%0 Conference Proceedings %T Annotation-Based Static Analysis for Personal Data Protection %+ Geniem %+ University of Turku %A Hjerppe, Kalle %A Ruohonen, Jukka %A Leppänen, Ville %Z Part 7: Privacy Classification and Security Assessment %< avec comité de lecture %( IFIP Advances in Information and Communication Technology %B 14th IFIP International Summer School on Privacy and Identity Management (Privacy and Identity) %C Windisch, Switzerland %Y Michael Friedewald %Y Melek Önen %Y Eva Lievens %Y Stephan Krenn %Y Samuel Fricker %I Springer International Publishing %3 Privacy and Identity Management. Data for Better Living: AI and Privacy %V AICT-576 %P 343-358 %8 2019-08-19 %D 2019 %R 10.1007/978-3-030-42504-3_22 %K Data protection %K Privacy %K Static analysis %K Java %K GDPR %Z Computer Science [cs]Conference papers %X This paper elaborates the use of static source code analysis in the context of data protection. The topic is important for software engineering in order for software developers to improve the protection of personal data during software development. To this end, the paper proposes a design of annotating classes and functions that process personal data. The design serves two primary purposes: on one hand, it provides means for software developers to document their intent; on the other hand, it furnishes tools for automatic detection of potential violations. This dual rationale facilitates compliance with the General Data Protection Regulation (GDPR) and other emerging data protection and privacy regulations. In addition to a brief review of the state-of-the-art of static analysis in the data protection context and the design of the proposed analysis method, a concrete tool is presented to demonstrate a practical implementation for the Java programming language. %G English %Z TC 9 %Z TC 11 %Z WG 9.2 %Z WG 9.6 %Z WG 11.7 %Z WG 11.6 %2 https://inria.hal.science/hal-03378964/document %2 https://inria.hal.science/hal-03378964/file/496005_1_En_22_Chapter.pdf %L hal-03378964 %U https://inria.hal.science/hal-03378964 %~ IFIP %~ IFIP-AICT %~ IFIP-TC %~ IFIP-WG %~ IFIP-TC9 %~ IFIP-TC11 %~ IFIP-WG9-2 %~ IFIP-WG9-6 %~ IFIP-WG11-7 %~ IFIP-WG11-6 %~ IFIP-PRIMELIFE %~ IFIP-AICT-576