Springer","DOI":"10.1007\/978-3-540-39650-5_10"},{"key":"305_CR29","doi-asserted-by":"crossref","unstructured":"Brodie CA, Karat C-M, Karat J (2006) An empirical study of natural language parsing of privacy policy rules using the SPARCLE policy workbench. In: Proceedings of the second symposium on Usable privacy and security. ACM","DOI":"10.1145\/1143120.1143123"},{"key":"305_CR30","unstructured":"W3C, P3P 1.0 Implementations. http:\/\/www.w3.org\/P3P\/implementations . Accessed 14 Nov 2018"},{"key":"305_CR31","doi-asserted-by":"crossref","unstructured":"Uszok A, Bradshaw J, Jeffers R, Suri N, Hayes P, Breedy M, Bunch L, Johnson M, Kulkarni S, Lott J (2003) KAoS policy and domain services: toward a description-logic approach to policy representation, deconfliction, and enforcement. In: 4th IEEE international workshop on policies for distributed systems and networks, pp 93\u201396","DOI":"10.1109\/POLICY.2003.1206963"},{"key":"305_CR32","doi-asserted-by":"publisher","first-page":"123","DOI":"10.1016\/j.datak.2015.07.007","volume":"98","author":"E Paja","year":"2015","unstructured":"Paja E, Dalpiaz F, Giorgini P (2015) Modeling and reasoning about security requirements in socio-technical systems. Data Knowl Eng 98:123\u2013143","journal-title":"Data Knowl Eng"},{"key":"305_CR33","unstructured":"W3C (2011) Notation3 (N3): a readable RDF syntax. https:\/\/www.w3.org\/TeamSubmission\/n3\/ . Accessed 14 Nov 2018"},{"key":"305_CR34","unstructured":"Shah AB (2005) An integrated development environment for policies. Master Thesis. University of Baltimore"},{"key":"305_CR35","volume-title":"Security requirements engineering: designing secure socio-technical systems","author":"F Dalpiaz","year":"2016","unstructured":"Dalpiaz F, Paja E, Giorgini P (2016) Security requirements engineering: designing secure socio-technical systems. MIT Press, Cambridge"},{"key":"305_CR36","doi-asserted-by":"crossref","unstructured":"Wishart R, Corapi D, Marinovic S, Sloman M (2010) Collaborative privacy policy authoring in a social networking context. In: Proceedings of the policy symposium. IEEE, pp 1\u20138","DOI":"10.1109\/POLICY.2010.13"},{"issue":"2","key":"305_CR37","doi-asserted-by":"publisher","first-page":"75","DOI":"10.1109\/MTS.2016.2554419","volume":"35","author":"S Winkler","year":"2016","unstructured":"Winkler S, Zeadally S (2016) Privacy policy analysis of popular web platforms. IEEETechnology and Society Magazine 35(2):75\u201385","journal-title":"IEEETechnology and Society Magazine"},{"key":"305_CR38","doi-asserted-by":"crossref","unstructured":"Gharib M, Giorgini P, Mylopoulos J (2017) Towards an ontology for privacy requirements via a systematic literature review. In: International conference on conceptual modeling. Springer","DOI":"10.1007\/978-3-319-69904-2_16"},{"issue":"02","key":"305_CR39","doi-asserted-by":"publisher","first-page":"285","DOI":"10.1142\/S0218194007003240","volume":"17","author":"H Mouratidis","year":"2007","unstructured":"Mouratidis H, Giorgini P (2007) Secure tropos: a security-oriented extension of the tropos methodology. Int J Software Eng Knowl Eng 17(02):285\u2013309","journal-title":"Int J Software Eng Knowl Eng"},{"key":"305_CR40","unstructured":"Moore B, Ellesson E, Strassner J, Westerinen A (2001) Policy core information 1.0 specification, RFC 3060. http:\/\/www.ietf.org\/rfc\/rfc3060 . Accessed 14 Nov 2018"},{"issue":"Part B","key":"305_CR41","doi-asserted-by":"publisher","first-page":"105","DOI":"10.1016\/j.scico.2013.05.004","volume":"89","author":"A Nadas","year":"2014","unstructured":"Nadas A, Levendovszky T, Jackson EK, Madari I, Sztipanovits J (2014) A model-integrated authoring environment for privacy policies. Sci Comput Program. 89(Part B):105\u2013125","journal-title":"Sci Comput Program."},{"key":"305_CR42","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1109\/TSE.2007.70746","volume":"34","author":"T Breaux","year":"2008","unstructured":"Breaux T, Anton A (2008) Analyzing regulatory rules for privacy and security requirements. IEEE Trans Softw Eng 34:5\u201320","journal-title":"IEEE Trans Softw Eng"},{"key":"305_CR43","doi-asserted-by":"publisher","first-page":"33","DOI":"10.1007\/s00766-010-0108-6","volume":"16","author":"J Young","year":"2011","unstructured":"Young J (2011) Commitment analysis to operationalize software requirements from privacy policies\u201d. Requir Eng 16:33\u201346","journal-title":"Requir Eng"},{"key":"305_CR44","first-page":"119","volume":"79","author":"H Nissenbaum","year":"2004","unstructured":"Nissenbaum H (2004) Privacy as contextual integrity. Wash L Rev 79:119","journal-title":"Wash L Rev"},{"key":"305_CR45","doi-asserted-by":"publisher","first-page":"477","DOI":"10.2307\/40041279","volume":"154","author":"DJ Solove","year":"2006","unstructured":"Solove DJ (2006) A taxonomy of privacy. Univ Pa Law Rev 154:477","journal-title":"Univ Pa Law Rev"},{"key":"305_CR46","doi-asserted-by":"crossref","unstructured":"Massey A, Otto P, Hayward L, Anton A (2010) Evaluating existing security and privacy requirements for legal compliance. In: Proceedings of the