OntoROPA Deliverable 2. Proposed Design Specification and Approach.

OntoROPA deals with the automated creation and maintenance of a critical piece of legal compliance required by the GDPR—the Records of Processing Activities (ROPA). It includes the design of a knowledge graph—an RDF graph—tohandleinformationaboutROPAs,combining alegalprofessional ontology (which wil...

Descripción completa

Detalles Bibliográficos
Autores: Martínez González, María Mercedes, Alvite Díez, María Luisa, Casanovas, Pompeu, Casellas, Nuria, Sanz, David, Aparicio De La Fuente, Amador, Gutiérrez, Inma
Tipo de recurso: informe técnico
Estado:Versión publicada
Fecha de publicación:2021
País:España
Institución:Universidad de Valladolid
Repositorio:UVaDOC. Repositorio Documental de la Universidad de Valladolid
OAI Identifier:oai:uvadoc.uva.es:10324/47864
Acceso en línea:https://uvadoc.uva.es/handle/10324/47864
Access Level:acceso abierto
Palabra clave:Semantic Web
Blockchain
Privacy
Legal compliance
Smart Legal Compliance
id ES_1807ea019cf0a23de60f7e773bd2a542
oai_identifier_str oai:uvadoc.uva.es:10324/47864
network_acronym_str ES
network_name_str España
repository_id_str
dc.title.none.fl_str_mv OntoROPA Deliverable 2. Proposed Design Specification and Approach.
title OntoROPA Deliverable 2. Proposed Design Specification and Approach.
spellingShingle OntoROPA Deliverable 2. Proposed Design Specification and Approach.
Martínez González, María Mercedes
Semantic Web
Blockchain
Privacy
Legal compliance
Smart Legal Compliance
title_short OntoROPA Deliverable 2. Proposed Design Specification and Approach.
title_full OntoROPA Deliverable 2. Proposed Design Specification and Approach.
title_fullStr OntoROPA Deliverable 2. Proposed Design Specification and Approach.
title_full_unstemmed OntoROPA Deliverable 2. Proposed Design Specification and Approach.
title_sort OntoROPA Deliverable 2. Proposed Design Specification and Approach.
dc.creator.none.fl_str_mv Martínez González, María Mercedes
Alvite Díez, María Luisa
Casanovas, Pompeu
Casellas, Nuria
Sanz, David
Aparicio De La Fuente, Amador
Gutiérrez, Inma
author Martínez González, María Mercedes
author_facet Martínez González, María Mercedes
Alvite Díez, María Luisa
Casanovas, Pompeu
Casellas, Nuria
Sanz, David
Aparicio De La Fuente, Amador
Gutiérrez, Inma
author_role author
author2 Alvite Díez, María Luisa
Casanovas, Pompeu
Casellas, Nuria
Sanz, David
Aparicio De La Fuente, Amador
Gutiérrez, Inma
author2_role author
author
author
author
author
author
dc.contributor.none.fl_str_mv Universidad de Valladolid
Universidad de León
Universidad Autónoma de Barcelona
dc.subject.none.fl_str_mv Semantic Web
Blockchain
Privacy
Legal compliance
Smart Legal Compliance
topic Semantic Web
Blockchain
Privacy
Legal compliance
Smart Legal Compliance
description OntoROPA deals with the automated creation and maintenance of a critical piece of legal compliance required by the GDPR—the Records of Processing Activities (ROPA). It includes the design of a knowledge graph—an RDF graph—tohandleinformationaboutROPAs,combining alegalprofessional ontology (which will be a part of this graph) with the collection and management of the specific knowledge of the community of privacy and data protection experts. The OntoROPA architecture is law and data driven. ROPAs are deemed to be the critical piece of legal compliance from a social perspective: they are the only available source of information, accessible to non- technical people (including citizens, judges, rulers, law experts, data protection users, and supervisors). Thus, this fact makes them a critical piece for GDPR legal compliance for all stakeholders—providers, controllers, supervisors, and companies. This is a market niche. Deliverable 2, OntoROPA proposed design specification and approach, is focused on a modular, distributed, and ontological approach for the design of both layers—software and data—where each module is the answer to a legal requirement. Data comply with standards for the aim of interoperability, and the design of both layers are subjected to a legal governance scheme, specifically set to harmonize an innovative design for the marketplace with the law, policy, and ethics framework. On top of that, Deliverable 2 explores the possibilities that blockchain technology offers: the use of TEE for secure processing, the use of verifiable credentials with standard certificates for identity management, and the use of oracles for accessing external services. In Deliverable 2, Section 1 introduces the main contents. Section 2 presents a solution with two main components: (1) An OWL ontology that collects the expert knowledge from the target domain (ROPA community) for supporting validation and trustworthiness; (2) and the software artifacts that process ROPAs. This section (i) introduces OntoROPA modules—identity, linked RDF ROPAs, validation, certification, proactiveness—,(ii) offers a detailed design specification (ontology and software requirements, methodology, OntoROPA flowchart) (iii) and describes the interfaces for coordination with ONTOCHAIN blocks. Section 3 deals with the impacts. It includes the business model to get into the market as a new Law-Tech Web Service. It describes its main features, the OntoROPA contribution to bridging web semantics and blockchain technologies, and it defines the creation of ONTOCHAIN legal value. Legal knowledge (legal justification) is also required by the Spanish legislation for ROPAs. OntoROPA legal governance system, the 2 middle-out and inside-out approaches aligned with EU strategies and policies, and the generation of the OntoROPA regulatory legal ecosystem, are explained in detail, including the compatibility between blockchain solutions and GDPR requirements. Section 4 copes with the implementation process, comprising ontology modularity, software modularity, and real time performance of the solution (Ontology and Software KPIs, experimental evaluation, and interoperability aspects, followed by a granular implementation plan). This is heading to an OntoROPA standardisation process. Finally, Section 5, highlights in the Conclusion some results and what is next.
