Using enterprise architecture models for creating the record of processing activities (Art. 30 GDPR)

Dominik Huth, Ahmet Tanakol, Florian Matthes

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

11 Scopus citations

Abstract

The record of processing activities (RPA) is a central document in demonstrating compliance with the General Data Protection Regulation (GDPR). Article 30 of the GDPR specifies the information that has to be made available to the supervisory authority upon request. Currently, data protection management experts conduct their own data collection and maintain isolated RPAs. We show how existing Enterprise Architecture models can be augmented with the necessary information to maintain and generate an RPA. We evaluate the completeness and usefulness of the approach together with data protection management experts.

Original languageEnglish
Title of host publicationProceedings - 2019 IEEE 23rd International Enterprise Distributed Object Computing Conference, EDOC 2019
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages98-104
Number of pages7
ISBN (Electronic)9781728127026
DOIs
StatePublished - Oct 2019
Event23rd IEEE International Enterprise Distributed Object Computing Conference, EDOC 2019 - Paris, France
Duration: 28 Oct 201931 Oct 2019

Publication series

NameProceedings - 2019 IEEE 23rd International Enterprise Distributed Object Computing Conference, EDOC 2019

Conference

Conference23rd IEEE International Enterprise Distributed Object Computing Conference, EDOC 2019
Country/TerritoryFrance
CityParis
Period28/10/1931/10/19

Keywords

  • ArchiMate
  • Data protection
  • Enterprise Architecture Management
  • GDPR
  • RPA
  • Record of processing activities

Fingerprint

Dive into the research topics of 'Using enterprise architecture models for creating the record of processing activities (Art. 30 GDPR)'. Together they form a unique fingerprint.

Cite this