• Cite Icon11
  • https://doi.org/10.1145/3407023.3407061Copy DOI Icon

SoK

  • Aug 25, 2020
  • Giovanni Maria Riva +2 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

The processing of personal data is becoming a key business factor, especially for high-tech system industries such as automotive and healthcare service providers. To protect such data, the European Union (EU) has introduced the General Data Protection Regulation (GDPR), with the aim to standardize and strengthen data protection policies across EU countries. The GDPR defines stringent requirements on the collection and processing of personal data and imposes severe fines and penalties on data controllers and processors for non-compliance. Although the GDPR is enforce since 2018, many public and private organizations are still struggling to fully comply with the regulation. A main reason for this is the lack of usable methodologies that can support developers in designing of GDPR-complaint high-tech systems. This paper examines the growing literature on methodologies for the design of privacy-aware systems, and identifies the main challenges to be addressed in order to facilitate developers in the design of such systems. In particular, we investigate to what extent existing methodologies (i) cover GDPR and privacy-by-design principles, (ii) address different levels of system design concerns, and (iii) have demonstrated their suitability for the purpose. Our literature study shows that the domain landscape appears to be heterogeneous and disconnected, as existing methodologies often focus only on subsets of the GDPR principles and/or on specific angles of system design. Based on our findings, we provide recommendations on the definition of comprehensive methodologies tailored to designing GDPR-compliant high-tech systems.

Similar Papers
  • Research Article

The GDPR and Processing of Personal Data for Research Purposes: What About Case Law?

  • Mar 01, 2021
  • European Public Law
  • Jane Reichel
  • Research Article
  • Citations384

EU General Data Protection Regulation: Changes and implications for personal data collecting companies

  • Jun 07, 2017
  • Computer Law & Security Review
  • Christina Tikkinen-Piri +2
  • PDF
  • Research Article
  • Citations20

Big Picture on Privacy Enhancing Technologies in e-Health: A Holistic Personal Privacy Workflow

  • Jul 08, 2020
  • Information
  • Stefan Becher +3
  • Supplementary Content
  • Citations4

Over Troubled Water: E-Health Platforms and the Protection of Personal Data: The Case of Portugal

  • Jan 01, 2017
  • Portuguese Journal of Public Health
  • Maria Eduarda Gonçalves +1
  • Research Article
  • Citations21

Data Protection Directive (EU) 2016/680 for Police and Criminal Justice Authorities

  • Jan 01, 2017
  • SSRN Electronic Journal
  • Juraj Sajfert +1
  • Research Article
  • Citations1

A data privacy approach for cyber-physical systems

  • Sep 01, 2019
  • Cyber Security: A Peer-Reviewed Journal
  • Jan Weldert +2
  • Research Article

Personal Data Protection in Tanzania: Legal Challenges and Enforcement Prospects in the Digital Era

  • Nov 19, 2025
  • East African Journal of Law and Ethics
  • Winifrida M Ernest
  • Research Article
  • Citations15

Consent for targeted advertising: the case of Facebook

  • May 12, 2020
  • AI & SOCIETY
  • Sourya Joyee De +1
  • Book Chapter

The Transformation of the Right to Privacy and the Right to Data Protection

  • Oct 01, 2018
  • Bart Van Der Sloot
  • Research Article
  • Citations15

The significance of general data protection regulation in the compliant data contribution to the European Society of Thoracic Surgeons database.

  • Aug 17, 2023
  • European Journal of Cardio-Thoracic Surgery
  • Luca Bertolaccini +6
  • Research Article
  • Citations1

Implementation of privacy by design model to an eHealth information system

  • Sep 06, 2022
  • Online Journal of Applied Knowledge Management
  • Matjaž Drev +2
  • Research Article
  • Citations20

Financial Intelligence Units: Reflections on the applicable data protection legal framework

  • Oct 06, 2021
  • Computer Law & Security Review
  • Magdalena Brewczyńska
  • Book Chapter
  • Citations1

A critical reflection on the material scope of the application of the Law Enforcement Directive and its boundaries with the General Data Protection Regulation

  • Apr 22, 2022
  • Magdalena Brewczyäñska
  • Conference Article
  • Citations59

Using Models to Enable Compliance Checking Against the GDPR: An Experience Report

  • Sep 01, 2019
  • Damiano Torre +5
  • Conference Article
  • Citations3

With or Without EU: Navigating GDPR Constraints in Human Subjects Research in an Education Environment

  • Jun 08, 2021
  • Alex Duncan +1
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.