Privacy by Design: Aligning GDPR and Software Engineering Specifications with a Requirements Engineering Approach
Oleksandr Kosenkov, Ehsan Zabardast, Davide Fucci, Daniel Mendez, Michael Unterkalmsteiner

TL;DR
This paper presents a requirements engineering approach that aligns GDPR legal concepts with software specifications to enhance privacy by design, addressing practical challenges faced by practitioners in achieving compliance.
Contribution
It introduces a novel modeling approach that captures GDPR legal content within requirements specifications to support transparency, traceability, and legal knowledge integration.
Findings
The approach supports capturing legal knowledge in specifications.
It enhances traceability and transparency in privacy requirements.
Practitioners find the approach suitable for practical GDPR compliance.
Abstract
Context: Consistent requirements and system specifications are essential for the compliance of software systems towards the General Data Protection Regulation (GDPR). Both artefacts need to be grounded in the original text and conjointly assure the achievement of privacy by design (PbD). Objectives: There is little understanding of the perspectives of practitioners on specification objectives and goals to address PbD. Existing approaches do not account for the complex intersection between problem and solution space expressed in GDPR. In this study we explore the demand for conjoint requirements and system specification for PbD and suggest an approach to address this demand. Methods: We reviewed secondary and related primary studies and conducted interviews with practitioners to (1) investigate the state-of-practice and (2) understand the underlying specification objectives and goals…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
