Privacy Engineering in the Wild: Understanding the Practitioners' Mindset, Organisational Culture, and Current Practices

11/16/2022
by   Leonardo Horn Iwaya, et al.
0

Privacy engineering, as an emerging field of research and practice, comprises the technical capabilities and management processes needed to implement, deploy, and operate privacy features and controls in working systems. For that, software practitioners and other stakeholders in software companies need to work cooperatively toward building privacy-preserving businesses and engineering solutions. Significant research has been done to understand the software practitioners' perceptions of information privacy, but more emphasis should be given to the uptake of concrete privacy engineering components. This research delves into the software practitioners' perspectives and mindset, organisational aspects, and current practices on privacy and its engineering processes. A total of 30 practitioners from various countries and backgrounds were interviewed, sharing their experiences and voicing their opinions on a broad range of privacy topics. The thematic analysis methodology was adopted to code the interview data qualitatively and construct a rich and nuanced thematic framework. As a result, we identified three critical interconnected themes that compose our thematic framework for privacy engineering "in the wild": (1) personal privacy mindset and stance, categorised into practitioners' privacy knowledge, attitudes and behaviours; (2) organisational privacy culture, such as decision-power and positive and negative examples of privacy climate; and, (3) privacy engineering practices, such as procedures and controls concretely used in the industry. Among the main findings, this study provides many insights about the state-of-the-practice of privacy engineering, pointing to a positive influence of privacy laws (e.g., EU General Data Protection Regulation) on practitioners' behaviours and organisations' cultures. Aspects such as organisational privacy culture and climate were also confirmed to [...]

READ FULL TEXT

page 9

page 23

research
07/16/2020

Privacy Engineering Meets Software Engineering. On the Challenges of Engineering Privacy ByDesign

Current day software development relies heavily on the use of service ar...
research
09/12/2020

Designing a Serious Game: Teaching Developers to Embed Privacy into Software Systems

Software applications continue to challenge user privacy when users inte...
research
09/16/2021

The Influence of Human Aspects on Requirements Engineering: Software Practitioners Perspective

Requirements Engineering (RE) is a process that requires high collaborat...
research
06/18/2020

Robotics Software Engineering: A Perspective from the Service Robotics Domain

Robots that support humans by performing useful tasks (a.k.a., service r...
research
09/06/2020

Data Visualization Practitioners' Perspectives on Chartjunk

Chartjunk is a popular yet contentious topic. Previous studies have show...
research
03/16/2021

No Intruder, no Validity: Evaluation Criteria for Privacy-Preserving Text Anonymization

For sensitive text data to be shared among NLP researchers and practitio...
research
11/30/2018

A Core Ontology for Privacy Requirements Engineering

Nowadays, most companies need to collect, store, and manage personal inf...

Please sign up or login with your details

Forgot password? Click here to reset