GDPR Compliance in the Context of Continuous Integration

02/17/2020
by   Ze Shi Li, et al.
0

The enactment of the General Data Protection Regulation (GDPR) in 2018 forced any organization that collects and/or processes EU-based personal data to comply with stringent privacy regulations. Software organizations have struggled to achieve GDPR compliance both before and after the GDPR deadline. While some studies have relied on surveys or interviews to find general implications of the GDPR, there is a lack of in-depth studies that investigate compliance practices and compliance challenges of software organizations. In particular, there is no information on small and medium enterprises (SMEs), which represent the majority of organizations in the EU, nor on organizations that practice continuous integration. Using design science methodology, we conducted an in-depth study over the span of 20 months regarding GDPR compliance practices and challenges in collaboration with a small, startup organization. We first identified our collaborator's business problems and then iteratively developed two artifacts to address those problems: a set of operationalized GDPR principles, and an automated GDPR tool that tests those GDPR-derived privacy requirements. This design science approach resulted in four implications for research and for practice. For example, our research reveals that GDPR regulations can be partially operationalized and tested through automated means, which improves compliance practices, but more research is needed to create more efficient and effective means to disseminate and manage GDPR knowledge among software developers.

READ FULL TEXT
research
03/07/2021

Uncovering the Benefits and Challenges of Continuous Integration Practices

In 2006, Fowler and Foemmel defined ten core Continuous Integration (CI)...
research
07/23/2020

Model Driven Engineering for Data Protection and Privacy: Application and Experience with GDPR

In Europe and indeed worldwide, the General Data Protection Regulation (...
research
10/11/2017

Understanding Organizational Approach towards End User Privacy

End user privacy is a critical concern for all organizations that collec...
research
03/25/2020

Norms and Sanctions as a Basis for Promoting Cybersecurity Practices

Many cybersecurity breaches occur due to users not following good cybers...
research
10/06/2021

Trustworthy Artificial Intelligence and Process Mining: Challenges and Opportunities

The premise of this paper is that compliance with Trustworthy AI governa...
research
08/22/2018

Are we there yet? Understanding the challenges faced in complying with the General Data Protection Regulation (GDPR)

The EU General Data Protection Regulation (GDPR), enforced from 25th May...
research
05/19/2022

An Empirical Evaluation of the Implementation of the California Consumer Privacy Act (CCPA)

On January 1, 2020, California passed the California Consumer Privacy Ac...

Please sign up or login with your details

Forgot password? Click here to reset