Master'sOpen Access

Assessment of general data protection regulation in the context of smart city solutions

2021
0 views
0 downloads
Advisor: Dr. Öğr. Üyesi Muhammed Abdullah Bülbül

Abstract (EN)

After the European Union's new General Data Protection Regulation (GDPR) became applicable in May 2018, concerns related to the legal compliance of several technologies including IoT devices, blockchain systems, or smart city applications have emerged considering the individual rights guaranteed by GDPR. This study aims to reveal the implications of GDPR on smart city applications. Smart city applications convert data coming from many interconnected devices to meaningful information and use them to raise the standards of daily life. To better understand how the smart city sector sees the challenges posed by GDPR, and how they address them, this study analyses privacy policies of smart city applications which are legal documents that explain what data is collected from users and how they are processed. These analyzes were made by taking into account nine main elements extracted from the GDPR, which may be important in the context of the smart city. These main topics are; Explicit Consent, Right to Withdraw Consent, Right to Erasure, Right to Data Portability, Right of Access, Storage Limitation, Transparency, Transfer of Data, Data Minimisation. According to these GDPR elements, personal data cannot be processed without the explicit consent of the user, users have the right to access the data at any time, to make copies of the data, to delete the data, and to withdraw their consent at any time. In this study, privacy policies of 68 applications are collected, web page-specific policies are eliminated, and 42 privacy policies are analyzed. Furthermore, this study contains results of the study aiming at automating the evaluation of GDPR compliance of privacy policies via information retrieval techniques. For this purpose, 70% of the privacy policies collected are used as a training set and 30% are used in the test set. During the training phase, the keywords, determined by running Tf-Idf over the selected privacy policies, are given as input to the system for the next test phase. The Okapi BM25 method calculated a score on sentences for each set of keywords, taking into account the given keywords. Considering the scores, the most appropriate sentences for each GDPR element were automatically calculated. Then, the system was evaluated based on the results obtained. In addition, this method has been compared with fastText, which is one of the text classification methods, and the results are shared.

Author

Dr. Şeyma Nur Tunç

How to Cite

Şeyma Nur Tunç (Master Thesis). Assessment of general data protection regulation in the context of smart city solutions, 2021, Ankara Yıldırım Beyazıt University.

Keywords

License

Tüm Hakları Saklıdır

This work is shared under the specified license terms.

More theses from Ankara Yıldırım Beyazıt University