Score
Designs, implements, and evaluates policies, controls, and governance structures to protect personal and sensitive data across its lifecycle, including data retention schedules, placement and handling controls, and data access policies. Produces and assesses data protection impact assessments and builds or adapts data governance frameworks and practices to ensure compliance with applicable data protection law and organizational requirements.
This work addresses the limitations of existing data governance tools, which struggle to dynamically adapt to emerging regulations such as India’s Digital Personal Data Protection (DPDP) Act and often lack transparency and explainability, leading to inadequate compliance. To bridge this gap, the paper introduces the first goal-driven agent framework specifically designed for data compliance. The framework integrates a KYU Agent and a Compliance Agent that jointly leverage semantic understanding, user trust modeling, and data sensitivity reasoning, embedding regulatory logic directly into the system to ensure auditable and interpretable decisions. It incorporates anonymization strategies—including masking, pseudonymization, and generalization—and demonstrates significant improvements in DPDP compliance across ten domains, including healthcare, education, and e-commerce, enabling transparent, efficient, and cross-domain adaptive data governance.
This paper addresses unique data governance challenges arising from artificial general intelligence (AGI) systems endowed with recursive self-improvement and self-replication capabilities. It identifies seven urgent, AGI-specific risks surpassing those of conventional AI: autonomous data acquisition bypassing informed consent; data retention decisions driven by optimization objectives rather than human values; supranational, unregulated data sharing among decentralized AGI agents; erosion of data provenance due to dynamic system evolution; ambiguous ownership of AI-generated content; diminished regulatory enforcement across jurisdictions; and rapid obsolescence of static governance frameworks. Employing conceptual analysis and systematic reasoning, the study integrates theories of recursive self-improvement, data provenance, and cross-border regulatory compliance to construct a risk identification and response framework. Its key contribution is a novel tripartite governance paradigm—“embedded safety constraints, real-time adaptive monitoring, and multilateral co-evolution”—advancing data governance from static rule-based models toward continuous, adaptive evolution, thereby offering theoretical foundations and actionable pathways for global AGI policy development.
This study investigates how data protection regulations (e.g., GDPR, CCPA) impact open-source software (OSS) development practices, focusing on the reporting, discussion, and resolution of personal-data-related issues in GitHub projects. Using an exploratory empirical approach—combining inductive thematic coding, annotating reporter roles and issue states, and conducting relevance-based statistical analysis—the authors systematically identify six recurrent categories of data protection issues. Results show that such issues are predominantly reported by non-core contributors; resolution rates are low and rely heavily on non-technical negotiation rather than code-level fixes; and a structural tension exists between regulatory compliance requirements and OSS development culture. This work is the first to empirically demonstrate how data protection obligations are substantively embedded within OSS development workflows, thereby bridging regulatory compliance and OSS engineering practice. It provides foundational evidence and design insights for developing compliance-aware open-source governance mechanisms.
This study examines Bangladesh’s 2025 data protection legislation, arguing that its three newly enacted laws fail to effectively safeguard citizens’ data due to a fundamental misalignment between institutional design and the country’s sociotechnical realities. Through systematic legal text analysis and institutional critique, complemented by a human-computer interaction (HCI) lens, the paper reconceptualizes data protection as a sociotechnical challenge shaped by informal infrastructures prevalent in the global South—thereby challenging dominant, individual-centric legal paradigms. The research identifies critical constraints in Bangladesh’s data governance framework, including insufficient regulatory independence, uneven enforcement capacity, and a systemic neglect of informal data flows. These factors collectively undermine the implementation of formal mechanisms, offering a critical theoretical framework and practical insights for data governance in other global South contexts.
