Identifying Personal Data Processing for Code Review

01/04/2023
by   Feiyang Tang, et al.
0

Code review is a critical step in the software development life cycle, which assesses and boosts the code's effectiveness and correctness, pinpoints security issues, and raises its quality by adhering to best practices. Due to the increased need for personal data protection motivated by legislation, code reviewers need to understand where personal data is located in software systems and how it is handled. Although most recent work on code review focuses on security vulnerabilities, privacy-related techniques are not easy for code reviewers to implement, making their inclusion in the code review process challenging. In this paper, we present ongoing work on a new approach to identifying personal data processing, enabling developers and code reviewers in drafting privacy analyses and complying with regulations such as the General Data Protection Regulation (GDPR).

READ FULL TEXT

page 1

page 2

page 3

page 4

research
06/20/2023

Helping Code Reviewer Prioritize: Pinpointing Personal Data and its Processing

Ensuring compliance with the General Data Protection Regulation (GDPR) i...
research
07/10/2023

A Novel Approach to Identify Security Controls in Source Code

Secure by Design has become the mainstream development approach ensuring...
research
04/13/2023

Understanding issues related to personal data and data protection in open source projects on GitHub

Context: Data protection regulations such as the GDPR and the CCPA affec...
research
02/01/2023

Privacy Dashboards for Citizens and GDPR Services for Small Data Holders: A Literature Review

Citizens have gained many rights with the GDPR, e.g. the right to get a ...
research
04/10/2012

Publishing Identifiable Experiment Code And Configuration Is Important, Good and Easy

We argue for the value of publishing the exact code, configuration and d...
research
03/08/2019

The Seven Sins of Personal-Data Processing Systems under GDPR

In recent years, our society is being plagued by unprecedented levels of...
research
09/09/2022

Scalable Discovery and Continuous Inventory of Personal Data at Rest in Cloud Native Systems

Cloud native systems are processing large amounts of personal data throu...

Please sign up or login with your details

Forgot password? Click here to reset