Evangelia Vanezi

dblp:242/3236 · DBLP profile ↗
← Back
8ranked-venue papers
7as first author
5since 2021 · last 2026
0000-0003-1958-5574ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 4 · 3 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 first-author · 1 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Modelling GDPR-Based Privacy Requirements with Software Engineering Diagrams: A Systematic Literature Review
abstract
The application of the General Data Protection Regulation (GDPR) has significantly affected privacy requirements elicitation, modelling, and verification in Software Engineering (SE). One of the affected areas is requirements visualisation through modelling diagrams, which plays a crucial role in ensuring privacy compliance, as functional system requirements should be integrated with GDPR-based privacy requirements. We present a systematic literature review on how SE diagrams have been employed to capture and integrate GDPR-based privacy requirements into software system design. The study aims to identify the existing research landscape, existing gaps, and directions for future work. Following a rigorous search protocol and addressing two research questions, 18 primary studies published between 2017 and 2025 were selected, analysed, and categorised based on (i) the diagram types used, and (ii) the GDPR principles or rights addressed. The findings highlight the need for inter-diagram integration, full lifecycle traceability mechanisms, tool support, and automated compliance checking.
Evangelia Vanezi, Georgia M. Kapitsaki, Anna Philippou
ENASE (1)1
2025 FOSS-Chain: Using Blockchain for Open Source Software License Compliance
Kypros Iacovou, Georgia M. Kapitsaki, Evangelia Vanezi
PROFES3
2025 Privacy-Enhanced Software Design: Purpose-Aware UML Diagrams
Evangelia Vanezi, Georgia M. Kapitsaki, Anna Philippou
PROFES1
2024 What's Your Purpose? An Approach to Incorporating GDPR Purposes into Requirements Analysis
Evangelia Vanezi, Georgia M. Kapitsaki, Anna Philippou
ICISSP1
2021 CompLicy: Evaluating the GDPR Alignment of Privacy Policies - A Study on Web Platforms
Evangelia Vanezi, George Zampa, Christos Mettouris, Alexandros Yeratziotis, George Angelos Papadopoulos
RCIS1
2020 DiálogoP - A Language and a Graphical Tool for Formally Defining GDPR Purposes
abstract
The notion of processing purpose , as set out in the EU General Data Protection Regulation (GDPR), comprises a crucial part of a software system’s privacy policy. Processing purposes are meant to characterize the usage of personal data within a system. In this work, we propose a formal type language for defining purposes as the communication exchanges between a system’s entities, based on session types enhanced with privacy notions. In order to provide software engineers with the means to easily define processing purposes, we encode the formal language syntax to a UML-based domain model and we present DiálogoP, a tool that supports the graphical model definition and subsequently translates it into formal language definitions.
Evangelia Vanezi, Georgia M. Kapitsaki, Dimitrios Kouzapas, Anna Philippou, George Angelos Papadopoulos
RCIS1
2019 A Formal Modeling Scheme for Analyzing a Software System Design against the GDPR
abstract
Since the adoption of the EU General Data Protection Regulation (GDPR) in May 2018, designing software systems that conform to the GDPR principles has become vital. Modeling languages can be a facilitator for this process, following the principles of model-driven development. In this paper, we present our work on the usage of a π-calculus-based language for modeling and reasoning about the GDPR provisions of 1) lawfulness of processing by providing consent, 2) consent withdrawal, and 3) right to erasure. A static analysis method based on type checking is proposed to validate that a model conforms to associated privacy requirements. This is the first step towards a rigorous Privacy-By-Design methodology for analyzing and validating a software system model against the GDPR. A use case is presented to discuss and illustrate the framework.
Evangelia Vanezi, Georgia M. Kapitsaki, Dimitrios Kouzapas, Anna Philippou
ENASE1
2019 GDPR Compliance in the Design of the INFORM e-Learning Platform: a Case Study
abstract
The European Union General Data Protection Regulation (GDPR) governs personal data processing, aiming to ensure privacy in all systems handling such data. All systems that process personal data, including software systems are legally obliged to comply to all articles of the GDPR applicable to them. In this paper, the case study of an e-Learning software platform, namely the INFORM platform and its compliance to relevant articles of the GDPR is presented. The e-Learning platform was developed with the objective to host the educational material developed under the JUSTICE EU-funded project INFORM, targeting judiciary, court staff and legal practitioners, in order to provide free and open distance access to the content. In particular, the paper demonstrates the compliance of the platform with the articles and principles of: Data Minimisation, Lawfulness of Processing, Right to Erasure, Right of Access, Right to Data Portability, Right to Rectification and Security of Processing. By applying these articles, conformance to the provision for Data Protection by design is also achieved; the platform's software development process integrates the articles of the GDPR early in the development steps, from the specification and design phases. We show how the design process progressed and demonstrate the corresponding functionality within the e-Learning platform. The paper extracts a list of lessons learned and conclusions on software GDPR compliance.
Evangelia Vanezi, Dimitrios Kouzapas, Georgia M. Kapitsaki, Theodora Costi, Alexandros Yeratziotis, Christos Mettouris, Anna Philippou, George Angelos Papadopoulos
RCIS1