PAM: a domain-specific language for specifying privacy requirements from regulation to runtime

Abstract Privacy regulations such as the General Data Protection Regulation (GDPR) require organizations to specify what personal data they collect, for which purpose, how long they retain it, and under what consent conditions—yet practitioners struggle to translate these legal requirements into specifications that can be validated and enforced. We present Privacy Attribute Matrix (PAM), a domain-specific language that bridges this gap. PAM provides four constructs, derived directly from GDPR articles, for specifying personally identifiable information (PII) fields with sensitivity classifications, processing purposes with legal bases, retention policies with deletion strategies, and consent requirements with expiration semantics. Its scope is deliberately bounded to the technical data-handling obligations GDPR imposes—which data, for which purpose, for how long, under what consent—rather than organizational duties such as staff training or breach notification. Unlike annotation-based approaches that document but cannot enforce, PAM specifications are executable: the runtime validates data access against declared policies, detects violations, and applies configurable erasure strategies (hard deletion, anonymization). We evaluate PAM through a case study on a university payment system, replicated on the open-source Solidus e-commerce platform. The , , and constructs are exercised directly by the production system, whose legal basis is contract and legal obligation rather than consent; the construct is validated end-to-end through an extension that adds an optional consent-gated purpose. PAM expressed 90% of the Information Commissioner’s Office (ICO) GDPR technical checklist requirements for the evaluated system in about 70 lines of specification. The work advances requirements engineering by showing how regulatory requirements can be specified in a DSL that is both human-readable for compliance auditors and machine-enforceable at runtime.

Authors

Publication Details

Journal
Requirements Engineering
Published
2026-10-06
DOI
https://doi.org/10.1007/s00766-026-00469-6
Primary Topic
Model-Driven Software Engineering Techniques
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
article

PAM: a domain-specific language for specifying privacy requirements from regulation to runtime

Christos Kalloniatis, Michail Pantelelis
Requirements Engineering
Model-Driven Software Engineering Techniques
article

PAM: a domain-specific language for specifying privacy requirements from regulation to runtime

Christos Kalloniatis, Michail Pantelelis
article en

Abstract

Abstract Privacy regulations such as the General Data Protection Regulation (GDPR) require organizations to specify what personal data they collect, for which purpose, how long they retain it, and under what consent conditions—yet practitioners struggle to translate these legal requirements into specifications that can be validated and enforced. We present Privacy Attribute Matrix (PAM), a domain-specific language that bridges this gap. PAM provides four constructs, derived directly from GDPR articles, for specifying personally identifiable information (PII) fields with sensitivity classifications, processing purposes with legal bases, retention policies with deletion strategies, and consent requirements with expiration semantics. Its scope is deliberately bounded to the technical data-handling obligations GDPR imposes—which data, for which purpose, for how long, under what consent—rather than organizational duties such as staff training or breach notification. Unlike annotation-based approaches that document but cannot enforce, PAM specifications are executable: the runtime validates data access against declared policies, detects violations, and applies configurable erasure strategies (hard deletion, anonymization). We evaluate PAM through a case study on a university payment system, replicated on the open-source Solidus e-commerce platform. The , , and constructs are exercised directly by the production system, whose legal basis is contract and legal obligation rather than consent; the construct is validated end-to-end through an extension that adds an optional consent-gated purpose. PAM expressed 90% of the Information Commissioner’s Office (ICO) GDPR technical checklist requirements for the evaluated system in about 70 lines of specification. The work advances requirements engineering by showing how regulatory requirements can be specified in a DSL that is both human-readable for compliance auditors and machine-enforceable at runtime.

Requirements EngineeringVol. 31(2)
Openalex Percentile: Top 3%
Model-Driven Software Engineering Techniques
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

PAM: a domain-specific language for specifying privacy requirements from regulation to runtime — Christos Kalloniatis, Michail Pantelelis · Requirements Engineering (2026) | TGRS Research Map | TGRS