Score
Designs, implements, and evaluates systems, processes, and policies that prevent unauthorized access, disclosure, or misuse of data and that control how data is collected, stored, shared, and deleted. Builds and analyzes technical and organizational controls—such as access control, encryption, anonymization and de-identification, auditing and logging, consent mechanisms, and privacy-preserving algorithms—and assesses privacy risk, privacy–utility trade-offs, and compliance with relevant legal or regulatory requirements.
This study addresses the escalating threat of unauthorized data access confronting enterprises and proposes an integrated defense framework that synergistically combines technological, human, and organizational dimensions. The framework establishes a robust security foundation through technical measures such as firewalls, intrusion detection systems, and encryption, while simultaneously reinforcing this infrastructure with employee security awareness training and rigorous enforcement of data access policies. By integrating these layers into a cohesive, defense-in-depth architecture, the approach not only substantially mitigates the risk of data breaches but also enhances organizational compliance and overall cyber resilience. This work thus offers a practical, holistic solution for effective data governance in complex enterprise environments.
Users widely perceive a loss of data control, stemming from existing privacy mechanisms that conflate two distinct types of control: interpersonal privacy (e.g., social sharing settings) and user-institutional privacy (e.g., platform-level data processing rights). This paper introduces and rigorously substantiates the “dichotomy of control objects,” arguing that current privacy design overemphasizes the former while systematically neglecting the latter. Through an interdisciplinary investigation—including controlled human-computer interaction experiments, comparative analysis of privacy policy texts, and critical information ethics inquiry—the study exposes the structural inadequacies of prevailing “one-size-fits-all” privacy interfaces. Findings inform the redesign of privacy interfaces, strengthen regulatory enforcement (e.g., GDPR compliance), and advance institutional innovations such as data trusts. Collectively, this work shifts the paradigm from procedural consent toward substantive user empowerment in data governance.
This study addresses the core challenge of balancing regulatory compliance—specifically with LGPD and GDPR—with data utility in privacy-preserving data anonymization. We systematically evaluate the privacy protection strength and utility loss of mainstream techniques—including aggregation, generalization, perturbation, and k-anonymity—on real-world sensitive datasets. Through quantitative comparative experiments, we characterize their distinct trade-offs along the privacy–utility spectrum and propose a context-aware technical selection framework guided by application-specific features (e.g., data dimensionality, analytical task type, and regulatory emphasis). Our key contributions are threefold: (1) the first unified empirical validation of the interplay between multi-regulatory compliance and utility preservation; (2) identification of mechanistic links between anonymization method choice and cross-jurisdictional compliance feasibility; and (3) a practical, evidence-based decision guide for privacy engineers to select optimal anonymization strategies under legal and operational constraints. (149 words)
This study investigates how data protection regulations (e.g., GDPR, CCPA) impact open-source software (OSS) development practices, focusing on the reporting, discussion, and resolution of personal-data-related issues in GitHub projects. Using an exploratory empirical approach—combining inductive thematic coding, annotating reporter roles and issue states, and conducting relevance-based statistical analysis—the authors systematically identify six recurrent categories of data protection issues. Results show that such issues are predominantly reported by non-core contributors; resolution rates are low and rely heavily on non-technical negotiation rather than code-level fixes; and a structural tension exists between regulatory compliance requirements and OSS development culture. This work is the first to empirically demonstrate how data protection obligations are substantively embedded within OSS development workflows, thereby bridging regulatory compliance and OSS engineering practice. It provides foundational evidence and design insights for developing compliance-aware open-source governance mechanisms.
In enterprise databases, access control policy specification and enforcement are often decoupled, leading to cumbersome, non-systematic manual auditing. To address this, we propose Intent-Based Access Control for Databases (IBAC-DB), a novel model supporting semantic policy modeling and bidirectional traceability between policies and their implementations. We introduce IBACBench—the first benchmark tailored for database access control—and DePLOI, an LLM-based system featuring a task-decomposition paradigm for NL2SQL translation. DePLOI integrates domain-customized NL2SQL, role-hierarchy-aware modeling, and hybrid synthetic data generation for evaluation. Experiments on IBACBench demonstrate that DePLOI achieves significantly higher synthesis accuracy and auditing F1-score (+10 F1) than state-of-the-art baselines, validating the feasibility and robustness of automating secure access control policy deployment.
This study addresses the challenges posed by divergent and conflicting data protection regulations across jurisdictions, which hinder the early identification of compliance requirements in software development and often lead to costly rework and legal risks. Drawing on interviews with 70 legal experts from G20 and other countries, the research employs systematic content analysis and deductive qualitative methods to distill, for the first time from a legal expert perspective, both commonalities—such as consent—and key divergences—such as the right to be forgotten—across global data protection laws. These insights are innovatively operationalized into a comprehensive set of Data Protection Officer (DPO) user stories mapped to each phase of the software development lifecycle and enterprise architecture layers, significantly enhancing the actionable integration of compliance requirements into early-stage software engineering practices.
This work addresses the challenge of efficiently verifying whether corporate privacy policies comply with data protection laws. It proposes APLiance, a novel framework that formalizes legal compliance as an attribute-based access control (ABAC) authorization decision: by semantically mapping privacy policy clauses into implicit access requests and checking whether they are permitted under an ABAC policy modeled from legal provisions. Integrating natural language processing with access control mechanisms, the approach enables automated compliance verification. Empirical evaluation in the context of India’s Digital Personal Data Protection Act demonstrates its effectiveness, and the authors release an open-source browser extension that allows users to assess the legal compliance of website privacy policies in real time.
This study addresses the long-standing lack of a unified software engineering perspective on privacy documents throughout their lifecycle, which has led to fragmented approaches in generation, analysis, compliance verification, and usability evaluation. Through a systematic literature review (SoK) of 290 studies published between 2010 and 2025, this work proposes the first comprehensive lifecycle framework encompassing definition, generation, analysis, compliance validation, and usability assessment. The research identifies 15 key trends, 21 open challenges, and four major future directions, with particular emphasis on leveraging large language models for analyzing consistency between privacy policies and code implementations. By establishing a structured knowledge base and introducing a novel paradigm that balances usability for both end users and developers, this work lays a shared foundation for privacy documentation research in the AI era.
This study addresses the challenges of assessing compliance between organizational cybersecurity policies and abstract security control frameworks such as NIST SP 800-53, which are often time-consuming, difficult to standardize, and lack traceability. To overcome these limitations, the authors propose PROPAGATE, a novel framework that leverages large language models (LLMs) to automate control-level compliance evaluation for the first time. By integrating both open-source and closed-source LLMs, the framework automatically retrieves relevant policy text, evaluates coverage across 1,007 security controls, and generates interpretable gap analyses with actionable improvement recommendations. Experimental results on two real-world organizational policy corpora demonstrate high effectiveness, achieving F1 scores of 88.54 and 82.31, respectively, thereby enabling traceable and explainable compliance enhancement.