A BERT Based Approach to Measure Web Services Policies Compliance With GDPR

dc.contributor.authorLavanya, Elluri
dc.contributor.authorChukkapalli, Sai Sree Laya
dc.contributor.authorJoshi, Karuna
dc.contributor.authorFinin, Tim
dc.contributor.authorJoshi, Anupam
dc.date.accessioned2021-12-10T17:49:43Z
dc.date.available2021-12-10T17:49:43Z
dc.date.issued2021-10-28
dc.description.abstractData confidentiality is an issue of increasing importance. Several authorities and regulatory bodies are creating new laws that control how web services data is handled and shared. With the rapid increase of such regulations, web service providers face challenges in complying with these evolving regulations across jurisdictions. Providers must update their service policies regularly to address the new regulations. The challenge is that regulatory documents are large text documents and require substantial human effort to comprehend and enforce. On the other hand, web service provider privacy policies are relatively short compared to the regulatory texts, so it is hard to determine if an organization's policy document addresses the regulation's essential elements. We have developed a framework to automatically compare web service policies with regulatory policies to measure how closely the web service provider complies with a regulation. In this paper, we present our framework's details along with the results of analyzing a corpus of 3,000 privacy policies against GDPR. Our framework uses BiLSTM multi-class classification and a BERT extractive summarizer. We evaluate the framework's efficacy by checking the context similarity score between summarized GDPR and web service provider privacy policies.en_US
dc.description.sponsorshipThis work was supported in part by NSF Phase I IndustryUniversity Cooperative Research Centers (IUCRC) UMBC: Center for Accelerated Real-time Analytics (CARTA) under NSF Award 1747724 and an award by IBM Research.en_US
dc.description.urihttps://ieeexplore.ieee.org/document/9592800en_US
dc.format.extent13 pagesen_US
dc.genrejournal articlesen_US
dc.identifierdoi:10.13016/m2jtr8-bpa7
dc.identifier.citationL. Elluri, S. S. L. Chukkapalli, K. P. Joshi, T. Finin and A. Joshi, "A BERT Based Approach to Measure Web Services Policies Compliance With GDPR," in IEEE Access, vol. 9, pp. 148004-148016, 2021, doi: 10.1109/ACCESS.2021.3123950.en_US
dc.identifier.urihttp://hdl.handle.net/11603/23571
dc.identifier.urihttps://doi.org/10.1109/ACCESS.2021.3123950
dc.language.isoen_USen_US
dc.publisherIEEEen_US
dc.relation.isAvailableAtThe University of Maryland, Baltimore County (UMBC)
dc.relation.ispartofUMBC Information Systems Department Collection
dc.relation.ispartofUMBC Computer Science and Electrical Engineering Department
dc.relation.ispartofUMBC Student Collection
dc.relation.ispartofUMBC Faculty Collection
dc.rightsThis item is likely protected under Title 17 of the U.S. Copyright Law. Unless on a Creative Commons license, for uses protected by Copyright Law, contact the copyright holder or the author.en_US
dc.rightsAttribution 4.0 International (CC BY 4.0)
dc.rights.urihttps://creativecommons.org/licenses/by/4.0/
dc.subjectUMBC Ebiquity Research Group
dc.titleA BERT Based Approach to Measure Web Services Policies Compliance With GDPRen_US
dc.typeTexten_US
dcterms.creatorhttps://orcid.org/0000-0002-8881-3369en_US
dcterms.creatorhttps://orcid.org/0000-0002-3663-9231en_US
dcterms.creatorhttps://orcid.org/0000-0002-6354-1686en_US
dcterms.creatorhttps://orcid.org/0000-0002-6593-1792en_US
dcterms.creatorhttps://orcid.org/0000-0002-8641-3193en_US

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
A_BERT_Based_Approach_to_Measure_Web_Services_Policies_Compliance_With_GDPR.pdf
Size:
1.52 MB
Format:
Adobe Portable Document Format
Description:
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
2.56 KB
Format:
Item-specific license agreed upon to submission
Description: