Score
Designs and evaluates technical and organizational systems, architectures, and processes to identify, quantify, and mitigate privacy risks across data lifecycles, including performing privacy risk assessments, privacy impact assessments, threat modeling, and mapping risks to privacy compliance frameworks and law. Builds or specifies privacy-preserving techniques and engineering solutions—such as data anonymization, privacy-by-design architectures, access and data-privacy controls, and confidential computing deployments—and operationalizes privacy and security compliance.
Smart home systems suffer from inadequate protection of user and device identity data privacy, coupled with fragmented threat analysis and risk management practices. Method: This paper proposes the first privacy engineering framework that centrally incorporates device identity privacy. It integrates Data Flow Diagrams (DFDs) with LINDDUN PRO for end-to-end threat modeling, and combines Privacy Impact Assessments (PIAs) with Privacy-Enhancing Technologies (PETs) to systematically identify, quantitatively assess, and prioritize privacy risks. Contributions: (1) It establishes— for the first time—the critical role of device identity privacy within smart home privacy engineering; (2) it introduces an actionable risk prioritization matrix and standardized mitigation strategies; and (3) it delivers implementable privacy governance pathways for device manufacturers, cloud service providers, end users, and regulatory authorities.
This study addresses the challenge of operationalizing GDPR compliance in software engineering—specifically, how to realize “Privacy by Design” (PbD) at the requirements and system specification levels while reconciling heterogeneous stakeholder interests and ensuring semantic consistency and traceability between legal provisions and technical specifications. We propose a formal modeling approach grounded in original legal concepts, systematically mapping GDPR articles to reusable privacy requirement patterns. Integrating systematic literature analysis, industry interviews, and requirements modeling, we develop a joint specification framework supporting cross-layer abstraction and transparent, bidirectional traceability. Empirical evaluation demonstrates that the framework significantly improves the accuracy of privacy requirement elicitation and the transparency of regulatory specification, thereby providing a scalable, methodology-driven foundation for law–technology co-governance.
This work addresses the practical adoption barriers of Privacy-Enhancing Technologies (PETs), which stem from their technical complexity and the fragmentation among engineering, legal, and business perspectives. To bridge these disciplinary divides, the paper innovatively integrates multidisciplinary viewpoints into a systematic requirements engineering framework. By formally modeling and specifying the diverse needs of developers, integrators, and adopters, the proposed approach effectively aligns cross-domain concerns. The resulting requirements engineering–driven framework not only fills a critical gap in multidisciplinary collaboration for PET deployment but also substantially enhances the efficiency and regulatory compliance of integrating PETs into software systems.
Developers face significant practical challenges in implementing data privacy regulations (e.g., GDPR, CPRA) and lack adequate automated tooling to support compliance. Method: We conducted a mixed-methods study with 68 software developers—including structured surveys, in-depth interviews, and statistical modeling—to systematically identify their core requirements for privacy-compliance tools and the factors influencing those needs. Contribution/Results: We find that developers strongly prefer integrated, context-aware tooling; moreover, those with greater privacy experience place higher emphasis on tool reliability and legal alignment. Our analysis reveals a statistically significant positive association between developers’ privacy expertise and their demand for sophisticated, regulation-aware tool features. This study is the first empirical investigation centered explicitly on developers’ privacy-compliance enablement needs, thereby filling a critical gap in the literature. The findings provide foundational, evidence-based guidance for designing next-generation, generative-AI–powered privacy compliance automation tools.
This study addresses the challenges posed by divergent and conflicting data protection regulations across jurisdictions, which hinder the early identification of compliance requirements in software development and often lead to costly rework and legal risks. Drawing on interviews with 70 legal experts from G20 and other countries, the research employs systematic content analysis and deductive qualitative methods to distill, for the first time from a legal expert perspective, both commonalities—such as consent—and key divergences—such as the right to be forgotten—across global data protection laws. These insights are innovatively operationalized into a comprehensive set of Data Protection Officer (DPO) user stories mapped to each phase of the software development lifecycle and enterprise architecture layers, significantly enhancing the actionable integration of compliance requirements into early-stage software engineering practices.
This study addresses the inadequate awareness of privacy protection principles—such as Privacy by Design and data minimization—among ERP system developers and consultants, which hinders compliance with regulations like the GDPR. For the first time, the Fogg Behavior Model (FBM) is introduced into the ERP domain, integrated with qualitative thematic analysis to systematically construct privacy-related behavior models for these two key stakeholder groups. The research uncovers the motivational drivers and implementation barriers underlying their privacy practices. By extending the applicability of FBM to enterprise software privacy governance, this work not only advances theoretical understanding but also offers actionable insights for designing targeted interventions to enhance privacy compliance in ERP ecosystems.
This study addresses the challenge of privacy communication in human–robot collaboration systems within Industry 5.0, where sensitive data monitoring raises significant privacy concerns that are often obscured by technical complexity, leading to mistrust and resistance among non-technical stakeholders. To bridge this gap, the authors propose a novel conceptual framework that integrates Privacy by Design principles with large language models (LLMs), leveraging LLMs for the first time in the requirements engineering process to automatically generate natural-language privacy reports tailored for non-technical audiences from representative human–robot monitoring scenarios. Evaluation across two industrial use cases demonstrates that the approach substantially enhances the comprehensibility of privacy information and supports informed decision-making, thereby addressing a critical accessibility gap in existing privacy communication mechanisms.
This study addresses the significant privacy risks children face when using large language model (LLM) applications, exacerbated by the absence of actionable design guidance in existing regulations. To bridge this gap, the work proposes the first comprehensive privacy-by-design framework that systematically integrates key privacy laws—including GDPR, COPPA, and PIPEDA—with children’s rights standards from the UNCRC and the Age Appropriate Design Code (AADC). The framework spans the entire LLM application lifecycle, embedding compliance and child-friendly mechanisms across data collection, model training, runtime monitoring, and ongoing validation. It synergistically combines privacy-enhancing technologies, organizational controls, and age-appropriate interaction design. Validation through an educational tutoring application demonstrates that the framework effectively mitigates privacy risks while ensuring regulatory compliance and robust protection of children’s digital rights.
This work addresses the challenge of aligning real-world data processing practices in distributed systems with the purpose limitation principle under the General Data Protection Regulation (GDPR). To this end, it introduces the first formal framework that integrates multiparty session types with GDPR compliance. The approach models data processing purposes as structured interaction protocols among participants, employing a process calculus enriched with private data semantics to capture system behavior. A novel type system is developed to enforce subject reduction and purpose fidelity, ensuring that runtime execution strictly adheres to declared purposes. Formal verification guarantees alignment between stated purposes and actual behavior. The framework’s effectiveness is demonstrated through its application to a healthcare system case study, offering an engineering-oriented theoretical foundation for privacy-by-design.