The Privaciz/GDPR model is based on the ArchiMate model, and extended by stereotypes provided by the Privaciz Model module.

General

Tools to model basic GDPR concepts.

Stereotype Label Description

GDPRElement

GDPR element

Indicates that an element belongs to the GDPR model.

gdprdiagram.png GDPRDiagram

GDPR diagram

GDPR diagram

gdprfunctionaldiagram.png GDPRFunctionalDiagram

GDPR functional diagram

GDPR functional diagram

gdprriskdiagram.png GDPRRiskDiagram

GDPR risk diagram

GDPR risk diagram

gdprtechnicaldiagram.png GDPRTechnicalDiagram

GDPR technical diagram

GDPR technical diagram

DataProcessing

Tools to model the GDPR personal data processing.

Stereotype Label Description

dataprocessing.png DataProcessing

Data processing

Operation or set of operations addressing personal data.

process.png Process

Process

Representation of the flow of interactions between functions and services.

processlink.png ProcessLink

Process

Indicates that a data processing is carried out within a process.

purpose.png Purpose

Purpose

Reason why personal data are being processed.

purposelink.png PurposeLink

Purpose

Indicates the purpose of a data processing.

datausagelink.png DataUsageLink

Usage

Indicates that personal data is being used in a process.

personaldataflowlink.png PersonalDataFlowLink

Personal data flow

Indicates that personal data is being exchanged between participants or processes.

conveyedlink.png ConveyedLink

Conveyed

Indicates which personal data is conveyed via a data flow.

delegationrealizationlink.png DelegationLink

Delegation

Indicates who the data processing is subcontracted to.

implementationlink.png ImplementationLink

Implementation

Indicates that an organization unit (organization, department or subcontractor) implements a process.

Implementations

Tools to model GDPR implementation concepts.

Stereotype Label Description

datacarrier.png DataCarrier

Data carrier

Personal data carrier

artifact.png Artifact

Artifact

Piece of data that is used or produced in a software development process, or by deployment and operation of an IT system.

material.png Material

Material

Structure element that represents tangible physical matter or physical elements.

node.png Node

Node

Physical item (hardware device).

cloud.png Cloud

Cloud

Applications, storage and other services which are accessed via the Web.

server.png Server

Server

Remote system used to access information.

hostinglink.png HostingLink

Hosting

Indicates that an application component is hosted by a node.

applicationcomponent.png ApplicationComponent

Application component

Element used to model entire applications or individual parts of such applications.

database.png Database

Database

Structure used to store and organize large amounts of data.

application.png Application

Application

Element used to model entire applications (deployed and operational IT systems).

applicationlink.png ApplicationLink

Application

Indicates that a process is realized by an application.

hostcountrylink.png HostCountryLink

Host country

Indicates in which country the Data Carrier is hosted.

country.png Country

Country

Country from which a participant operates, or where personal data is stored.

Contract

Contract

Abstract signed agreement (processing, storage, transfer or cooperation).

cooperationcontract.png CooperationContract

Cooperation Contract

Signed agreement that defines the cooperation terms between two participants.

processingcontract.png ProcessingContract

Processing contract

Signed agreement that binds a data controler and a subcontractor over the processing of data.

datacontract.png StorageContract

Storage contract

Signed agreement that defines the terms of data storage.

transfercontract.png TransferContract

Transfer contract

Signed agreement that defines the terms of data transfer.

conveyedcontractlink.png ConveyedContractLink

Contract

Indicates which contract is used.

Participants

Tools to model GDPR participants.

Stereotype Label Description

participant.png Participant

Participant

Person or organization which takes part in processing data.

OrganizationUnit

Organization unit

Participant which is not a natural person.

organization.png Organization

Organization

Either a company or a non-commercial organization which is responsible for the data processing.

processor.png Processor

Subcontractor

Subcontractor who processes data for the controller.

delegationservinglink.png DelegationLink

Delegation

Indicates who the data processing is subcontracted to.

subsequentlink.png SubsequentLink

Subsequent

Indicates that a subcontractor processes the data for the subcontractor.

department.png Department

Department

Sub-organization entity, like a department, or a business unit.

departmentlink.png DepartmentLink

Department

Indicates that an organization, or a subcontractor has a department.

gdprcorrespondent.png GDPRCorrespondent

GDPR correspondent

Agent in charge with personal data privacy at department or business unit level. Appointed by the Organization. Reports to the DPO.

correspondentlink.png CorrespondentLink

Correspondent

Indicates who is the organization’s GDPR correspondent.

Role

Role

Person or agent which takes part in processing data.

Agent

Agent

Operator taking part in the processing of personal data.

externalagent.png ExternalAgent

External Agent

Operator who takes part in the processing personal data from outside the organization.

internalagent.png InternalAgent

Internal agent

Operator who takes part in the processing of personal data from within the organization.

