Beatriz Esteves

dblp:305/4725 · DBLP profile ↗
← Back
6ranked-venue papers
4as first author
6since 2021 · last 2025
0000-0003-0259-7560ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Databases, data management, data science and information retrieval · 3 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 Interoperable Interpretation and Evaluation of ODRL Policies
Wout Slabbinck, Julián Rojas 0001, Beatriz Esteves, Pieter Colpaert, Ruben Verborgh
ESWC (2)3
2024 How to Manage My Data? With Machine-Interpretable GDPR Rights!
abstract
The EU GDPR is a landmark regulation that introduced several rights for individuals to obtain information and control how their personal data is being processed, as well as receive a copy of it. However, there are gaps in the effective use of rights due to each organisation developing custom methods for rights declaration and management. Simultaneously, there is a technological gap as there is no single consistent standards-based mechanism that can automate the handling of rights for both organisations and individuals. In this article, we present a specification for exercising and managing rights in a machine-interpretable format based on semantic web standards. Our approach uses the comprehensive Data Privacy Vocabulary to create a streamlined workflow for individuals to understand what rights exist, how and where to exercise them, and for organisations to effectively manage them. This work pushes the state of the art in GDPR rights management and is crucial for data reuse and rights management under technologically intensive developments, such as Data Spaces.
Beatriz Esteves, Harshvardhan Jitendra Pandit, Georg Philip Krog, Paul Ryan
JURIX1
2024 Data Privacy Vocabulary (DPV) - Version 2.0
abstract
Abstract The Data Privacy Vocabulary (DPV), developed by the W3C Data Privacy Vocabularies and Controls Community Group (DPVCG), enables the creation of machine-readable, interoperable, and standards-based representations for describing the processing of personal data. The group has also published extensions to the DPV to describe specific applications to support legislative requirements such as the EU’s GDPR. The DPV fills a crucial niche in the state of the art by providing a vocabulary that can be embedded and used alongside other existing standards such as W3C ODRL, and which can be customised and extended for adapting to specifics of use-cases or domains. This article describes the version 2 iteration of the DPV in terms of its contents, methodology, current adoptions and uses, and future potential. It also describes the relevance and role of DPV in acting as a common vocabulary to support various regulatory (e.g., EU’s DGA and AI Act) and community initiatives (e.g., Solid) emerging across the globe.
Harshvardhan Jitendra Pandit, Beatriz Esteves, Georg Philip Krog, Paul Ryan, Delaram Golpayegani, Julian Flake
ISWC (3)2
2022 Automating the Response to GDPR's Right of Access
abstract
With the enforcement of the European Union’s General Data Protection Regulation, users of Web services – the ‘data subjects’ –, which are powered by the intensive usage of personal data, have seen their rights be incremented, and the same can be said about the obligations imposed on the ‘data controllers’ responsible for these services. In particular, the ‘Right of Access’, which gives users the option to obtain a copy of their personal data as well as relevant details such as the categories of personal data being processed or the purposes and duration of said processing, is putting increasing pressure on controllers as their execution often requires a manual response effort, and the wait time is negatively affecting the data subjects. In this context, the main goal of this work is the development of an API, which builds on the previously mentioned structured information, to assist controllers in the automation of replies to right of access requests. The implemented API method is then used in the implementation of a Solid application whose main goal is to assist users in exercising their right of access to data stored in Solid Pods.
Beatriz Esteves, Víctor Rodríguez-Doncel, Ricardo Longares
JURIX1
2022 Now, Later, Never: A Study of Urgency in Mobile Push-Notifications
Beatriz Esteves, Kieran Fraser, Shridhar Kulkarni, Owen Conlan, Víctor Rodríguez-Doncel
MoMM1
2022 Extracting and Understanding Call-to-actions of Push-Notifications
Beatriz Esteves, Kieran Fraser, Shridhar Kulkarni, Owen Conlan, Víctor Rodríguez-Doncel
NLDB1