Advanced search
2 files | 1.70 MB Add to list

Factors related to GDPR compliance promises in privacy policies : a machine learning and NLP approach

Author
Organization
Abstract
This paper employs Machine Learning (ML) and Natural Language Processing (NLP) techniques to examine the relationship between organizational factors, such as company size and headquarters location, of data processing entities and their GDPR compliance promises as disclosed in privacy policies. Our methodology comprises three main stages, each representing a key contribution. Firstly, we developed five NLP-based classification models with precision scores of at least 0.908 to assess different GDPR compliance promises in privacy policies. Secondly, we have collected a data set of 8,614 organizations in the European Union containing organizational information and the GDPR compliance promises derived from the organization’s privacy policy. Lastly, we have analyzed the organizational factors correlating to these GDPR compliance promises. The findings reveal, among other things, that small or medium-sized enterprises negatively correlate with the disclosure of two GDPR privacy policy core requirements. Moreover, as a headquarters location, Denmark performs best regarding positively correlating with disclosing GDPR privacy policy core requirements, whereas Spain, Italy, and Slovenia negatively correlate with multiple requirements. This study contributes to the novel field of GDPR compliance, offering valuable insights for policymakers and practitioners to enhance data protection practices and mitigate non-compliance risks.
Keywords
general data protection regulation, privacy, privacy policy, natural, language processing, machine learning

Downloads

  • Factors related to GDPR compliance promises in privacy policies a machine learning and NLP approach.pdf
    • full text (Accepted manuscript)
    • |
    • open access
    • |
    • PDF
    • |
    • 732.17 KB
  • (...).pdf
    • full text (Published version)
    • |
    • UGent only
    • |
    • PDF
    • |
    • 968.03 KB

Citation

Please use this url to cite or link to this publication:

MLA
Aberkane, Abdel-Jaouad, et al. “Factors Related to GDPR Compliance Promises in Privacy Policies : A Machine Learning and NLP Approach.” IJISPM-INTERNATIONAL JOURNAL OF INFORMATION SYSTEMS AND PROJECT MANAGEMENT, vol. 13, no. 2, 2025, doi:10.12821/ijispm130202.
APA
Aberkane, A.-J., vanden Broucke, S., & Poels, G. (2025). Factors related to GDPR compliance promises in privacy policies : a machine learning and NLP approach. IJISPM-INTERNATIONAL JOURNAL OF INFORMATION SYSTEMS AND PROJECT MANAGEMENT, 13(2). https://doi.org/10.12821/ijispm130202
Chicago author-date
Aberkane, Abdel-Jaouad, Seppe vanden Broucke, and Geert Poels. 2025. “Factors Related to GDPR Compliance Promises in Privacy Policies : A Machine Learning and NLP Approach.” IJISPM-INTERNATIONAL JOURNAL OF INFORMATION SYSTEMS AND PROJECT MANAGEMENT 13 (2). https://doi.org/10.12821/ijispm130202.
Chicago author-date (all authors)
Aberkane, Abdel-Jaouad, Seppe vanden Broucke, and Geert Poels. 2025. “Factors Related to GDPR Compliance Promises in Privacy Policies : A Machine Learning and NLP Approach.” IJISPM-INTERNATIONAL JOURNAL OF INFORMATION SYSTEMS AND PROJECT MANAGEMENT 13 (2). doi:10.12821/ijispm130202.
Vancouver
1.
Aberkane A-J, vanden Broucke S, Poels G. Factors related to GDPR compliance promises in privacy policies : a machine learning and NLP approach. IJISPM-INTERNATIONAL JOURNAL OF INFORMATION SYSTEMS AND PROJECT MANAGEMENT. 2025;13(2).
IEEE
[1]
A.-J. Aberkane, S. vanden Broucke, and G. Poels, “Factors related to GDPR compliance promises in privacy policies : a machine learning and NLP approach,” IJISPM-INTERNATIONAL JOURNAL OF INFORMATION SYSTEMS AND PROJECT MANAGEMENT, vol. 13, no. 2, 2025.
@article{01JNNRCF9KKSB3QDNKC4DFPB0V,
  abstract     = {{This paper employs Machine Learning (ML) and Natural Language Processing (NLP) techniques to examine the relationship between organizational factors, such as company size and headquarters location, of data processing entities and their GDPR compliance promises as disclosed in privacy policies. Our methodology comprises three main stages, each representing a key contribution. Firstly, we developed five NLP-based classification models with precision scores of at least 0.908 to assess different GDPR compliance promises in privacy policies. Secondly, we have collected a data set of 8,614 organizations in the European Union containing organizational information and the GDPR compliance promises derived from the organization’s privacy policy. Lastly, we have analyzed the organizational factors correlating to these GDPR compliance promises. The findings reveal, among other things, that small or medium-sized enterprises negatively correlate with the disclosure of two GDPR privacy policy core requirements. Moreover, as a headquarters location, Denmark performs best regarding positively correlating with disclosing GDPR privacy policy core requirements, whereas Spain, Italy, and Slovenia negatively correlate with multiple requirements. This study contributes to the novel field of GDPR compliance, offering valuable insights for policymakers and practitioners to enhance data protection practices and mitigate non-compliance risks.}},
  articleno    = {{e2}},
  author       = {{Aberkane, Abdel-Jaouad and vanden Broucke, Seppe and Poels, Geert}},
  issn         = {{2182-7788}},
  journal      = {{IJISPM-INTERNATIONAL JOURNAL OF INFORMATION SYSTEMS AND PROJECT MANAGEMENT}},
  keywords     = {{general data protection regulation,privacy,privacy policy,natural,language processing, machine learning}},
  language     = {{eng}},
  number       = {{2}},
  pages        = {{23}},
  title        = {{Factors related to GDPR compliance promises in privacy policies : a machine learning and NLP approach}},
  url          = {{http://doi.org/10.12821/ijispm130202}},
  volume       = {{13}},
  year         = {{2025}},
}

Altmetric
View in Altmetric