An Exploratory Mixed-Methods Study on General Data Protection Regulation (GDPR) Compliance in Open-Source Software
Lucas Franke, Huayu Liang, Sahar Farzanehpour, Aaron Brantly, and James C. Davis, Chris Brown

TL;DR
This study investigates how GDPR impacts open-source software development through surveys and repository analysis, revealing increased development activity, challenges in compliance, and negative developer perceptions, highlighting the need for supportive tools and resources.
Contribution
It provides the first empirical insights into GDPR's effects on open-source development, combining survey data and repository metrics to identify key challenges and developer perceptions.
Findings
GDPR complicates open-source development processes.
Developers perceive GDPR compliance as challenging and costly.
GDPR-related pull requests show increased coding and review activity.
Abstract
Background: Governments worldwide are considering data privacy regulations. These laws, e.g. the European Union's General Data Protection Regulation (GDPR), require software developers to meet privacy-related requirements when interacting with users' data. Prior research describes the impact of such laws on software development, but only for commercial software. Open-source software is commonly integrated into regulated software, and thus must be engineered or adapted for compliance. We do not know how such laws impact open-source software development. Aims: To understand how data privacy laws affect open-source software development. We studied the European Union's GDPR, the most prominent such law. We investigated how GDPR compliance activities influence OSS developer activity (RQ1), how OSS developers perceive fulfilling GDPR requirements (RQ2), the most challenging GDPR…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsPrivacy, Security, and Data Protection
