Modern software has been an integral part of everyday activities in many disciplines and application contexts. Introducing intelligent automation by leveraging artificial intelligence (AI) led to break-throughs in many fields. The effectiveness of AI can be attributed to several factors, among which is the increasing availability of data. Regulations such as the general data protection regulation (GDPR) in the European Union (EU) are introduced to ensure the protection of personal data. Software systems that collect, process, or share personal data are subject to compliance with such regulations. Developing compliant software depends heavily on addressing legal requirements stipulated in applicable regulations, a central activity in the requirements engineering (RE) phase of the software development process. RE is concerned with specifying and maintaining requirements of a system-to-be, including legal requirements. Legal agreements which describe the policies organizations implement for processing personal data can provide an additional source to regulations for eliciting legal requirements. In this chapter, we explore a variety of methods for analyzing legal requirements and exemplify them on GDPR. Specifically, we describe possible alternatives for creating machine-analyzable representations from regulations, survey the existing automated means for enabling compliance verification against regulations, and further reflect on the current challenges of legal requirements analysis.
翻译:现代软件已成为众多学科和应用场景日常活动中不可或缺的组成部分。通过引入人工智能实现智能自动化,已在多个领域取得突破性进展。人工智能的有效性可归因于多项因素,其中数据的日益可得性尤为关键。欧盟《通用数据保护条例》等法规的出台,旨在保障个人数据安全。凡是收集、处理或共享个人数据的软件系统,均须遵循此类法规。开发合规软件的关键在于落实适用法规中的法律要求,这已成为软件开发过程中需求工程阶段的核心活动。需求工程关注待建系统的需求(含法律需求)的明确与维护。描述组织机构处理个人数据政策的法律协议,可作为法律需求获取的法规补充来源。本章从GDPR切入,探究多种法律需求分析方法:具体包括构建法规机器可解析表征的多种方案,梳理支持法规合规性验证的自动化方法,并深入剖析当前法律需求分析面临的挑战。