5  CONCLUSIONS 
By 2024, more than 6 years after the GDPR has been 
enforced in all European State Members to regulate 
citizens  personal  data  protection,  not  many  works 
were  found  in  the  literature  that  aim  to  understand 
users’ knowledge, needs and contexts to implement 
GDPR compliance in practice. 
The lack of research on this topic impacts the way 
users  and  organizations  will  approach  this 
requirement. Also, not many straightforward tools are 
available to provide the right knowledge and support 
the  usage  of  that  knowledge  within  stakeholders’ 
professional contexts, without needing to be experts 
in law or privacy. 
On  the  way  to  fill  this  gap,  this  study  aimed  to 
explore  the  perceptions,  preferences  and  needs 
regarding interactive and assistive tools, together with 
its content, to support GDPR compliance in practice. 
Our results show that stakeholders who frequently 
need to perform personal data processing do not often 
have the knowledge, experience or required support 
to  put  compliance  procedures  into  practice  in  their 
context. This work contributes to understanding what 
content  and  functionalities  could  be  included  in  an 
interactive  tool  to  be designed  to provide  a  holistic 
management  of  all  requirements  and  further 
enhancing the capability of GDPR compliance. 
Our  study  outcomes  can  be  leveraged  with  the 
outcomes  of  previous  works  to  integrate  both  user 
research needs not only at the interaction and design 
level but also on the content needs and expectations.    
ACKNOWLEDGEMENTS 
This work is funded by project Health from Portugal 
- HfPT (Aviso 2022-C05i0101-02 Agendas/Alianças 
mobilizadoras  para  a  reindustrialização,  Projeto  nº 
C630926586-00465198”). 
Ana  Ferreira  is  supported  by  Fundação  para  a 
Ciência  e  Tecnologia  (FCT),  project  DRAPE-
Designing  Trust  and  Privacy  into  Research,  Ref. 
2022.00381.CEECIND/CP1712/CT0001;  DOI:  
10.54499/2022.00381.CEECIND/CP1712/CT0001. 
Rute  Almeida  is  supported  by  FCT,  Ref.  
CEECINST/00056/2021/CP2804/CT0004;  DOI: 
10.54499/CEECINST/00056/2021/CP2804/CT0004. 
 
 
 
 
 
REFERENCES 
AI ACT. (2024). General Data Protection Regulation (EU) 
2024/1689  of  the  European  Parliament  and  of  the 
Council. Official Journal of the European Union. 
Chhetri, E., Fensel, A., DeLong, R. (2024). GDPR consent 
management  and  automated  compliance  verification 
tool,  SoftwareX,  Volume  27,  2024,  101821, 
https://doi.org/10.1016/j.softx.2024.101821. 
Cool,  A.  (2019).  Impossible,  unknowable,  accountable: 
Dramas and dilemmas of data law. Soc Stud Sci. 
49(4):503-530. doi: 10.1177/0306312719846557.  
de  Montety  C.,  Antignac  T.,  Slim  C.  (2019).  GDPR 
modelling  for  log-based  compliance  checking  IFIP 
Advances in Information and Communication 
Technology, 563 IFIP, pp. 1 - 18. DOI: 10.1007/978-3-
030-33716-2_1. 
Ferreira, A. (2020). GDPR: What’s in a year (and a half)? 
22nd International Conference on Enterprise 
Information Systems. Volume 2, 209-216.  
Ferreira, L., Martins, T., Dias, E. and Ferreira, A. (2024). 
IRIS: A Prototype for GDPR Health Research 
Compliance.  CHIRA  2024  –  8
th
  International 
Conference on Computer-Human Interaction Research 
and Applications. (In Press). 
GDPR.  (2016).  General  Data  Protection  Regulation  (EU) 
2016/679  of  the  European  Parliament  and  of  the 
Council L 119. Official Journal of the European Union. 
ladinić  A.,  Vukić  Z.,  Rončević  A.  (2023).  GDPR 
Compliance Challenges in Croatian Micro, Small and 
Medium Sized Enterprises. Pravni vjesnik. 39 (3-4), pp. 
53 – 75. DOI: 10.25234/pv/23972.  
IAPP and Trust Arc. (2019). Trust Arc: Measuring Privacy 
Operations.  International Association of Privacy 
Professionals. 
IAPP-EY.  (2019).  Annual  Privacy  Governance  Report. 
International Association of Privacy Professionals. 
Libal, T.  (2021). Towards Automated GDPR Compliance 
Checking.  Lecture Notes in Computer Science 
(including subseries Lecture Notes in Artificial 
Intelligence and Lecture Notes in Bioinformatics), 
12641  LNAI,  pp.  3  –  19.  DOI:  10.1007/978-3-030-
73959-1_1 
PIA  -  Privacy  Impact  Assessment  Software.  CNIL - 
Commission Nationale de l’Informatique et des 
Libertés.  Available  at:  https://www.cnil.fr/en/privacy-
impact-assessment-pia. Acccessed on: 11/12/2024. 
Politou,  E.,  Alepis,  E.,  Patsakis.  C.  (2018).  Forgetting 
personal data and revoking consent under the  GDPR: 
Challenges  and  proposed  solutions,  Journal of 
Cybersecurity,  Volume  4,  Issue  1. 
https://doi.org/10.1093/cybsec/tyy001. 
Quinn,  P.,  Quinn,  L.  (2018).  Big  genetic  data  and  its big 
data protection challenges, Computer Law & Security 
Review,  Volume  34,  Issue  5,1000-1018. 
https://doi.org/10.1016/j.clsr.2018.05.028. 
Ryan P., Crane M., Brennan R. (2021). GDPR Compliance 
Tools:  Best  Practice  from  RegTech. Lecture Notes in 
Business Information Processing,  417,  pp.  905 -  929, 
Cited 14 times. DOI: 10.1007/978-3-030-75418-1_41.