Abstract
AbstractPrivacy by design is nowadays recognized as essential in bringing data privacy into software systems. However, developers still face many challenges in reconciling privacy and software requirements and implementing privacy protections in software systems. One emerging trend is the adoption of microservices architectures—they bring in some qualities that can benefit privacy by design. The main goal of this study is to adapt privacy by design to the qualities brought by microservices. The main focus is at the architectural level, where the main structural decisions are made. A systematic literature review is adopted to identify a set of privacy models that underscore significant differences in software systems’ protection using microservices. From the literature review, a decision framework is developed. The decision framework provides guidance and supports design decisions in implementing data privacy using microservices. The framework helps select and integrate different privacy models. An illustration of using the framework, which considers the design of an electronic voting system, is provided. This study contributes to closing the gap between regulation and implementation through design, where decisions related to data privacy are integrated with decisions on architecting systems using microservices.
Publisher
Springer Science and Business Media LLC
Reference89 articles.
1. Alhazmi, A., Arachchilage, N.: I’m all ears! Listening to software developers on putting GDPR principles into software development practice. Personal. Uniquit. Comput. 25, 879–892 (2021)
2. Saltarella, M., Desolda, G., Lanzilotti, R., Barletta, V.: Translating privacy design principles into human-centered Software Lifecycle: A literature review. Int. J. Human–Computer Interact. 1–19. (2023)
3. EU, General Data Protection Regulation (GDPR): Official J. Eur. Union L. 119, 1 (2016)
4. State of California, California Consumer Privacy Act (CCPA), State of California - Department of Justice - Office of the Attorney General: (2024). https://oag.ca.gov/privacy/ccpa (accessed November 16, 2023)
5. Spiekermann, S.: The challenges of privacy by design. Commun. ACM. 55, 38–40 (2012). https://doi.org/10.1145/2209249.2209263