CS talk: Static Analysis for Android GDPR Compliance Assurance

Scenic overview of city

Event Date

Location
2022 Academic Surge

Abstract

Many Android applications collect data from users. When they do, they must protect this collected data according to the current legal frameworks. This need for data protection has become even more crucial with the introduction of the General Data Protection Act (GDPR) by the European Union. While many Android applications state a privacy policy, privacy assessments are manual and thus very costly and error prone. One of the main challenges in such privacy assessments is bridging the gap between legal privacy statements (in English) and the technical measures implemented by Android apps to protect user privacy.

In this talk, I will explore how static analysis can be used to address key questions around data protection. Our primary goal is to design tool-based approaches that help app developers, privacy specialists, and legal experts ensure data protection in Android applications using automated static program analysis.

Speaker Biography

Mugdha Khedkar is a 3rd year PhD student working with Prof. Dr. Eric Bodden (https://www.bodden.de/) at the Secure Software Engineering group at Paderborn University (Germany). Her research interests include an intersection of program analysis and data protection. In her PhD, she is exploring if static analyses can play a role in diagnosing data privacy issues in Android apps. She completed her Master's in Computer Science from the Chennai Mathematical Institute, India (https://www.cmi.ac.in/). In her free time, she enjoys traveling and shares her experiences on her blog: https://mugdhak30.github.io/year-archive/.

Event Category