4.6 Review

Translating Privacy Design Principles Into Human-Centered Software Lifecycle: A Literature Review

Publisher

TAYLOR & FRANCIS INC
DOI: 10.1080/10447318.2023.2219964

Keywords

Privacy by design; privacy by default; privacy design strategies; human-centered design approach

Ask authors/readers for more resources

The study addresses the importance of considering privacy principles in software development and the lack of practical guidance from data protection regulations. It provides insights into how privacy principles translate into software requirements and how they integrate into a Human-Centred Design process.
Companies and organizations involved in software development are stimulated and often obliged to consider procedures and technical solutions to guarantee data privacy and protection from the early phases of the software lifecycle. In addition, by default, personal data might be processed with the highest privacy protection level. These two requirements are Privacy by Design and Privacy by Default principles. Their importance has grown quickly in the last few years, as demonstrated by data protection regulations, like GDPR and PIPEDA, which include them as an important part of some of their articles. However, such regulations do not provide any practical or concrete indications of software requirements, and developers often lack adequate knowledge to understand the privacy prescriptions expressed in legal language. This study addresses these limitations by presenting a systematic and rigorous literature review that aims to answer the following research questions: (RQ1) How do Privacy-By-Design and Privacy-By-Default principles translate into software requirements? and (RQ2) How Privacy-By-Design and Privacy-By-Default principles integrate into a Human-Centred Design process? For RQ1, the analysis of the resulting publications led to identifying several software requirements and business processes organized along 8 data-oriented and process-oriented privacy design strategies. For RQ2, the analysis of the retrieved publications provided a comprehensive view of the HCI methodologies adopted to comply with privacy requirements identified current shortcomings, and proposed future research directions. The results have been distilled into an initial framework that may aid the development of software that must comply with such principles and aims to integrate them into an HCD process.

Authors

I am an author on this paper
Click your name to claim this paper and add it to your profile.

Reviews

Primary Rating

4.6
Not enough ratings

Secondary Ratings

Novelty
-
Significance
-
Scientific rigor
-
Rate this paper

Recommended

No Data Available
No Data Available