Journal article Open Access

DPCat: Specification for an Interoperable and Machine-Readable Data Processing Catalogue based on GDPR

Ryan, Paul; Brennan, Rob; Pandit, Harshvardhan J.

The GDPR requires Data Controllers and Data Protection Officers (DPO) to maintain a
Register of Processing Activities (ROPA) as part of overseeing the organisation’s compliance processes.
The ROPA must include information from heterogeneous sources such as (internal) departments with
varying IT systems and (external) data processors. Current practices use spreadsheets or proprietary
systems that lack machine-readability and interoperability, presenting barriers to automation. We
propose the Data Processing Catalogue (DPCat) for the representation, collection and transfer of
ROPA information, as catalogues in a machine-readable and interoperable manner. DPCat is based
on the Data Catalog Vocabulary (DCAT) and its extension DCAT Application Profile for data portals
in Europe (DCAT-AP), and the Data Privacy Vocabulary (DPV). It represents a comprehensive
semantic model developed from GDPR’s Article and an analysis of the 17 ROPA templates from
EU Data Protection Authorities (DPA). To demonstrate the practicality and feasibility of DPCat,
we present the European Data Protection Supervisor’s (EDPS) ROPA documents using DPCat,
verify them with SHACL to ensure the correctness of information based on legal and contextual
requirements, and produce reports and ROPA documents based on DPA templates using SPARQL.
DPCat supports a data governance process for data processing compliance to harmonise inputs from
heterogeneous sources to produce dynamic documentation that can accommodate differences in
regulatory approaches across DPAs and ease investigative burdens toward efficient enforcement.

DPCat Specification: https://w3id.org/dpcat

Resources: https://w3id.org/dpcat/repo

This research has received funding from Uniphar PLC, and the ADAPT Centre for Digital Content Technology which is funded under the SFI Research Centres Programme (Grant 13/RC/2106_P2) and co-funded by the European Regional Development Fund. Harshvardhan J. Pandit has received funding under the Irish Research Council's Government of Ireland Postdoctoral Fellowship Grant#GOIPD/2020/790.
Files (995.6 kB)
Name Size
information-13-00244.pdf
md5:1407f05b3988f4bb06145f09f524a391
995.6 kB Download
100
74
views
downloads
All versions This version
Views 10029
Downloads 7429
Data volume 74.0 MB28.9 MB
Unique views 9229
Unique downloads 6428

Share

Cite as