{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,7,3]],"date-time":"2025-07-03T04:06:06Z","timestamp":1751515566186,"version":"3.41.0"},"reference-count":41,"publisher":"Springer Science and Business Media LLC","issue":"20","license":[{"start":{"date-parts":[[2024,11,4]],"date-time":"2024-11-04T00:00:00Z","timestamp":1730678400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,11,4]],"date-time":"2024-11-04T00:00:00Z","timestamp":1730678400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"DOI":"10.13039\/501100009886","name":"Regione Puglia","doi-asserted-by":"publisher","award":["6ESURE5"],"award-info":[{"award-number":["6ESURE5"]}],"id":[{"id":"10.13039\/501100009886","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Multimed Tools Appl"],"DOI":"10.1007\/s11042-024-20308-6","type":"journal-article","created":{"date-parts":[[2024,11,4]],"date-time":"2024-11-04T09:22:09Z","timestamp":1730712129000},"page":"23163-23185","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Enhancing privacy awareness through a novel BPMN based methodology"],"prefix":"10.1007","volume":"84","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7292-9471","authenticated-orcid":false,"given":"Antonio","family":"Capodieci","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Luca","family":"Mainetti","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Stefano","family":"Lisi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Roberto","family":"Paiano","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sara","family":"Matino","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mariavittoria","family":"Ugirashebuja","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,11,4]]},"reference":[{"key":"20308_CR1","unstructured":"Wilhelm E-O. A brief history of the General Data Protection Regulation, https:\/\/iapp.org\/resources\/article\/a-brief-history-of-the-general-data-protection-regulation\/"},{"key":"20308_CR2","doi-asserted-by":"publisher","unstructured":"Pesic M et al (2007) DECLARE: Full support for loosely-structured processes. In: Proceedings. https:\/\/doi.org\/10.1109\/EDOC.2007.14","DOI":"10.1109\/EDOC.2007.14"},{"key":"20308_CR3","doi-asserted-by":"publisher","unstructured":"Hildebrandt TT, Mukkamala RR (2011) Declarative event-based workflow as distributed dynamic condition response graphs. Arxiv preprint arxiv:1110.4161. https:\/\/doi.org\/10.4204\/EPTCS.69.5","DOI":"10.4204\/EPTCS.69.5"},{"key":"20308_CR4","doi-asserted-by":"publisher","DOI":"10.1111\/j.1462-2920.2012.02849.x","author":"D Harel","year":"1998","unstructured":"Harel D et al (1998). Modeling reactive systems with statecharts. https:\/\/doi.org\/10.1111\/j.1462-2920.2012.02849.x","journal-title":"Modeling reactive systems with statecharts"},{"issue":"3","key":"20308_CR5","doi-asserted-by":"publisher","first-page":"197","DOI":"10.1142\/S0219649208002081","volume":"7","author":"P Ardimento","year":"2008","unstructured":"Ardimento P et al (2008) Empirical investigation of the efficacy and efficiency of tools for transferring software engineering knowledge. J Info Know Mgmt 7(3):197\u2013207. https:\/\/doi.org\/10.1142\/S0219649208002081","journal-title":"J Info Know Mgmt"},{"issue":"1","key":"20308_CR6","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/s13173-010-0003-5","volume":"16","author":"S Espa\u00f1a","year":"2010","unstructured":"Espa\u00f1a S et al (2010) An empirical comparative evaluation of requirements engineering methods. J Braz Comput Soc 16(1):3\u201319. https:\/\/doi.org\/10.1007\/s13173-010-0003-5","journal-title":"J Braz Comput Soc"},{"key":"20308_CR7","doi-asserted-by":"publisher","unstructured":"Fernandez-Saez AM et al (2015) On the use of UML documentation in software maintenance: results from a survey in industry. In: 2015 ACM\/IEEE 18th international conference on model driven