OntoPriv: Towards Designing a DPV-based Legal Ontology for Knowledge Retrieval and Compliance in Privacy Legislation
DOI:
https://doi.org/10.19153/cleiej.28.5.4Keywords:
data privacy, data protection regulation GDPR, LOPDP, legal ontology, compliance, dpv, data privacy vocabularyAbstract
In an increasingly digital world, protecting personal data has become a pressing global issue, prompting the creation of complex regulations aimed at safeguarding individuals' privacy. However, achieving compliance with these frameworks poses significant challenges for organizations, requiring a methodical and well-structured approach. In this context, OntoPriv was developed as a legal ontology tailored to support compliance with Ecuador's Organic Law on Personal Data Protection (LOPDP). OntoPriv serves as a systematic framework that not only clarifies legal obligations but also provides tools to strengthen privacy practices and encourage accountability. This extended work goes a step further by aligning OntoPriv with the Data Privacy Vocabulary (DPV), an internationally recognized W3C standard. This alignment significantly enhances OntoPriv's modularity, semantic depth, and interoperability, effectively connecting local and global data privacy frameworks. By integrating DPV, OntoPriv incorporates standardized concepts such as legal bases, purposes, and risk mitigation strategies. This ensures cross-jurisdictional compatibility and addresses prior challenges like limited interoperability and insufficient semantic connections. This integration positions OntoPriv as a powerful tool that facilitates automated compliance, comprehensive risk assessments, and improved data governance while fostering a shared understanding of privacy standards across different regions. This article discusses OntoPriv's development, the methodology for its alignment with DPV, and its implications for advancing data privacy compliance in Ecuador and beyond.
References
References
G. Suntaxi, K. Ojeda, and F. Rodr´?guez, “OntoPriv: Enhancing Understanding and Compliance in
Privacy Legislation via Legal Ontologies,” in 2024 L Latin American Computer Conference (CLEI),
, pp. 1–10. [Online]. Available: https://doi.org/10.1109/CLEI64178.2024.10700326
G. Suntaxi, A. A. E. Ghazi, and K. B¨ohm, “Preserving secrecy in mobile social networks,” ACM
Transactions on Cyber-Physical Systems, vol. 5, no. 1, pp. 1–29, 2020.
B. Gibson, S. Townes, D. Lewis, and S. Bhunia, “Vulnerability in massive api scraping: 2021 linkedin
data breach,” in 2021 International Conference on Computational Science and Computational Intelli-
gence (CSCI), 2021, pp. 777–782.
European Union, “General data protection regulation (gdpr),” Sep 2019, [Accessed April 1st, 2024].
[Online]. Available: https://gdpr-info.eu/
Presidˆencia da Rep´ublica Secretaria-Geral , “General personal data protection act (lgpd),” August
, [Accessed April 1st, 2024]. [Online]. Available: https://lgpd-brazil.info/
A. N. R. del Ecuador, “Ley org´anica de protecci´on de datos personales,” May 2021, [Accessed April
st, 2024]. [Online]. Available: https://bit.ly/41q3Att
T. Mikkonen, “Perceptions of controllers on eu data protection reform: A finnish perspective,” Computer
law & security review, vol. 30, no. 2, pp. 190–195, 2014.
A. F. Guzman-Castillo, G. Suntaxi, B. N. Flores-Sarango, and D. A. Flores, “Towards designing a
privacy-oriented architecture for managing personal identifiable information,” Journal of internet ser-
vices and information security, vol. 14, no. 1, pp. 64–84, 2024.
J. Jiang, H. Aldewereld, V. Dignum, S. Wang, and Z. Baida, “Regulatory compliance of business
processes,” AI & society, vol. 30, no. 3, pp. 393–402, 2015.
C. Tankard, “What the gdpr means for businesses,” Network Security, vol. 2016, no. 6, pp. 5–8, 2016.
S. Sirur, J. R. Nurse, and H. Webb, “Are we there yet? understanding the challenges faced in complying
with the general data protection regulation (gdpr),” in Proceedings of the 2nd International Workshop
on Multimedia Privacy and Security, 2018, pp. 88–95.
M. Palmirani, M. Martoni, A. Rossi, B. Cesare, R. Livio et al., “Legal ontology for modelling gdpr
concepts and norms,” Frontiers in Artificial Intelligence and Applications, vol. 313, pp. 91–100, 2018.
H. J. Pandit, C. Debruyne, D. O‘Sullivan, and D. Lewis, “Gconsent-a consent ontology based on the
gdpr,” in The Semantic Web: 16th International Conference, ESWC 2019, Portoro?z, Slovenia, June
–6, 2019, Proceedings 16. Springer, 2019, pp. 270–282.
