Agile Teams’ Perception in Privacy Requirements Elicitation: LGPD’s compliance in Brazil

E. Canedo, A. Calazans, Anderson Jefferson Cerqueira, P. Costa, E. Masson
{"title":"Agile Teams’ Perception in Privacy Requirements Elicitation: LGPD’s compliance in Brazil","authors":"E. Canedo, A. Calazans, Anderson Jefferson Cerqueira, P. Costa, E. Masson","doi":"10.1109/RE51729.2021.00013","DOIUrl":null,"url":null,"abstract":"Context: The implementation of the Brazilian General Data Protection Law (LGPD) may impact activities carried out by the software development teams. It is necessary for developers to know the existing techniques and tools to carry out privacy requirements elicitation. Objectives: In this research, we investigated the perception of agile software development team members from different organizations, regarding the impact that LGPD will have on the activities of the software development process. Methods: We conducted an online survey and a systematic literature review to identify the techniques, methodologies and tools used in the literature to perform privacy requirements elicitation in the context of Agile Software Development (ASD). In addition, we also investigated the perception of an agile team from a Federal Public Administration organization regarding the impacts of the obligation to develop software in accordance with the LGPD. Results: Our findings reveal that agile teams know the concepts related to data privacy legislation, but they do not use the techniques proposed in the literature to perform privacy requirements elicitation. In addition, agile teams face problems with outdated software requirements specifications and stakeholders’ lack of knowledge regarding data privacy. Conclusions: Agile teams need to improve their knowledge on privacy requirements.","PeriodicalId":440285,"journal":{"name":"2021 IEEE 29th International Requirements Engineering Conference (RE)","volume":"109 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-09-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"7","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 IEEE 29th International Requirements Engineering Conference (RE)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/RE51729.2021.00013","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 7

Abstract

Context: The implementation of the Brazilian General Data Protection Law (LGPD) may impact activities carried out by the software development teams. It is necessary for developers to know the existing techniques and tools to carry out privacy requirements elicitation. Objectives: In this research, we investigated the perception of agile software development team members from different organizations, regarding the impact that LGPD will have on the activities of the software development process. Methods: We conducted an online survey and a systematic literature review to identify the techniques, methodologies and tools used in the literature to perform privacy requirements elicitation in the context of Agile Software Development (ASD). In addition, we also investigated the perception of an agile team from a Federal Public Administration organization regarding the impacts of the obligation to develop software in accordance with the LGPD. Results: Our findings reveal that agile teams know the concepts related to data privacy legislation, but they do not use the techniques proposed in the literature to perform privacy requirements elicitation. In addition, agile teams face problems with outdated software requirements specifications and stakeholders’ lack of knowledge regarding data privacy. Conclusions: Agile teams need to improve their knowledge on privacy requirements.
敏捷团队在隐私需求引出中的感知:巴西LGPD的遵从性
背景:巴西通用数据保护法(LGPD)的实施可能会影响软件开发团队开展的活动。开发人员有必要了解现有的技术和工具来进行隐私需求挖掘。目的:在本研究中,我们调查了来自不同组织的敏捷软件开发团队成员对LGPD对软件开发过程活动的影响的看法。方法:我们进行了一项在线调查和系统的文献综述,以确定文献中用于在敏捷软件开发(ASD)的背景下执行隐私需求引出的技术、方法和工具。此外,我们还调查了来自联邦公共管理组织的敏捷团队对按照LGPD开发软件的义务的影响的看法。结果:我们的研究结果表明,敏捷团队知道与数据隐私立法相关的概念,但他们没有使用文献中提出的技术来进行隐私需求引出。此外,敏捷团队还面临着过时的软件需求规范和利益相关者缺乏数据隐私知识的问题。结论:敏捷团队需要提高他们对隐私需求的了解。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信