论文标题

为什么开发人员在开发保护隐私软件系统时会努力将GDPR付诸实践?

Why are Developers Struggling to Put GDPR into Practice when Developing Privacy-Preserving Software Systems?

论文作者

Alhazmi, Abdulrahman, Arachchilage, Nalin Asanka Gamagedara

论文摘要

软件应用程序的使用是不可避免的,因为它们为用户提供了不同的服务。该软件应用程序收集,存储用户的数据,有时甚至在未经用户同意的情况下与第三方共享。可以说,软件开发人员不会在开发的软件应用程序中实施隐私,也不会考虑GDPR(一般数据保护法)法律。未能做到这一点,可能会导致打开隐私漏洞的软件应用程序(例如数据泄露)。 GDPR法律为开发人员和组织提供了一套指南,以与软件应用程序进行交互时如何保护他们的数据。先前的研究试图调查将隐私嵌入软件系统中的阻碍开发人员。但是,没有关于为什么他们无法开发隐私的系统来考虑GDPR的详细调查,这对于开发保留隐私的软件应用程序至关重要。因此,本文研究了阻碍软件开发人员在板上实施软件应用程序的问题。我们的研究结果表明,开发人员不熟悉GDPR原则。即使是其中的一些人,他们都缺乏对GDPR原则的了解及其在开发保护隐私软件系统时使用的技术

The use of software applications is inevitable as they provide different services to users. The software applications collect, store users' data, and sometimes share with the third party, even without the user consent. One can argue that software developers do not implement privacy into the software applications they develop or take GDPR (General Data Protection Law) law into account. Failing to do this, may lead to software applications that open up privacy breaches (e.g. data breach). The GDPR law provides a set of guidelines for developers and organizations on how to protect user data when they are interacting with software applications. Previous research has attempted to investigate what hinders developers from embedding privacy into software systems. However, there has been no detailed investigation on why they cannot develop privacy-preserving systems taking GDPR into consideration, which is imperative to develop software applications that preserve privacy. Therefore, this paper investigates the issues that hinder software developers from implementing software applications taking GDPR law on-board. Our study findings revealed that developers are not familiar with GDPR principles. Even some of them are, they lack knowledge of the GDPR principles and their techniques to use when developing privacy-preserving software systems

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源