Existing Web data storage platforms struggle to meet the demands of decentralized, semantically rich, and legally compliant data usage control. This work proposes a novel approach that integrates the User-Managed Access (UMA) authorization framework with the W3C Open Digital Rights Language (ODRL) policy language to replace Solid’s native access control mechanism, thereby decoupling authorization from storage. For the first time within the Solid ecosystem, this integration advances access control from mere permission management toward legally aware usage control. The authors also design a policy evaluation mechanism tailored for non-standardized semantic environments. A prototype implementation demonstrates that the proposed method maintains compatibility with Solid while enabling flexible, interoperable, and legally aligned data governance.
This study addresses the challenges posed by divergent and conflicting data protection regulations across jurisdictions, which hinder the early identification of compliance requirements in software development and often lead to costly rework and legal risks. Drawing on interviews with 70 legal experts from G20 and other countries, the research employs systematic content analysis and deductive qualitative methods to distill, for the first time from a legal expert perspective, both commonalities—such as consent—and key divergences—such as the right to be forgotten—across global data protection laws. These insights are innovatively operationalized into a comprehensive set of Data Protection Officer (DPO) user stories mapped to each phase of the software development lifecycle and enterprise architecture layers, significantly enhancing the actionable integration of compliance requirements into early-stage software engineering practices.
Traditional enterprise security models, reliant on static perimeters, struggle to address the dynamic risks introduced by production-grade AI agents operating within authorized workflows. This work proposes the first five-plane reference architecture for runtime governance of AI agents—spanning inference, network, identity, endpoint, and data—and introduces core primitives including arbitrary-point interception, composite subjects with capability decay, and structured audit evidence. By extending policy enforcement from atomic subjects to decay-aware composite subjects, the framework defines six interruption primitives and four correctness invariants. Evaluated across five real-world workflows, it successfully mitigates seven threat classes, achieves microsecond-scale policy decisions, and validates correctness of capability decay, audit reconstructability, and tamper resistance, thereby filling a critical gap in dynamic governance for agent-driven workflows.
This study addresses the ambiguity in defining privacy-related professional roles and the unclear cross-disciplinary competency requirements in the AI era. By applying rule-based text mining and BERTopic modeling to job posting data from LinkedIn and Indeed in the United States, we systematically analyze the evolving landscape of privacy positions. The analysis identifies 18 latent topics, revealing that AI governance responsibilities are becoming deeply embedded within existing privacy roles, thereby catalyzing hybrid positions that demand both compliance expertise and technical proficiency. Results indicate that over half of the postings require AI-related skills, with privacy roles increasingly integrating multidimensional competencies spanning legal, technical, and managerial domains. This work provides empirical evidence for understanding the AI-driven evolution of privacy professions.
This study addresses the prevailing overemphasis on legal compliance in student data governance within learning analytics, which often neglects critical ethical dimensions such as fairness, student autonomy, accountability, and educational purpose. To bridge this gap, the work proposes LEAGUE—a six-pillar ethical governance framework encompassing Legitimacy, Equity, Autonomy, Governance, Utility, and Ethics-by-Design—integrating insights from learning analytics, data ethics, and capability-oriented theories of educational justice. Moving beyond conventional compliance paradigms, this framework pioneers the application of value-sensitive design in the field. Through conceptual review, interdisciplinary theoretical synthesis, and a case analysis of an early warning system, the study demonstrates the framework’s feasibility in enhancing transparency, educational meaningfulness, and ethical justifiability, offering a theoretically grounded yet practically actionable pathway for ethically robust learning analytics.
This study addresses the absence of governance frameworks for digital legacies after a user’s death and the coordination difficulties faced by bereaved survivors. Through a multidimensional content analysis of 800 Reddit posts, it investigates sociotechnical collaboration and conflict surrounding post-mortem digital privacy and security. The findings reveal the critical role of devices as access gateways and identify data loss as a primary harm. Building on these insights, the authors construct a post-mortem digital governance framework organized along dimensions such as assets and actors. This framework establishes a foundation for mechanism design to support survivor coordination, thereby bridging significant theoretical and practical gaps in the field of digital legacy governance.