Understanding the GDPR from a requirements engineering perspective—a systematic mapping study on regulatory data protection requirements

Author:

Negri-Ribalta ClaudiaORCID,Lombard-Platet Marius,Salinesi Camille

Abstract

AbstractData protection compliance is critical from a requirements engineering (RE) perspective, both from a software development lifecycle (SDLC) perspective and regulatory compliance. Not including these requirements from the early phases of the SDLC can prove costly and challenging afterward. The general data protection regulation (GDPR) from the European Union (EU) sets a list of requirements that organizations working within its scope should satisfy. However, these requirements are complex to work with, as legal prose tends to be vague and imprecise, and not all requirements have received the same attention from researchers. This study aims to identify the research published in RE for helping compliance with regulatory data protection requirements. We gathered and analyzed 90 articles from 2016 to 2022 through a systematic mapping study. We analyzed key trends in the sample, such as year of publication, publication venue, type of research, interdisciplinarity in the author’s background, GDPR focus of compliance element, and type of proposal. Our main findings show ongoing interest, mostly published in conferences, in achieving overall compliance with the GDPR and consent as the most popular topics. Other topics, such as cookies or children’s data, did not receive significant attention. Research over the whole RE process has been done. 20 (22%) of the papers have authors affiliated with non-computer science; however, most research seems not interdisciplinary. We finally discuss gaps in the literature, possible future areas of research, and the importance of interdisciplinary research for regulatory data protection requirements in RE.

Funder

Horizon 2020 Framework Programme

Publisher

Springer Science and Business Media LLC

Reference61 articles.

1. European Union: Regulation (EU) 2016/678 of the European Parliament and of the Council—General Data Protection Regulation

2. Data Protection Commission: Data Protection Commission announces conclusion of two inquiries into Meta Ireland | 04/01/2023 | Data Protection Commission. https://dataprotection.ie/en/news-media/data-protection-commission-announces-conclusion-two-inquiries-meta-ireland. Accessed 27 Jan 2023

3. Schmidt A, Esser L (2022) Numbers and figures | GDPR Enforcement Tracker Report 2022. https://cms.law/en/fra/publication/gdpr-enforcement-tracker-report/numbers-and-figures. Accessed 27 Jan 2023

4. Breaux TD, Antón AI (2007) A systematic method for acquiring regulatory requirements: a frame-based approach. RHAS-6), Delhi, India

5. He Q, Antón AI et al (2003) A framework for modeling privacy requirements in role engineering. In: Proceedings of REFSQ, vol 3, pp 137–146

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3