Self-adaptive systems play an important role in dynamic software environments because they can independently adjust their functionality and structure to changing operating conditions and requirements. However, when these systems process personal data, this capability can lead to data protection problems — specifically whenever the way the data is processed also changes, e.g., with regard to the purpose of processing or the associated risk. Consent previously obtained may then no longer cover this new situation, potentially resulting in a violation of the General Data Protection Regulation (GDPR).
In his dissertation "Preventing consent violations due to self-adaptation at runtime", Paul developed a model-based approach that checks planned self-adaptations before they are executed – so that violations are prevented from occurring in the first place, rather than being detected only after the fact. To this end, the expected effects of a planned adaptation are modeled in instance models of the system and analyzed from two perspectives: 1) changes in processing purposes, and 2) increased security risks.
Paul implemented his approach in a prototype and evaluated it experimentally using a generated dataset of systems and adaptation scenarios. The results show that adaptations violating existing consent can be detected before they are executed. Paul's approach thus provides an important contribution for data protection-compliant, self-adaptive systems.
We warmly congratulate Dr. Paul-Andrei Dragan on his outstanding achievement and wish him all the best for his future!