A Taxonomy for Mining and Classifying Privacy Requirements in Issue Reports

Digital and physical footprints are a trail of user activities collected over the use of software applications and systems. As software becomes ubiquitous, protecting user privacy has become challenging. With the increasing of user privacy awareness and advent of privacy regulations and policies, there is an emerging need to implement software systems that enhance the protection of personal data processing. However, existing privacy regulations and policies only provide high-level principles which are difficult for software engineers to design and implement privacy-aware systems. In this paper, we develop a taxonomy that provides a comprehensive set of privacy requirements based on two well-established and widely-adopted privacy regulations and frameworks, the General Data Protection Regulation (GDPR) and the ISO/IEC 29100. These requirements are refined into a level that is implementable and easy to understand by software engineers, thus supporting them to attend to existing regulations and standards. We have also performed a study on how two large open-source software projects (Google Chrome and Moodle) address the privacy requirements in our taxonomy through mining their issue reports. The paper discusses how the collected issues were classified, and presents the findings and insights generated from our study.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
12/28/2021

Mining and Classifying Privacy and Data Protection Requirements in Issue Reports

Digital and physical footprints are a trail of user activities collected...
research
07/26/2023

Sources of Opacity in Computer Systems: Towards a Comprehensive Taxonomy

Modern computer systems are ubiquitous in contemporary life yet many of ...
research
08/04/2018

Understanding Software Developers' Approach towards Implementing Data Minimization

Data Minimization (DM) is a privacy practice that requires minimizing th...
research
06/08/2020

Engineering Privacy by Design: Are engineers ready to live up to the challenge?

Organizations struggle to comply with legal requirements as well as cust...
research
10/18/2022

Privacy Explanations - A Means to End-User Trust

Software systems are ubiquitous, and their use is ingrained in our every...
research
11/24/2020

Transforming Data Flow Diagrams for Privacy Compliance (Long Version)

Recent regulations, such as the European General Data Protection Regulat...
research
08/11/2020

Towards Software-Defined Data Protection: GDPR Compliance at the Storage Layer is Within Reach

Enforcing data protection and privacy rules within large data processing...

Please sign up or login with your details

Forgot password? Click here to reset