Guidelines adopted by agile teams in privacy requirements elicitation after the Brazilian general data protection law (LGPD) implementation

被引:9
|
作者
Canedo, Edna Dias [1 ]
Seidel Calazans, Angelica Toffano [2 ]
Bandeira, Ian Nery [1 ]
Teixeira Costa, Pedro Henrique [1 ]
Seidel Masson, Eloisa Toffano [2 ]
机构
[1] Univ Brasilia UnB, Comp Sci Dept, POB 4466, Brasilia, DF, Brazil
[2] Univ Ctr UniCEUB, Brasilia, DF, Brazil
关键词
Privacy requirements elicitation; Agile teams; Techniques; Perception; LGPD; CHALLENGES; SECURITY;
D O I
10.1007/s00766-022-00391-7
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The Brazilian General Data Protection Law (LGPD) implementation has impacted activities carried out by the software development teams. Due to it, developers had to become aware of the existing techniques and tools to carry out privacy requirements elicitation. Extending our previous work, we have investigated the actions taken by organizations regarding the LGPD, specifically in software development, considering the perception of agile development teams after two years of the LGPD implementation. In addition, we also investigated the perception of an agile team regarding the practices, techniques, and tools previously cited by practitioners as potential solutions for use in this context, along with techniques already in use in the current context. We have conducted a systematic literature review (SLR) and selected 36 primary studies. Furthermore, we have conducted a survey with 53 IT practitioners and semi-structured interviews with ten practitioners. The LGPD principles are known by most agile teams and are being implemented by the organizations, although the existing tools to support privacy requirements elicitation are still underused by agile teams. Moreover, agile teams consider that software requirements and software construction are the most impacted areas of knowledge by the LGPD, and most of them use user stories in privacy requirements elicitation. Our findings reveal that agile teams and Brazilian organizations are more concerned with user data privacy issues after the LGPD became effective. However, agile teams still face challenges in privacy requirements elicitation.
引用
收藏
页码:545 / 567
页数:23
相关论文
共 3 条
  • [1] Guidelines adopted by agile teams in privacy requirements elicitation after the Brazilian general data protection law (LGPD) implementation
    Edna Dias Canedo
    Angelica Toffano Seidel Calazans
    Ian Nery Bandeira
    Pedro Henrique Teixeira Costa
    Eloisa Toffano Seidel Masson
    Requirements Engineering, 2022, 27 : 545 - 567
  • [2] Agile Teams' Perception in Privacy Requirements Elicitation: LGPD's compliance in Brazil
    Canedo, Edna Dias
    Seidel Calazans, Angelica Toffano
    Cerqueira, Anderson Jefferson
    Teixeira Costa, Pedro Henrique
    Seidel Masson, Eloisa Toffano
    29TH IEEE INTERNATIONAL REQUIREMENTS ENGINEERING CONFERENCE (RE 2021), 2021, : 58 - 69
  • [3] A panorama of the implementation of the General Law for the Protection of Personal Data (LGPD) in Brazil: an exploratory survey
    Ferreira, Lamara
    Okano, Marcelo Tsuguio
    Aguiar, Fernanda
    Lobo dos Santos, Henry de Castro
    Ursini, Edson Luiz
    2022 IEEE 12TH ANNUAL COMPUTING AND COMMUNICATION WORKSHOP AND CONFERENCE (CCWC), 2022, : 723 - 729