RE","DOI":"10.1007\/s00766-009-0089-5"},{"key":"305_CR47","doi-asserted-by":"publisher","first-page":"109","DOI":"10.1145\/1272516.1272522","volume":"50","author":"AI Anton","year":"2007","unstructured":"Anton AI, Bertino E, Li N, Yu T (2007) A roadmap for comprehensive online privacy policy management. Commun ACM 50:109\u2013116","journal-title":"Commun ACM"},{"key":"305_CR48","doi-asserted-by":"crossref","unstructured":"Barth A, Datta A, Mitchell JC, Nissenbaum H (2006) Privacy and contextual integrity: framework and applications. In: Proceedings 2006 IEEE symposium on security and privacy","DOI":"10.1109\/SP.2006.32"},{"key":"305_CR49","doi-asserted-by":"crossref","unstructured":"Cleland-Huang J, Czauderna A, Gibiec M, Emenecker J (2010) A machine learning approach for tracing regulatory codes to product specific requirements. In: ICSE","DOI":"10.1145\/1806799.1806825"},{"key":"305_CR50","doi-asserted-by":"publisher","first-page":"277","DOI":"10.1145\/1072997.1072999","volume":"14","author":"V Gervasi","year":"2005","unstructured":"Gervasi V, Zowghi D (2005) Reasoning about inconsistencies in natural language requirements. ACM Trans Softw Eng Methodol 14:277\u2013330","journal-title":"ACM Trans Softw Eng Methodol"},{"key":"305_CR51","doi-asserted-by":"crossref","unstructured":"Guha A, Fredrikson M, Livshits B, Swamy N (2011) Verified security for browser extensions. In: 2011 IEEE symposium on security and privacy","DOI":"10.1109\/SP.2011.36"},{"key":"305_CR52","doi-asserted-by":"crossref","unstructured":"Johnson ML, Egelman S, Bellovin SM (2012) Facebook and privacy: it\u2019s complicated. In: SOUPS","DOI":"10.1145\/2335356.2335369"},{"key":"305_CR53","unstructured":"Gurses S, Rizk R, Gunther O (2008) Privacy design in online social networks: learning from privacy breaches and community feedback. In: ICIS 2008 proceedings. ACM"},{"key":"305_CR54","doi-asserted-by":"crossref","unstructured":"Bonneau J, Preibusch S (2010) The privacy jungle: on the market for data protection in social networks. In: Economics of information security and privacy. Springer","DOI":"10.1007\/978-1-4419-6967-5_8"},{"key":"305_CR55","doi-asserted-by":"crossref","unstructured":"Acquisti A, Gross R (2006) Imagined communities: awareness, information sharing, and privacy on the facebook. In: Privacy enhancing technologies. Springer","DOI":"10.1007\/11957454_3"},{"key":"305_CR56","unstructured":"Drgon M, Magnuson G, Sabo J (eds) (2016) Privacy management reference model and methodology (PMRM) version 1.0. OASIS. http:\/\/docs.oasis-open.org\/pmrm\/PMRM\/v1.0\/cs02\/PMRM-v1.0-cs02.html . Accessed 14 Nov 2018"},{"key":"305_CR57","unstructured":"Diamantopoulou V, Pavlidis M, Mouratidis H (2017) Privacy level agreements for public administration information systems. In: CAiSE 2017 forum and doctoral consortium papers"},{"issue":"3","key":"305_CR58","doi-asserted-by":"publisher","first-page":"241","DOI":"10.1007\/s00766-008-0067-3","volume":"13","author":"C Kalloniatis","year":"2008","unstructured":"Kalloniatis C, Kavakli E, Gritzalis S (2008) Addressing privacy requirements in system design: the PriS method. Requir Eng 13(3):241\u2013255","journal-title":"Requir Eng"},{"key":"305_CR59","doi-asserted-by":"crossref","unstructured":"Nurse JR, Atamli A, Martin A (2016) Towards a usable framework for modelling security and privacy risks in the smart home. In: International conference on human aspects of information security, privacy, and trust. Springer, pp 255\u2013267","DOI":"10.1007\/978-3-319-39381-0_23"},{"key":"305_CR60","first-page":"22","volume":"25","author":"J Bhatia","year":"2016","unstructured":"Bhatia J, Breaux T, Schaub F (2016) Privacy goal mining through hybridized task re-composition. ACM Trans Soft Eng Method 25:22","journal-title":"ACM Trans Soft Eng Method"},{"key":"305_CR61","unstructured":"Gon\u00e7alves L, Silva AR (2018) Towards a catalogue of reusable security requirements, vulnerabilities and threats. In: Designing digitalization (ISD2018 Proceedings). ISBN:978-91-7753-876-9. http:\/\/aisel.aisnet.org\/isd2014\/proceedings2018\/HCI\/5 . Accessed 14 Nov 2018"}],"container-title":["Requirements Engineering"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s00766-018-0305-2\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00766-018-0305-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00766-018-0305-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,4]],"date-time":"2026-04-04T04:26:59Z","timestamp":1775276819000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s00766-018-0305-2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,11,21]]},"references-count":61,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2019,3]]}},"alternative-id":["305"],"URL":"https:\/\/doi.org\/10.1007\/s00766-018-0305-2","relation":{},"ISSN":["0947-3602","1432-010X"],"issn-type":[{"value":"0947-3602","type":"print"},{"value":"1432-010X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018,11,21]]},"assertion":[{"value":"7 October 2016","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"8 November 2018","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"21 November 2018","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}