Table of Contents
Fetching ...

Privacy by Design: Aligning GDPR and Software Engineering Specifications with a Requirements Engineering Approach

Oleksandr Kosenkov, Ehsan Zabardast, Davide Fucci, Daniel Mendez, Michael Unterkalmsteiner

TL;DR

This work addresses the challenge of embedding GDPR-driven privacy by design into software engineering by proposing a conjoint requirements and system specification (R&S) approach anchored in GDPR content. It combines a structured literature review, a candidate approach grounded in a legal-object content model, and semi-structured practitioner interviews to identify specification objectives and assess practical usefulness. The study identifies five specification objectives—capturing legal knowledge, traceability, separation of concerns, transparency, and system flexibility—and demonstrates that reflecting legal knowledge in R&S specifications can improve PbD traceability and communication, while revealing challenges in operationalizing the approach. The findings advocate for addressing GDPR demands across abstraction levels in the engineering lifecycle and call for further empirical work and industrial deployment to operationalize the method and extend it to related regulations. Overall, the research contributes a systematic, GDPR-grounded content-model approach to jointly develop R&S specifications for PbD and provides initial evidence on its practicality and limitations in industry.

Abstract

Context: Consistent requirements and system specifications are essential for the compliance of software systems towards the General Data Protection Regulation (GDPR). Both artefacts need to be grounded in the original text and conjointly assure the achievement of privacy by design (PbD). Objectives: There is little understanding of the perspectives of practitioners on specification objectives and goals to address PbD. Existing approaches do not account for the complex intersection between problem and solution space expressed in GDPR. In this study we explore the demand for conjoint requirements and system specification for PbD and suggest an approach to address this demand. Methods: We reviewed secondary and related primary studies and conducted interviews with practitioners to (1) investigate the state-of-practice and (2) understand the underlying specification objectives and goals (e.g., traceability). We developed and evaluated an approach for requirements and systems specification for PbD, and evaluated it against the specification objectives. Results: The relationship between problem and solution space, as expressed in GDPR, is instrumental in supporting PbD. We demonstrate how our approach, based on the modeling GDPR content with original legal concepts, contributes to specification objectives of capturing legal knowledge, supporting specification transparency, and traceability. Conclusion: GDPR demands need to be addressed throughout different levels of abstraction in the engineering lifecycle to achieve PbD. Legal knowledge specified in the GDPR text should be captured in specifications to address the demands of different stakeholders and ensure compliance. While our results confirm the suitability of our approach to address practical needs, we also revealed specific needs for the future effective operationalization of the approach.

Privacy by Design: Aligning GDPR and Software Engineering Specifications with a Requirements Engineering Approach

TL;DR

This work addresses the challenge of embedding GDPR-driven privacy by design into software engineering by proposing a conjoint requirements and system specification (R&S) approach anchored in GDPR content. It combines a structured literature review, a candidate approach grounded in a legal-object content model, and semi-structured practitioner interviews to identify specification objectives and assess practical usefulness. The study identifies five specification objectives—capturing legal knowledge, traceability, separation of concerns, transparency, and system flexibility—and demonstrates that reflecting legal knowledge in R&S specifications can improve PbD traceability and communication, while revealing challenges in operationalizing the approach. The findings advocate for addressing GDPR demands across abstraction levels in the engineering lifecycle and call for further empirical work and industrial deployment to operationalize the method and extend it to related regulations. Overall, the research contributes a systematic, GDPR-grounded content-model approach to jointly develop R&S specifications for PbD and provides initial evidence on its practicality and limitations in industry.

Abstract

Context: Consistent requirements and system specifications are essential for the compliance of software systems towards the General Data Protection Regulation (GDPR). Both artefacts need to be grounded in the original text and conjointly assure the achievement of privacy by design (PbD). Objectives: There is little understanding of the perspectives of practitioners on specification objectives and goals to address PbD. Existing approaches do not account for the complex intersection between problem and solution space expressed in GDPR. In this study we explore the demand for conjoint requirements and system specification for PbD and suggest an approach to address this demand. Methods: We reviewed secondary and related primary studies and conducted interviews with practitioners to (1) investigate the state-of-practice and (2) understand the underlying specification objectives and goals (e.g., traceability). We developed and evaluated an approach for requirements and systems specification for PbD, and evaluated it against the specification objectives. Results: The relationship between problem and solution space, as expressed in GDPR, is instrumental in supporting PbD. We demonstrate how our approach, based on the modeling GDPR content with original legal concepts, contributes to specification objectives of capturing legal knowledge, supporting specification transparency, and traceability. Conclusion: GDPR demands need to be addressed throughout different levels of abstraction in the engineering lifecycle to achieve PbD. Legal knowledge specified in the GDPR text should be captured in specifications to address the demands of different stakeholders and ensure compliance. While our results confirm the suitability of our approach to address practical needs, we also revealed specific needs for the future effective operationalization of the approach.
Paper Structure (72 sections, 2 figures, 5 tables)

This paper contains 72 sections, 2 figures, 5 tables.

Figures (2)

  • Figure 1: Summary of the methodology applied in this study. We annotate each step of the method execution and refer to them in the text of the manuscript.
  • Figure 2: Left: Conceptual model underlying our approach to R&S specification for GDPR compliance. Right: Example of the text of excerpts from GDPR Art. 4 and 6 annotated following the conceptual model and the resulting R&S specification content model.