R. Arp, B. Smith, and A. D. Spear, Building ontologies with basic formal ontology. Mit Press, 2015.
A. Guzm´an-Castillo, G. Suntaxi, B. N. Flores-Sarango, and D. A. Flores, “Towards designing a privacy-
oriented architecture for managing personal identifiable information,” Journal of Internet Services and
Information Security, 2024.
C. de la Naci´on Argentina, “Ley 25.326 de protecci´on de los datos personales,” Sep 2000, [Accessed
April 5st, 2024]. [Online]. Available: https://www.argentina.gob.ar/sites/default/files/arg ley25326.pdf
C. N. de Brasil, “Lei geral de prote¸c˜ao de dados pessoais (lgpd),” Aug 2020, [Accessed April 5st, 2024].
[Online]. Available: https://www.gov.br/esporte/pt-br/acesso-a-informacao/lgpd
C. Chileno, “Ley 19628 sobre protecci´on de la vida privada,” Aug 1999, [Accessed April 5st, 2024].
[Online]. Available: https://www.bcn.cl/leychile/navegar?idNorma=141599
C. de Colombia, “Pol´?tica de tratamiento y protecci´on de datos,” Oct 2012, [Accessed April 5st, 2024].
[Online]. Available: https://www.minambiente.gov.co/wpcontent/uploads/2023/03/DS-E-GET-01.pdf
C. de Costa Rica, “Ley de protecci´on de la persona frente al tratamiento de sus
datos personales ley 8968,” Sep 2011, [Accessed April 5st, 2024]. [Online]. Avail-
able: https://www.oas.org/es/sla/ddi/docs/CR4%20Ley%20de%20Protecci%C3%B3n%20de%20la%
Persona%20frente%20al%20Tratamiento%20de%20sus%20Datos%20Personales.pdf
A. N. del Poder Popular de Cuba, “Ley 149 de protecci´on de datos personales,” Aug 2022,
[Accessed April 5st, 2024]. [Online]. Available: https://www.minjus.gob.cu/sites/default/files/
archivos/publicacion/2022-08/goc-2022-o90 0 0.pdf
C. de la Rep´ublica de El Salvador, “Ley de protecci´on de datos personales y habeas data,” Jun
, [Accessed April 5st, 2024]. [Online]. Available: https://www.asamblea.gob.sv/sites/default/files/
documents/correspondencia/2A326CE8-F13A-4828-8640-648235C228BF.pdf
C. de Honduras, “Propuesta de ley de protecci´on de datos personales de honduras,” Jan 2013,
[Accessed April 5st, 2024]. [Online]. Available: https://cei.iaip.gob.hn/doc/Ley%20de%20Proteccion%
de%20Datos%20Personales.pdf
C. de la Uni´on de M´exico, “Ley federal de protecci´on de datos personales en posesi´on de los particulares,”
Jul 2010, [Accessed April 5st, 2024]. [Online]. Available: https://www.gob.mx/cms/uploads/
attachment/file/123648/Ley Federal de Protecci n de Datos Personales en Posesi n de los.pdf
A. N. de Nicaragua, “Ley de protecci´on de datos personales, ley n 787,” Mar 2012,
[Accessed April 5st, 2024]. [Online]. Available: http://legislacion.asamblea.gob.ni/normaweb.nsf/
e314815a08d4a6206257265005d21f9/e5d37e9b4827fc06062579ed0076ce1d
A. N. de Panam´a, “Ley 81 de protecci´on de datos personales,” May 2021, [Accessed April 5st, 2024].
[Online]. Available: https://www.antai.gob.pa/reglamentan-ley-81-de-proteccion-de-datos-personales/
C. de Datos de Paraguay, “Ley N 6534 de protecci´on de datos personales crediticios,” Oct 2020,
[Accessed April 5st, 2024]. [Online]. Available: https://www.bacn.gov.py/leyes-paraguayas/9417/
ley-n-6534-de-proteccion-de-datos-personales-crediticios
A. N. de Datos Personales (ANPD), “Ley N 29733 ley de protecci´on de datos personales de per´u,” Jul
, [Accessed April 5st, 2024]. [Online]. Available: https://www.leyes.congreso.gob.pe/Documentos/
Leyes/29733.pdf
C. N. de la Rep´ublica Dominicana, “Ley de protecci´on de datos personales dominicana, Ley No.
-13,” Dic 2013, [Accessed April 5st, 2024]. [Online]. Available: https://www.tribunalconstitucional.
gob.do/transparencia/marco-legal/leyes/ley-172-13/
R. O. del Uruguay, “Protecci´on de datos personales y acci´on de “habeas data”, Ley No. 18.331,” Aug
, [Accessed April 5st, 2024]. [Online]. Available: https://seleccion.poderjudicial.gub.uy/seleccion/
archivos/ley18331habeasdata2008.pdf
N. Guarino, D. Oberle, and S. Staab, “What is an ontology?” Handbook on ontologies, pp. 1–17, 2009.
V. Mla?ci´c, S. Virtanen, and A. Hakkala, Data protection regulation ontology for compliance. University
of Turku, 2022.
