Privacy engineering, as an emerging field of research and practice, comprises the technical capabilities and management processes needed to implement, deploy, and operate privacy features and controls in working systems. For that, software practitioners and other stakeholders in software companies need to work cooperatively toward building privacy-preserving businesses and engineering solutions. Significant research has been done to understand the software practitioners' perceptions of information privacy, but more emphasis should be given to the uptake of concrete privacy engineering components. This research delves into the software practitioners' perspectives and mindset, organisational aspects, and current practices on privacy and its engineering processes. A total of 30 practitioners from various countries and backgrounds were interviewed, sharing their experiences and voicing their opinions on a broad range of privacy topics. The thematic analysis methodology was adopted to code the interview data qualitatively and construct a rich and nuanced thematic framework. As a result, we identified three critical interconnected themes that compose our thematic framework for privacy engineering "in the wild": (1) personal privacy mindset and stance, categorised into practitioners' privacy knowledge, attitudes and behaviours; (2) organisational privacy culture, such as decision-power and positive and negative examples of privacy climate; and, (3) privacy engineering practices, such as procedures and controls concretely used in the industry. