Towards privacy compliance: A design science study in a small organization

被引:12
|
作者
Li, Ze Shi [1 ]
Werner, Colin [1 ]
Ernst, Neil [1 ]
Damian, Daniela [1 ]
机构
[1] Univ Victoria, Victoria, BC, Canada
关键词
Requirements engineering; Continuous software engineering; Privacy; GDPR; Design science; REQUIREMENTS; CHALLENGES; SECURITY; INTERNET;
D O I
10.1016/j.infsof.2022.106868
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Context: Complying with privacy regulations has taken on new importance with the introduction of the EU's General Data Protection Regulation (GDPR) and other privacy regulations. Privacy measures are becoming a paramount requirement demanding software organizations' attention as recent privacy breaches such as the Capital One data breach affected millions of customers. Software organizations, however, struggle with achieving privacy compliance. In particular, there is a lack of research into the organizational practices and challenges involved in compliance, particularly for small and medium enterprises (SMEs), which represent a sizeable portion of organizations. Many SMEs use a continuous software engineering (CSE) approach, which introduces additional adoption and application challenges. For example, the fast pace of CSE makes it harder for SMEs that are already more resource constrained to prioritize non-functional requirements such as privacy.Objective: This paper aims to fill a gap in the under-researched area of continuous compliance with privacy requirements in practice, by investigating how a continuous practicing SME dealt with GDPR compliance.Method: Using design science, we conducted an in-depth ethnographically informed study over the span of 16 months and iteratively developed two artifacts to help address the organization's challenges in addressing GDPR compliance.Results: We identified 3 main challenges that our collaborating organization experienced when trying to comply with the GDPR. To help mitigate the challenges, we developed two design science artifacts, which include a list of privacy requirements that operationalized the GDPR principles for automated verification, and an automated testing tool that helps to verify these privacy requirements. We validated these artifacts through close collaboration with our partner organization and applying our artifacts to the partner organization's system.Conclusions: We conclude with a discussion of opportunities and obstacles in leveraging CSE to achieve continuous compliance with the GDPR. We also highlight the importance of building a shared understanding of privacy non-functional requirements and how risk management plays an important role in an organization's GDPR compliance.
引用
收藏
页数:16
相关论文
共 50 条
  • [31] When privacy and utility are in harmony: towards better design of presence technologies
    Biehl, Jacob T.
    Rieffel, Eleanor G.
    Lee, Adam J.
    PERSONAL AND UBIQUITOUS COMPUTING, 2013, 17 (03) : 503 - 518
  • [32] Understanding the Implementation of Technical Measures in the Process of Data Privacy Compliance: A Qualitative Study
    Klymenko, Oleksandra
    Kosenkov, Oleksandr
    Meisenbacher, Stephen
    Elahidoost, Parisa
    Mendez, Daniel
    Matthes, Florian
    PROCEEDINGS OF THE16TH ACM/IEEE INTERNATIONAL SYMPOSIUM ON EMPIRICAL SOFTWARE ENGINEERING AND MEASUREMENT, ESEM 2022, 2022, : 261 - 271
  • [33] TOWARDS A UNIFIED THEORY OF PROPERTIES IN ENGINEERING DESIGN SCIENCE
    Suistoranta, Seppo
    DESIGN FOR HARMONIES, VOL 2: DESIGN THEORY AND RESEARCH METHODOLOGY, 2013,
  • [34] Towards Secure and Privacy-Preserving IoT Enabled Smart Home: Architecture and Experimental Study
    Abu-Tair, Mamun
    Djahel, Soufiene
    Perry, Philip
    Scotney, Bryan
    Zia, Unsub
    Carracedo, Jorge Martinez
    Sajjad, Ali
    SENSORS, 2020, 20 (21) : 1 - 14
  • [35] GDPR Compliance in the Design of the INFORM e-Learning Platform: a Case Study
    Vanezi, Evangelia
    Kouzapas, Dimitrios
    Kapitsaki, Georgia M.
    Costi, Theodora
    Yeratziotis, Alexandros
    Mettouris, Christos
    Philippou, Anna
    Papadopoulos, George A.
    2019 13TH INTERNATIONAL CONFERENCE ON RESEARCH CHALLENGES IN INFORMATION SCIENCE (RCIS), 2019, : 257 - +
  • [36] Integration of data science with product design towards data-driven design
    Liu, Ang
    Lu, Stephen
    Tao, Fei
    Anwer, Nabil
    CIRP ANNALS-MANUFACTURING TECHNOLOGY, 2024, 73 (02) : 509 - 532
  • [37] Data Privacy Act of 2012: A Case Study Approach to Philippine Government Agencies Compliance
    Ching, Michelle Renee D.
    Fabito, Bernie S.
    Celis, Nelson J.
    ADVANCED SCIENCE LETTERS, 2018, 24 (10) : 7042 - 7046
  • [38] HIPAA Privacy Rule compliance: An interpretive study using Norman's action theory
    Liginlal, Divakaran
    Sim, Inkook
    Khansa, Lara
    Fearn, Paul
    COMPUTERS & SECURITY, 2012, 31 (02) : 206 - 220
  • [39] Defining Requirements Strategies in Agile: A Design Science Research Study
    Muhammad, Amna Pir
    Knauss, Eric
    Batsaikhan, Odzaya
    El Haskouri, Nassiba
    Lin, Yi-Chun
    Knauss, Alessia
    PRODUCT-FOCUSED SOFTWARE PROCESS IMPROVEMENT, PROFES 2022, 2022, 13709 : 73 - 89