engineering languages and systems, MODELS 2015 \u2013 Proceedings, IEEE Inc, pp. 292\u2013301. https:\/\/doi.org\/10.1109\/MODELS.2015.7338260","DOI":"10.1109\/MODELS.2015.7338260"},{"key":"20308_CR8","doi-asserted-by":"publisher","unstructured":"Group OM (2015) OMG Unified Modeling Language TM ( OMG UML), Superstructure v.2.5. Informatikspektrum. https:\/\/doi.org\/10.1007\/s002870050092","DOI":"10.1007\/s002870050092"},{"key":"20308_CR9","doi-asserted-by":"publisher","unstructured":"Hull R et al (2011) Introducing the guard-stage-milestone approach for specifying business entity lifecycles. In: Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics). https:\/\/doi.org\/10.1007\/978-3-642-19589-1_1","DOI":"10.1007\/978-3-642-19589-1_1"},{"key":"20308_CR10","unstructured":"Object Management Group (2013) Case management model and notation (CMMN)"},{"key":"20308_CR11","doi-asserted-by":"publisher","unstructured":"Object Management Group (2011) Business process model and notation (BPMN) Version 2.0. https:\/\/doi.org\/10.1007\/s11576-008-0096-z.","DOI":"10.1007\/s11576-008-0096-z"},{"key":"20308_CR12","doi-asserted-by":"crossref","unstructured":"Cherdantseva Y et al (2012) Towards securebpmn - Aligning BPMN with the information assurance and security domain. In: Mendling J, Weidlich M (eds.) Business process model and notation. Springer Berlin Heidelberg, pp. 107\u2013115","DOI":"10.1007\/978-3-642-33155-8_9"},{"key":"20308_CR13","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2010.07.057","author":"M Enamul Kabir","year":"2011","unstructured":"Enamul Kabir M et al (2011) A conditional purpose-based access control model with dynamic roles. Expert Syst Appl. https:\/\/doi.org\/10.1016\/j.eswa.2010.07.057","journal-title":"Expert Syst Appl"},{"key":"20308_CR14","doi-asserted-by":"publisher","DOI":"10.4018\/978-1-59140-570-2.ch011","author":"M Cremonini","year":"2005","unstructured":"Cremonini M et al (2005) Security, privacy, and trust in mobile systems and applications. IGI Global. https:\/\/doi.org\/10.4018\/978-1-59140-570-2.ch011","journal-title":"IGI Global"},{"issue":"1","key":"20308_CR15","doi-asserted-by":"publisher","first-page":"57","DOI":"10.4018\/ijec.2014010104","volume":"10","author":"C Ardito","year":"2014","unstructured":"Ardito C et al (2014) Business process design meets business practices through enterprise patterns. Int J e-Collab 10(1):57\u201373. https:\/\/doi.org\/10.4018\/ijec.2014010104","journal-title":"Int J e-Collab"},{"issue":"1","key":"20308_CR16","first-page":"113","volume":"30","author":"U Barchetti","year":"2012","unstructured":"Barchetti U et al (2012) Modelling collaboration processes through design patterns. Comput Inf 30(1):113\u2013135","journal-title":"Comput Inf"},{"key":"20308_CR17","doi-asserted-by":"publisher","unstructured":"Capodieci A, Mainetti\u00a0L, Alem\u00a0L (2015) An innovative approach to digital engineering services delivery: An application in maintenance. In: 2015 11th International Conference on Innovations in Information Technology (IIT), Dubai, pp 342\u2013349. https:\/\/doi.org\/10.1109\/INNOVATIONS.2015.7381565","DOI":"10.1109\/INNOVATIONS.2015.7381565"},{"key":"20308_CR18","doi-asserted-by":"publisher","unstructured":"Labda W et al (2014) Modeling of privacy-aware business processes in bpmn to protect personal data. In: Proceedings of the 29th Annual ACM symposium on applied computing. ACM, New York, NY, USA, Pp. 1399\u20131405. https:\/\/doi.org\/10.1145\/2554850.2555014","DOI":"10.1145\/2554850.2555014"},{"key":"20308_CR19","doi-asserted-by":"publisher","unstructured":"Brucker AD (2013) Integrating security aspects into business process models. It \u2013 Information Technology it \u201355, 6, 239\u2013246. https:\/\/doi.org\/10.1515\/itit.2013.2004","DOI":"10.1515\/itit.2013.2004"},{"issue":"4","key":"20308_CR20","doi-asserted-by":"publisher","first-page":"93","DOI":"10.4018\/ijismd.2013100105","volume":"4","author":"O