publishDate 2021
dc.date.none.fl_str_mv 2021
dc.type.none.fl_str_mv info:eu-repo/semantics/report
info:eu-repo/semantics/publishedVersion
format report
status_str publishedVersion
dc.identifier.none.fl_str_mv https://uvadoc.uva.es/handle/10324/47864
url https://uvadoc.uva.es/handle/10324/47864
dc.language.none.fl_str_mv Inglés
language_invalid_str_mv Inglés
dc.relation.none.fl_str_mv info:eu-repo/grantAgreement/EC/H2020/957338
dc.rights.none.fl_str_mv info:eu-repo/semantics/openAccess
eu_rights_str_mv openAccess
dc.format.none.fl_str_mv application/pdf
dc.source.none.fl_str_mv reponame:UVaDOC. Repositorio Documental de la Universidad de Valladolid
instname:Universidad de Valladolid
instname_str Universidad de Valladolid
reponame_str UVaDOC. Repositorio Documental de la Universidad de Valladolid
collection UVaDOC. Repositorio Documental de la Universidad de Valladolid
repository.name.fl_str_mv
repository.mail.fl_str_mv
_version_ 1869403958192111616
spelling OntoROPA Deliverable 2. Proposed Design Specification and Approach.Martínez González, María MercedesAlvite Díez, María LuisaCasanovas, PompeuCasellas, NuriaSanz, DavidAparicio De La Fuente, AmadorGutiérrez, InmaSemantic WebBlockchainPrivacyLegal complianceSmart Legal ComplianceOntoROPA deals with the automated creation and maintenance of a critical piece of legal compliance required by the GDPR—the Records of Processing Activities (ROPA). It includes the design of a knowledge graph—an RDF graph—tohandleinformationaboutROPAs,combining alegalprofessional ontology (which will be a part of this graph) with the collection and management of the specific knowledge of the community of privacy and data protection experts. The OntoROPA architecture is law and data driven. ROPAs are deemed to be the critical piece of legal compliance from a social perspective: they are the only available source of information, accessible to non- technical people (including citizens, judges, rulers, law experts, data protection users, and supervisors). Thus, this fact makes them a critical piece for GDPR legal compliance for all stakeholders—providers, controllers, supervisors, and companies. This is a market niche. Deliverable 2, OntoROPA proposed design specification and approach, is focused on a modular, distributed, and ontological approach for the design of both layers—software and data—where each module is the answer to a legal requirement. Data comply with standards for the aim of interoperability, and the design of both layers are subjected to a legal governance scheme, specifically set to harmonize an innovative design for the marketplace with the law, policy, and ethics framework. On top of that, Deliverable 2 explores the possibilities that blockchain technology offers: the use of TEE for secure processing, the use of verifiable credentials with standard certificates for identity management, and the use of oracles for accessing external services. In Deliverable 2, Section 1 introduces the main contents. Section 2 presents a solution with two main components: (1) An OWL ontology that collects the expert knowledge from the target domain (ROPA community) for supporting validation and trustworthiness; (2) and the software artifacts that process ROPAs. This section (i) introduces OntoROPA modules—identity, linked RDF ROPAs, validation, certification, proactiveness—,(ii) offers a detailed design specification (ontology and software requirements, methodology, OntoROPA flowchart) (iii) and describes the interfaces for coordination with ONTOCHAIN blocks. Section 3 deals with the impacts. It includes the business model to get into the market as a new Law-Tech Web Service. It describes its main features, the OntoROPA contribution to bridging web semantics and blockchain technologies, and it defines the creation of ONTOCHAIN legal value. Legal knowledge (legal justification) is also required by the Spanish legislation for ROPAs. OntoROPA legal governance system, the 2 middle-out and inside-out approaches aligned with EU strategies and policies, and the generation of the OntoROPA regulatory legal ecosystem, are explained in detail, including the compatibility between blockchain solutions and GDPR requirements. Section 4 copes with the implementation process, comprising ontology modularity, software modularity, and real time performance of the solution (Ontology and Software KPIs, experimental evaluation, and interoperability aspects, followed by a granular implementation plan). This is heading to an OntoROPA standardisation process. Finally, Section 5, highlights in the Conclusion some results and what is next.Este trabajo forma parte del proyecto de investigación: NGI ONTOCHAIN. Grant Agreement No.: 957338. Call: H2020-ICT-2020-1. Topic: ICT-54-2020. Type of action: RIA.Universidad de ValladolidUniversidad de LeónUniversidad Autónoma de Barcelona2021info:eu-repo/semantics/reportinfo:eu-repo/semantics/publishedVersionapplication/pdfhttps://uvadoc.uva.es/handle/10324/47864reponame:UVaDOC. Repositorio Documental de la Universidad de Valladolidinstname:Universidad de ValladolidInglésinfo:eu-repo/grantAgreement/EC/H2020/957338info:eu-repo/semantics/openAccessoai:uvadoc.uva.es:10324/478642026-06-13T12:44:47Z
score 15,301603