The General Data Protection Regulation of the European Union (GDPR) introduced rules regarding privacy policies. These rules made the process of creating compliant privacy policies a complex process. We created the Privacy Policy Compliance Guidance framework (PriPoCoG), that supports all parties involved in creating and handling privacy policies. During policy creation our privacy policy editor gives compliance feedback and guidance to policy authors, ensuring that policies are GDPR-compliant. The framework uses a formal privacy policy language called Prolog-Layered Privacy Language (P-LPL), which also partially formalises the GDPR. The editor can also be used by data protection authorities to check existing P-LPL policies for GDPR-compliance. Privacy Policy Based Access Control (P2BAC) ensures that the data handling described inside the privacy policy is enforced. It ensures that no further processing of data, other than what is described in the policy, is performed by data controllers and data processors. Our privacy policy interface presents privacy policies in a comprehensible way to data subjects. Data subjects can customise the privacy policies and provide partial consent. We provide a management component which ensures that all parties involved in handling a data subject's data act according to the customised privacy policy. The management component updates all parties about any changes in the customised policies using a sticky policy approach. All in all, our framework aims at improving the overall privacy policy landscape.
Jens Ingo Leicht (Wed,) studied this question.