@article{LAMARI2026108065,
title = {Assisting the early development stages of privacy-aware software: The PRIAM tooled metamodel for GDPR},
journal = {Information and Software Technology},
volume = {194},
pages = {108065},
year = {2026},
issn = {0950-5849},
doi = {https://doi.org/10.1016/j.infsof.2026.108065},
url = {https://www.sciencedirect.com/science/article/pii/S0950584926000546},
author = {Selena Lamari and Nadjia Benblidia and Chouki Tibermacine and Christelle Urtado and Sylvain Vauttier},
keywords = {GDPR, Privacy rights, Personal data protection, Privacy-aware software, Model driven engineering, Metamodel, Domain-Specific Language, User stories},
abstract = {Context:
As software systems are more tailored to users, personal data is collected and exploited more than ever before. This situation raises the issue of user privacy protection. Conforming to personal data protection regulations, such as the European General Data Protection Regulation (GDPR), has thus become a legal obligation for application providers. However, there are no widely adopted proposals to formalize, implement, and assess compliance with the personal data privacy protection required by GDPR.
Objective:
In order to help application developers in the early stages of the development process, our overarching objective is to propose a tooled software engineering approach to integrate personal data protection capabilities, thus contributing to the development-by-design of privacy-aware software aligned with GDPR requirements.
Method:
We developed a method called PRIAM (PRIvacy Assessment Method) that goes beyond a conceptual description of the regulation by incorporating concrete, actionable software artifacts. This article presents the cornerstone of this method – PRIAM metamodel – along with its companion artifacts.
Results:
PRIAM metamodel captures the main concepts of GDPR and is then supported by a domain-specific language, user stories, and a dedicated database schema. The comprehensiveness and relevance of PRIAM metamodel have been qualitatively evaluated by GDPR experts through a questionnaire. Complementarily, an AI-based evaluation has been conducted, using some Large Language Models (LLMs), opening perspectives for fast, iterative evaluations of metamodels that formalize regulation texts. Besides, the practicality and usefulness of PRIAM metamodel and all its companion artifacts are highlighted through the running example of a Sport center management application, where privacy enforcement features, tailored to the specific personal data of the application, are generated and integrated.
Conclusion:
These two elements assert the viability of our proposal as a practical solution for assisting the development of privacy-aware applications that are compliant with GDPR requirements, thanks to customizable sets of actual development artifacts, systematically derived from a validated comprehensive formalization of the regulation articles.}
}