Altuhhov","year":"2013","unstructured":"Altuhhov O et al (2013) An Extension of business process model and notation for security risk management. Int J Inf Syst Model Des (IJISMD) 4(4):93\u2013113. https:\/\/doi.org\/10.4018\/ijismd.2013100105","journal-title":"Int J Inf Syst Model Des (IJISMD)"},{"key":"20308_CR21","doi-asserted-by":"crossref","unstructured":"Pullonen P et al (2017) PE-BPMN: privacy-enhanced business process model and notation. In: Carmona J et al. (eds.) Business process management. Springer International Publishing, pp. 40\u201356","DOI":"10.1007\/978-3-319-65000-5_3"},{"issue":"3","key":"20308_CR22","doi-asserted-by":"publisher","first-page":"737","DOI":"10.1007\/s10270-015-0499-4","volume":"16","author":"M Salnitri","year":"2017","unstructured":"Salnitri M et al (2017) Designing secure business processes with secbpmn. Softw Syst Model 16(3):737\u2013757. https:\/\/doi.org\/10.1007\/s10270-015-0499-4","journal-title":"Softw Syst Model"},{"key":"20308_CR23","doi-asserted-by":"crossref","unstructured":"Chergui MEA, Benslimane SM (2018) A valid BPMN Extension for supporting security requirements based on cyber security ontology. In: Abdelwahed EH et al (eds.) Model and data engineering. Springer International Publishing, pp. 219\u2013232","DOI":"10.1007\/978-3-030-00856-7_14"},{"key":"20308_CR24","doi-asserted-by":"publisher","unstructured":"Maines CL et al (2015) A cyber security ontology for bpmn-security extensions. In: 2015 IEEE International conference on computer and information technology; ubiquitous computing and communications; Dependable, autonomic and secure computing; Pervasive intelligence and computing, pp. 1756\u20131763. https:\/\/doi.org\/10.1109\/CIT\/IUCC\/DASC\/PICOM.2015.265.","DOI":"10.1109\/CIT\/IUCC\/DASC\/PICOM.2015.265"},{"key":"20308_CR25","doi-asserted-by":"publisher","unstructured":"Maines CL et al (2016) Adding a third dimension to bpmn as a means of representing cyber security requirements. In: 2016 9th international conference on developments in esystems engineering (dese), pp. 105\u2013110. https:\/\/doi.org\/10.1109\/dese.2016.69","DOI":"10.1109\/dese.2016.69"},{"key":"20308_CR26","doi-asserted-by":"publisher","unstructured":"Menzel M et al (2009) Security requirements specification in service-oriented business process management. In: 2009 international conference on availability, reliability and security, pp. 41\u201348. https:\/\/doi.org\/10.1109\/ARES.2009.90","DOI":"10.1109\/ARES.2009.90"},{"key":"20308_CR27","doi-asserted-by":"crossref","unstructured":"Palmirani M et al (2018) Pronto: privacy ontology for legal reasoning. In: K\u0151 A, Francesconi E (eds.) Electronic government and the information systems perspective. Springer International Publishing, pp. 139\u2013152","DOI":"10.1007\/978-3-319-98349-3_11"},{"key":"20308_CR28","doi-asserted-by":"crossref","unstructured":"Basin D et al (2018) On purpose and by necessity: compliance under the GDPR. In: Financial cryptography and data security (FC)","DOI":"10.1007\/978-3-662-58387-6_2"},{"key":"20308_CR29","doi-asserted-by":"publisher","unstructured":"Rodr\u00edguez A et al (2007) A BPMN extension for the modeling of security requirements in business processes. IEICE Trans Info Syst.https:\/\/doi.org\/10.1093\/ietisy\/e90-d.4.745","DOI":"10.1093\/ietisy\/e90-d.4.745"},{"key":"20308_CR30","unstructured":"Amantea IA et al (2022) Business process modelling in healthcare and compliance management: a logical framework. J Appl Log \u2014IfCoLog J Log Appl 9(4)"},{"key":"20308_CR31","unstructured":"Desiato D (2018) A methodology for GDPR compliant data processing. Sistemi Evoluti per Basi di Dati"},{"key":"20308_CR32","doi-asserted-by":"publisher","unstructured":"Matulevi\u010dius R, Tom J, Kala