Dias Canedo Edna, Toffano Seidel Calazans Angelica, Toffano Seidel Masson Eloisa, Teixeira Costa Pedro Henrique, Lima Fernanda
Department of Computer Science, University of Brasília (UnB), P.O. Box 4466, Brasília-DF 70910-900, Brazil.
University center-UniCEUB, Brasília-DF 70790-075, Brazil.
Entropy (Basel). 2020 Apr 10;22(4):429. doi: 10.3390/e22040429.
During software development activities, it is important for Information and Communication Technology (ICT) practitioners to know and understand practices and guidelines regarding information privacy, as software requirements must comply with data privacy laws and members of development teams should know current legislation related to the protection of personal data. In order to gain a better understanding on how industry ICT practitioners perceive the practical relevance of software privacy and privacy requirements and how these professionals are implementing data privacy concepts, we conducted a survey with ICT practitioners from software development organizations to get an overview of how these professionals are implementing data privacy concepts during software design. We performed a systematic literature review to identify related works with software privacy and privacy requirements and what methodologies and techniques are used to specify them. In addition, we conducted a survey with ICT practitioners from different organizations. Findings revealed that ICT practitioners lack a comprehensive knowledge of software privacy and privacy requirements and the Brazilian General Data Protection Law , nor they are able to work with the laws and guidelines governing data privacy. Organizations are demanded to define an approach to contextualize ICT practitioners with the importance of knowledge of software privacy and privacy requirements, as well as to address them during software development, since LGPD must change the way teams work, as a number of features and controls regarding consent, documentation, and privacy accountability will be required.
在软件开发活动中,对于信息通信技术(ICT)从业者而言,了解和理解有关信息隐私的实践与准则非常重要,因为软件需求必须符合数据隐私法,并且开发团队成员应该知晓与个人数据保护相关的现行法规。为了更好地了解行业ICT从业者如何看待软件隐私和隐私要求的实际相关性,以及这些专业人员如何实施数据隐私概念,我们对来自软件开发组织的ICT从业者进行了一项调查,以了解这些专业人员在软件设计过程中是如何实施数据隐私概念的。我们进行了系统的文献综述,以确定与软件隐私和隐私要求相关的作品,以及用于指定这些要求的方法和技术。此外,我们对来自不同组织的ICT从业者进行了一项调查。研究结果表明,ICT从业者缺乏对软件隐私和隐私要求以及巴西通用数据保护法的全面了解,他们也无法依据数据隐私相关的法律和准则开展工作。各组织需要定义一种方法,让ICT从业者了解软件隐私和隐私要求知识的重要性,并在软件开发过程中加以应对,因为巴西通用数据保护法必须改变团队的工作方式,因为在同意、文档记录和隐私问责方面需要一些功能和控制措施。