DataSubject

Data subject

Natural person whose personal data is being processed.

externalperson.png ExternalPerson

External person

Natural person whose personal data is processed and who is NOT part of the organization.

internalperson.png InternalPerson

Internal person

Natural person whose personal data is being processed and who is part of the organization.

dpo.png DPO

DPO

Data Privacy Officer (or Data Protection Officer) in charge with enforcing the compliancy with the GDPR within the organization.

cooperationmodelink.png CooperationModeLink

Cooperation

Indicates that a participant cooperates with another participant.

cooperationcontextlink.png CooperationContextLink

Cooperation context

Indicates the context of a participant cooperation.

partoflink.png PartOfLink

Part Of

Indicates that a role is part of an organization unit.

structurallink.png StructuralLink

Structural link

Indicates that a participant is bind to another participant.

legalownershiplink.png LegalOwnershipLink

Legal ownership

Indicates that the personal data of a European citizen are being collected, stored, or processed.

performlink.png PerformLink

Perform

Indicates that a process is executed by an agent.

controllerlink.png ControllerLink

Controller

Indicates which participant is in change with processing the personal data.

countrylink.png CountryLink

Country

Indicates the country from which a participant operates, or where personal data is stored.

PersonalData

Tools to model GDPR personal data.

Stereotype Label Description

PersonalData

Personal data

Personal data’ means any information relating to an identified or identifiable natural person whom can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

personaldatagroup.png PersonalDataGroup

Personal data group

Container gathering several personal data.

connectiondata.png ConnectionData

Connection data

Connection data (IP adresses, event logs, etc.)

financialdata.png FinancialData

Financial data

Financial or economic information.

identificationdata.png IdentificationData

Identification data

Civil status, identity, identification data, etc.

locationdata.png LocationData

Location data

Location data (mobility, GPS data, GSM, etc.).

personallifedata.png PersonalLifeData

Personal life data

Personal life related information (lifestyle, family situation, etc.)

professionallifedata.png ProfessionalLifeData

Professional life data

Professional life related data (CV, education, professional training, rewards, etc.).

biometricdata.png BiometricData

Biometric data

Personal data that resulted from specific processing related to physical and behavioral features of a person, which allows the identification of that person.

socialsecuritynumberdata.png SocialSecurityNumberData

Social security number

Unique identification number (such as social security number).

criminalconvictiondata.png CriminalConvictionData

Criminal conviction data

Sensitive data related to penal convictions or infractions.

ethnicdata.png EthnicData

Ethnic data

Data revealing the ethnic or racial origin of the data subject.

geneticdata.png GeneticData

Genetic data

Data related to a natural person’s genetic characteristics, which offers information about the mental or physical health of that person.

healthdata.png HealthData

Health data

Personal data referring to the personal mental and physical health of a person, including information on health services accessed.

opiniondata.png OpinionData

Opinion data

Data revealing political opinions.

religiousdata.png ReligiousData

Religious data

Data revealing religious or philosophical beliefs.

sexualorientationdata.png SexualOrientationData

Sexual orientation data

Data concerning the sexual life or sexual orientation.

uniondata.png UnionData

Union data

Data revealing the union membership.

otherpersonaldata.png OtherPersonalData

Other personal data

Other personal data, any kind of information related to a natural person.

datagroupinglink.png DataGroupingLink

Data grouping

Indicates which personal data compose the personal data group.

storagelink.png StorageLink

Storage

Indicates that personal data is stored in a specific data carrier.

Risks

Tools to model GDPR risk analysis concepts.

Stereotype Label Description

risk.png Risk

Risk

Breach in the system which represents a risk for the personal data being processed.

risklink.png RiskLink

Risk

Indicates that a process is subject to a specific risk.

measure.png Measure

Measure

Technical, organizational or legal measure taken by the organization to ensure that the data is safe.

appliedmeasurelink.png AppliedMeasureLink

Applied measure

Indicates that a risk is warded off by a security measure.

measuretype.png MeasureType

Measure type

Type of measure taken to guarantee the security of personal data.

measuretypelink.png MeasureTypeLink

Measure type

Indicates that a type is associated to a measure.

Focus

Tools to model focus diagrams.

Stereotype Label Description

focusdiagram.png FocusDiagram

Focus diagram

Abstract stereotype extended by concrete focus diagrams.

participantfocusdiagram.png ParticipantFocusDiagram

Participant focus diagram

Participant focus diagram

personaldatafocusdiagram.png PersonalDataFocusDiagram

Personal data focus diagram

Personal data focus diagram

processfocusdiagram.png ProcessFocusDiagram

Process focus diagram

Process focus diagram

riskfocusdiagram.png RiskFocusDiagram

Risk focus diagram

Risk focus diagram

FocusDiagramDependency

Focus diagram dependency

Link between a focus diagram and its central element.