The conceptual model (Second Version) was represented using a UML class diagram . The concepts of the conceptual model (52 concepts) were based on the first version of the SLR (54 concepts), which does not include Springer font, and the second version of the SLR (59 concepts – 54 from SLR first version and 5 concepts from Springer), which include Springer font. In the second version of the SLR were found other five new concepts (Risk, Auditability, Processor/Manager, Privacy Policy and Privacy Preferences) and these were also included in the conceptual model. The conceptual model is also based on the results of the survey (which discarded 7 concepts), but the survey evaluated only the concepts found in the first version of the SLR.
In summary, the conceptual model (52 concepts) was constructed based on 54 concepts from the SLR first version (which were evaluated in the survey that discarded 7 concepts) and 5 concepts from the SLR second version.Although the concepts found in the second version of the SLR have not been evaluated, they are cited in other sources, such as:
· Processor/Manager: Processes personally identifiable information on behalf of and in accordance with the instructions of a controller (ISO/IEC 29100:2011, 2011; GDPR, 2018).
· Risk: Define risk-related concepts along with their interrelations (GHARIB et al, 2017).
· Privacy Preference: Express user’s privacy preferences as policies attached to the data items (HE; ANTÓN, 2003).
· Privacy Policy: It is a privacy statement that defines the permitted and/or forbidden actions to be carried out by actors of the system toward information (GHARIB et al, 2017).