Understanding the GDPR from a requirements engineering perspective-a systematic mapping study on regulatory data protection requirements

被引:6
作者
Negri-Ribalta, Claudia [1 ,2 ]
Lombard-Platet, Marius [2 ]
Salinesi, Camille [1 ]
机构
[1] Univ Paris 1 Pantheon Sorbonne, Ctr Rech Informat, F-75000 Paris, France
[2] Univ Luxembourg, Interdisciplinary Ctr Secur Reliabil & Trust, 2 Ave Univ, L-10587 Belval, Luxembourg
关键词
Requirements; Compliance; Systematic mapping; Data protection; GDPR; PRIVACY;
D O I
10.1007/s00766-024-00423-4
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Data protection compliance is critical from a requirements engineering (RE) perspective, both from a software development lifecycle (SDLC) perspective and regulatory compliance. Not including these requirements from the early phases of the SDLC can prove costly and challenging afterward. The general data protection regulation (GDPR) from the European Union (EU) sets a list of requirements that organizations working within its scope should satisfy. However, these requirements are complex to work with, as legal prose tends to be vague and imprecise, and not all requirements have received the same attention from researchers. This study aims to identify the research published in RE for helping compliance with regulatory data protection requirements. We gathered and analyzed 90 articles from 2016 to 2022 through a systematic mapping study. We analyzed key trends in the sample, such as year of publication, publication venue, type of research, interdisciplinarity in the author's background, GDPR focus of compliance element, and type of proposal. Our main findings show ongoing interest, mostly published in conferences, in achieving overall compliance with the GDPR and consent as the most popular topics. Other topics, such as cookies or children's data, did not receive significant attention. Research over the whole RE process has been done. 20 (22%) of the papers have authors affiliated with non-computer science; however, most research seems not interdisciplinary. We finally discuss gaps in the literature, possible future areas of research, and the importance of interdisciplinary research for regulatory data protection requirements in RE.
引用
收藏
页码:523 / 549
页数:27
相关论文
共 61 条
[1]   Exploring Automated GDPR-Compliance in Requirements Engineering: A Systematic Mapping Study [J].
Aberkane, Abdel-Jaouad ;
Poels, Geert ;
Broucke, Seppe Vanden .
IEEE ACCESS, 2021, 9 :66542-66559
[2]   A systematic literature mapping of goal and non-goal modelling methods for legal and regulatory compliance [J].
Akhigbe, Okhaide ;
Amyot, Daniel ;
Richards, Gregory .
REQUIREMENTS ENGINEERING, 2019, 24 (04) :459-481
[3]   Evaluating Goal Models within the Goal-Oriented Requirement Language [J].
Amyot, Daniel ;
Ghanavati, Sepideh ;
Horkoff, Jennifer ;
Mussbacher, Gunter ;
Peyton, Liam ;
Yu, Eric .
INTERNATIONAL JOURNAL OF INTELLIGENT SYSTEMS, 2010, 25 (08) :841-877
[4]  
[Anonymous], Regulation (EU) 2016/679 of The European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
[5]  
Birnhack Michael, 2014, Jurimetrics: Journal of Law, Science and Technology, V55, P55
[6]  
Booch G., 2005, Unified Modeling Language user guide, V2nd
[7]  
Breaux TD, 2007, RHAS6
[8]   Analyzing regulatory rules for privacy and security requirements [J].
Breaux, Travis D. ;
Anton, Annie I. .
IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2008, 34 (01) :5-20
[9]   Legal Accountability as Software Quality: A US Data Processing Perspective [J].
Breaux, Travis D. ;
Norton, Thomas .
2022 30TH IEEE INTERNATIONAL REQUIREMENTS ENGINEERING CONFERENCE (RE 2022), 2022, :101-113
[10]  
Breaux Travis D., 2006, Towards regulatory compliance: Extracting rights and obligations to align requirements with regulations