Towards privacy compliance: A design science study in a small organization

被引:12
|
作者
Li, Ze Shi [1 ]
Werner, Colin [1 ]
Ernst, Neil [1 ]
Damian, Daniela [1 ]
机构
[1] Univ Victoria, Victoria, BC, Canada
关键词
Requirements engineering; Continuous software engineering; Privacy; GDPR; Design science; REQUIREMENTS; CHALLENGES; SECURITY; INTERNET;
D O I
10.1016/j.infsof.2022.106868
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Context: Complying with privacy regulations has taken on new importance with the introduction of the EU's General Data Protection Regulation (GDPR) and other privacy regulations. Privacy measures are becoming a paramount requirement demanding software organizations' attention as recent privacy breaches such as the Capital One data breach affected millions of customers. Software organizations, however, struggle with achieving privacy compliance. In particular, there is a lack of research into the organizational practices and challenges involved in compliance, particularly for small and medium enterprises (SMEs), which represent a sizeable portion of organizations. Many SMEs use a continuous software engineering (CSE) approach, which introduces additional adoption and application challenges. For example, the fast pace of CSE makes it harder for SMEs that are already more resource constrained to prioritize non-functional requirements such as privacy.Objective: This paper aims to fill a gap in the under-researched area of continuous compliance with privacy requirements in practice, by investigating how a continuous practicing SME dealt with GDPR compliance.Method: Using design science, we conducted an in-depth ethnographically informed study over the span of 16 months and iteratively developed two artifacts to help address the organization's challenges in addressing GDPR compliance.Results: We identified 3 main challenges that our collaborating organization experienced when trying to comply with the GDPR. To help mitigate the challenges, we developed two design science artifacts, which include a list of privacy requirements that operationalized the GDPR principles for automated verification, and an automated testing tool that helps to verify these privacy requirements. We validated these artifacts through close collaboration with our partner organization and applying our artifacts to the partner organization's system.Conclusions: We conclude with a discussion of opportunities and obstacles in leveraging CSE to achieve continuous compliance with the GDPR. We also highlight the importance of building a shared understanding of privacy non-functional requirements and how risk management plays an important role in an organization's GDPR compliance.
引用
收藏
页数:16
相关论文
共 50 条
  • [21] Towards controlled-privacy in e-health: A comparative study
    Sadki, Souad
    El Bakkali, Hanan
    2014 INTERNATIONAL CONFERENCE ON MULTIMEDIA COMPUTING AND SYSTEMS (ICMCS), 2014, : 680 - 685
  • [22] A Framework for Privacy and Security Requirements Analysis and Conflict Resolution for Supporting GDPR Compliance Through Privacy-by-Design
    Alkubaisy, Duaa
    Piras, Luca
    Al-Obeidallah, Mohammed Ghazi
    Cox, Karl
    Mouratidis, Haralambos
    EVALUATION OF NOVEL APPROACHES TO SOFTWARE ENGINEERING (ENASE 2021), 2022, 1556 : 67 - 87
  • [23] A systematic methodology for privacy impact assessments: a design science approach
    Oetzel, Marie Caroline
    Spiekermann, Sarah
    EUROPEAN JOURNAL OF INFORMATION SYSTEMS, 2014, 23 (02) : 126 - 150
  • [24] Towards privacy-driven design of a dynamic carpooling system
    Friginal, Jesus
    Gambs, Sebastien
    Guiochet, Jeremie
    Killijian, Marc-Olivier
    PERVASIVE AND MOBILE COMPUTING, 2014, 14 : 71 - 82
  • [25] BPM Supported Privacy by Design for Cross-Organization Business Processes
    Stevovic, Jovan
    Sottovia, Paolo
    Marchese, Maurizio
    Armellin, Giampaolo
    SERVICE-ORIENTED COMPUTING - ICSOC 2014 WORKSHOPS, 2015, 8954 : 71 - 83
  • [26] Towards a design science of ethical decision support
    Mathieson, Kieran
    JOURNAL OF BUSINESS ETHICS, 2007, 76 (03) : 269 - 292
  • [27] Towards a Design Science of Ethical Decision Support
    Kieran Mathieson
    Journal of Business Ethics, 2007, 76 : 269 - 292
  • [28] A BERT-based Empirical Study of Privacy Policies' Compliance with GDPR
    Zhang, Lu
    Moukafih, Nabil
    Alamri, Hamad
    Epiphaniou, Gregory
    Maple, Carsten
    2023 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY, CNS, 2023,
  • [29] Towards Design and Development of a Data Security and Privacy Risk Management Framework for WBAN Based Healthcare Applications
    Paul, Pangkaj Chandra
    Loane, John
    McCaffery, Fergal
    Regan, Gilbert
    APPLIED SYSTEM INNOVATION, 2021, 4 (04)
  • [30] When privacy and utility are in harmony: towards better design of presence technologies
    Jacob T. Biehl
    Eleanor G. Rieffel
    Adam J. Lee
    Personal and Ubiquitous Computing, 2013, 17 : 503 - 518