N. F. Noy, D. L. McGuinness et al., “Ontology development 101: A guide to creating your first ontology,”
H. J. Pandit, B. Esteves, G. P. Krog, P. Ryan, D. Golpayegani, and J. Flake, “Data privacy vocabulary
(dpv)–version 2.0,” in International Semantic Web Conference. Springer, 2024, pp. 171–193.
M. Geko and S. Tjoa, “An Ontology Capturing the Interdependence of the General Data Protection
Regulation (GDPR) and Information Security,” ResearchGate, pp. 1–6, Nov. 2018.
C. Bartolini, A. Calabr´o, and E. Marchetti, “Enhancing Business Process Modelling with Data Protec-
tion Compliance: An Ontology-based Proposal,” ResearchGate, pp. 421–428, Jan. 2019.
A. Dresch, D. P. Lacerda, J. A. V. Antunes Jr, A. Dresch, D. P. Lacerda, and J. A. V. Antunes, Design
science research. Springer, 2015.
B. Kitchenham, O. P. Brereton, D. Budgen, M. Turner, J. Bailey, and S. Linkman, “Systematic literature
reviews in software engineering–a systematic literature review,” Information and software technology,
vol. 51, no. 1, pp. 7–15, 2009.
“TOVE Ontologies | Enterprise Integration Laboratory – EIL,” Dec. 2023, [Online; accessed 6. Dec.
. [Online]. Available: https://eil.mie.utoronto.ca/theory/enterprise-modelling/tove
M. Fern´andez-L´opez, A. G´omez-P´erez, and N. Juristo, “METHONTOLOGY: from ontological art
towards ontological engineering,” Engineering Workshop on Ontological Engineering (AAAI97), Mar.
[Online]. Available: https://www.researchgate.net/publication/50236211 METHONTOLOGY
from ontological art towards ontological engineering
Y. Sure, S. Staab, and R. Studer, “On-to-knowledge methodology,” in Handbook on Ontologies, S. Staab
and R. Studer, Eds. Berlin: Springer, 2003, p. 811.
N. F. Noy and D. L. McGuinness, “Ontology development 101: A guide to creating your first ontology,”
Stanford Knowledge Systems Laboratory, Stanford, CA, Technical Report KSL-01-05, 2001.
P. F. Green and M. Rosemann, Business systems analysis with ontologies. IGI Global, 2005.
M. A. Musen, “The prot´eg´e project: a look back and a look forward,” AI matters, vol. 1, no. 4, pp.
–12, 2015.
E. Lee, N. Harris, M. Gibson, R. Chetty, and S. Lewis, “Apollo: a community resource for genome
annotation editing,” Bioinformatics, vol. 25, no. 14, pp. 1836–1837, 2009.
A. Kalyanpur, B. Parsia, E. Sirin, B. C. Grau, and J. Hendler, “Swoop: A web ontology editing browser,”
Journal of Web Semantics, vol. 4, no. 2, pp. 144–153, 2006.
J. C. Arp´?rez, O. Corcho, M. Fern´andez-L´opez, and A. G´omez-P´erez, “Webode: a scalable workbench
for ontological engineering,” in Proceedings of the 1st international conference on Knowledge capture,
, pp. 6–13.
“OntoPriv,” Apr. 2024, [Online; accessed 13. Apr. 2024]. [Online]. Available: https://github.com/
kelvinojedaepn/OntoPriv
A. Gomez-Perez and A. Lozano-Tello, “Applying the ontometric method to measure the suitability of
ontologies,” in Business Systems Analysis with Ontologies. IGI Global, 2005, pp. 249–269.
Y. Helmy, S. Ali, and M. Abd Ellatif, “Evaluating the proposed public budget ontological model,”
International Journal of Computer Science and Information Security (IJCSIS), vol. 16, no. 7, 2018.
(2023) Ontometrics. Universit ˜A¤t Rostock. [Online]. Available: https://ontometrics.informatik.
uni-rostock.de/ontologymetrics/index.jsp
Downloads
Published
Issue
Section
License
Copyright (c) 2025 Gabriela Suntaxi, Kelvin Ojeda, Francisco Rodríguez, Pablo del Hierro, Jorge Miño, Denys A. Flores

This work is licensed under a Creative Commons Attribution 4.0 International License.
CLEIej is supported by its home institution, CLEI, and by the contribution of the Latin American and international researchers community, and it does not apply any author charges whatsoever for submitting and publishing. Since its creation in 1998, all contents are made publicly accesibly. The current license being applied is a (CC)-BY license (effective October 2015; between 2011 and 2015 a (CC)-BY-NC license was used).