Privacy engineering, as an emerging field of research and practice, comprises the technical capabilities and management processes needed to implement, deploy, and operate privacy features and controls in working systems. For that, software practitioners and other stakeholders in software companies need to work cooperatively toward building privacy-preserving businesses and engineering solutions. Significant research has been done to understand the software practitioners' perceptions of information privacy, but more emphasis should be given to the uptake of concrete privacy engineering components. This research delves into the software practitioners' perspectives and mindset, organisational aspects, and current practices on privacy and its engineering processes. A total of 30 practitioners from nine countries and backgrounds were interviewed, sharing their experiences and voicing their opinions on a broad range of privacy topics. The thematic analysis methodology was adopted to code the interview data qualitatively and construct a rich and nuanced thematic framework. As a result, we identified three critical interconnected themes that compose our thematic framework for privacy engineering "in the wild": (1) personal privacy mindset and stance, categorised into practitioners' privacy knowledge, attitudes and behaviours; (2) organisational privacy aspects, such as decision-power and positive and negative examples of privacy climate; and, (3) privacy engineering practices, such as procedures and controls concretely used in the industry. Among the main findings, this study provides many insights about the state-of-the-practice of privacy engineering, pointing to a positive influence of privacy laws (e.g., EU General Data Protection Regulation) on practitioners' behaviours and organisations' cultures. Aspects such as organisational privacy culture and climate were also confirmed to have [...].
翻译:摘要:隐私工程作为研究与实践的新兴领域,涵盖在运行系统中实施、部署及运作隐私功能与控制所需的技术能力与管理流程。为此,软件公司中的从业者及其他利益相关者需协同合作,以构建注重隐私保护的业务和工程解决方案。已有大量研究关注软件从业者对信息隐私的认知,但应更加重视具体隐私工程组件的采纳。本研究深入探讨软件从业者对隐私及其工程过程的观点与心态、组织层面因素及当前实践。我们访谈了来自9个国家、具有不同背景的共30名从业者,他们分享了广泛隐私议题的经验与见解。采用主题分析法对访谈数据进行定性编码,构建了丰富细致的主题框架。最终,我们识别出构成现实世界中隐私工程主题框架的三个相互关联的关键主题:(1)个人隐私心态与立场,细分为从业者的隐私知识、态度与行为;(2)组织隐私层面,如决策权及隐私氛围的正面与负面案例;(3)隐私工程实践,例如行业中具体使用的流程与控制措施。本研究的主要发现揭示了隐私工程实践现状,指出隐私法规(如欧盟《通用数据保护条例》)对从业者行为及组织文化具有积极影响。此外,研究证实组织隐私文化与氛围等因素……