Technical Report on the Extension of the Layered Privacy Language

In this technical report, we list all changes we make in our extension of the Layered Privacy Language (LPL).
The changes focus on the improvement of the LPL's compatibility with the General Data Protection Regulation (GDPR).
We address drawbacks of the current version of LPL, which are concerned with the definition of legal bases for data processing; the declaration of official authority vested in the service provider; missing information regarding adequacy decisions for third country transfers; and drawbacks regarding data minimization in LPL.
In addition to addressing these drawbacks, we implement a purpose hierarchy, which improves the general structure of policies written in LPL and supports partially automatically generated privacy policies.
We also add fixed categories for purposes as well as data categories that improve the semantics of the language with respect to formal reasoning about LPL policies.


