Marco Robol

dblp:184/5354 · DBLP profile ↗
← Back
5ranked-venue papers
3as first author
4since 2021 · last 2026
0000-0003-4611-0371ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 3 · 3 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Consent under control with ProPrivacy: Business process compliance verification for GDPR-consent requirements
abstract
Context: Since its enforcement in 2018, the General Data Protection Regulation (GDPR) has continued to shape how organizations, in the European Economic Area, design and operate their data-driven services. Consent management, in particular, remains a cornerstone of compliance, but it has also become increasingly complex with the rise of data-intensive business models, digital health platforms, and AI-powered services. Despite the availability of technical and organizational tools, many companies still struggle to adapt legacy and large-scale processes to meet GDPR’s consent requirements. Knowledge about these processes is often fragmented across organizational silos, and documentation is incomplete, making re-engineering activities both tedious and error-prone. Objectives: Companies relies on experts for the re-engineering and validation of their processes, while a comprehensive method is still missing to support them in verifying the compliance of their processes with consent. To address these challenges, this paper proposes a model-based approach that supports business and privacy experts in aligning operational processes with GDPR consent principles. Methods.: Rather than introducing a new language that would require analysts modeling processes from scratch, our framework, ProPrivacy, builds on the widely adopted Business Process Model and Notation 2.0 (BPMN 2.0) modeling language, allowing analysts to enrich existing models with consent requirements. To mitigate verification errors and reduce the effort in analyzing complex models, ProPrivacy then automatically verifies compliance with key GDPR principles related to specific and freely given consent and data minimization. We demonstrate the applicability and scalability of our approach on realistic processes from the healthcare domain, where the management of sensitive data continues to present critical privacy challenges. Conclusions: The results suggest that automated verification of business processes can not only support organizations in achieving compliance with GDPR but also serve as a foundation for certifying accountable and transparent business processes.
Marco Robol, Mattia Salnitri, Elda Paja, Paolo Giorgini
Inf. Softw. Technol.1
2024 LLM-Driven Knowledge Extraction in Temporal and Description Logics
Damiano Duranti, Paolo Giorgini, Andrea Mazzullo, Marco Robol, Marco Roveri
EKAW4
2023 Consent Verification Monitoring
abstract
Advances in personalization of digital services are driven by low-cost data collection and processing, in addition to the wide variety of third-party frameworks for authentication, storage, and marketing. New privacy regulations, such as the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act, increasingly require organizations to explicitly state their data practices in privacy policies. When data practices change, a new version of the policy is released. This can occur a few times a year, when data collection or processing requirements are rapidly changing. Consent evolution raises specific challenges to ensuring GDPR compliance. We propose a formal consent framework to support organizations, data users, and data subjects in their understanding of policy evolution under a consent regime that supports both the retroactive and non-retroactive granting and withdrawal of consent. The contributions include (i) a formal framework to reason about data collection and access under multiple consent granting and revocation scenarios, (ii) a scripting language that implements the consent framework for encoding and executing different scenarios, (iii) five consent evolution use cases that illustrate how organizations would evolve their policies using this framework, and (iv) a scalability evaluation of the reasoning framework. The framework models are used to verify when user consent prevents or detects unauthorized data collection and access. The framework can be integrated into a runtime architecture to monitor policy violations as data practices evolve in real time. The framework was evaluated using the five use cases and a simulation to measure the framework scalability. The simulation results show that the approach is computationally scalable for use in runtime consent monitoring under a standard model of data collection and access and practice and policy evolution.
Marco Robol, Travis D. Breaux, Elda Paja, Paolo Giorgini
ACM Trans. Softw. Eng. Methodol.1
2022 Real-Time BDI Agents: A Model and Its Implementation
abstract
The BDI model proved to be effective for the developing of applications requiring high-levels of autonomy and to deal with the complexity and unpredictability of real-world scenarios. The model, however, has significant limitations in reacting and handling contingencies within the given real-time constraints. Without an explicit representation of time, existing real-time BDI implementations overlook the temporal implications during the agent’s decision process that may result in delays or unresponsiveness of the system when it gets overloaded. In this paper, we redefine the BDI agent control loop inspired by traditional and well establish algorithms for real-time systems to ensure a proper reaction of agents and their effective application in typical real-time domains. Our model proposes an effective real-time management of goals, plans, and actions with respect to time constraints and resources availability. We propose an implementation of the model for a resource-collection video-game and we validate the approach against a set of significant scenarios.
Andrea Traldi, Francesco Bruschetti, Marco Robol, Marco Roveri, Paolo Giorgini
IJCAI3
2019 Consent Verification Under Evolving Privacy Policies
abstract
Personal data provides important business value, for example, in the personalization of services. In addition, companies are moving toward new business models, in which products and services are offered without charge to users, but in exchange for targeted advertising revenue. New privacy regulations require organizations to explicitly state their data practices in privacy policies, including which data types will be collected. By consenting to data collections described in a policy, the user acknowledges that he or she is granting the company the authorizations needed to access their data. When data practices change, a new version of the policy is released. This release can occur a few times a year, when requirements are rapidly changing for the collection and processing of personal data. Furthermore, the user may change his or her privacy consent by opting in or out of the policy. We propose a formal framework to support companies and users in their understanding of policies evolution under consent regime that supports both retroactive and non-retroactive consent and consent revocation. Preliminary results include an ontology for policy evolution, expressed in Description Logic, that can be used to formalize consent and data collection logs and then query for which data types can be legally accessed.
Marco Robol, Travis D. Breaux, Elda Paja, Paolo Giorgini
RE1