K, Sing E (2020) A method for managing gdpr compliance in business processes. CAiSE Forum. https:\/\/doi.org\/10.1007\/978-3-030-58135-0_9","DOI":"10.1007\/978-3-030-58135-0_9"},{"key":"20308_CR33","doi-asserted-by":"crossref","unstructured":"Riva GM, Vasenev A, Zannone N (2020) SoK: engineering privacy-aware high-tech systems. Proceedings of the 15th International Conference on Availability, Reliability and Security","DOI":"10.1145\/3407023.3407061"},{"key":"20308_CR34","doi-asserted-by":"publisher","unstructured":"Ryan P, Crane M, Brennan R. (2020) GDPR compliance tools: best practice from RegTech. International conference on enterprise information systems. https:\/\/doi.org\/10.1007\/978-3-030-75418-1_41","DOI":"10.1007\/978-3-030-75418-1_41"},{"key":"20308_CR35","doi-asserted-by":"publisher","first-page":"531","DOI":"10.1108\/ICS-01-2020-0002","volume":"28","author":"A Tsohou","year":"2020","unstructured":"Tsohou A, Magkos E, Mouratidis H, Chrysoloras G, Piras L, Pavlidis M, Debussche J, Rotoloni M, Gallego-Nicasio B (2020) Privacy, security, legal and technology acceptance elicited and consolidated requirements for a GDPR compliance platform. Inf Comput Secur 28:531\u2013553","journal-title":"Inf Comput Secur"},{"key":"20308_CR36","doi-asserted-by":"publisher","unstructured":"Marikyan D, Papagiannidis S, Rana OF, Ranjan R (2023) General data protection regulation: a study on attitude and emotional empowerment. Behaviour & Information Technology 1-17. https:\/\/doi.org\/10.1080\/0144929X.2023.2285341","DOI":"10.1080\/0144929X.2023.2285341"},{"key":"20308_CR37","doi-asserted-by":"publisher","unstructured":"Essefi I, Rahmouni HB, Ladeb MF (2021) Integrated privacy decision in BPMN clinical care pathways models using DMN. Procedia Comp Sci. https:\/\/doi.org\/10.1016\/j.procs.2021.12.043","DOI":"10.1016\/j.procs.2021.12.043"},{"key":"20308_CR38","doi-asserted-by":"publisher","unstructured":"Capodieci A, Mainetti L (2019) Business process awareness to support GDPR compliance. In: In Proceedings of ICIST \u201919. ACM, Cairo. https:\/\/doi.org\/10.1145\/3361570.3361573.","DOI":"10.1145\/3361570.3361573"},{"key":"20308_CR39","doi-asserted-by":"publisher","unstructured":"Capodieci A, Mainetti L (2020) A structured approach to GDPR compliance. In: Przegalinska A, Grippa F, Gloor P (eds) Digital transformation of collaboration. COINs 2019. Springer Proceedings in Complexity. Springer, Cham. https:\/\/doi.org\/10.1007\/978-3-030-48993-9_16","DOI":"10.1007\/978-3-030-48993-9_16"},{"key":"20308_CR40","unstructured":"www.enisa.europe.eu. Accessed 30 July 2024"},{"key":"20308_CR41","unstructured":"https:\/\/www.cybersecurityframework.it\/framework2. Accessed 30 July 2024"}],"container-title":["Multimedia Tools and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11042-024-20308-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11042-024-20308-6\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11042-024-20308-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,2]],"date-time":"2025-07-02T11:23:28Z","timestamp":1751455408000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11042-024-20308-6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,11,4]]},"references-count":41,"journal-issue":{"issue":"20","published-online":{"date-parts":[[2025,6]]}},"alternative-id":["20308"],"URL":"https:\/\/doi.org\/10.1007\/s11042-024-20308-6","relation":{},"ISSN":["1573-7721"],"issn-type":[{"type":"electronic","value":"1573-7721"}],"subject":[],"published":{"date-parts":[[2024,11,4]]},"assertion":[{"value":"14 October 2023","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"12 September 2024","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"19 September 2024","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"4 November 2024","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}]}}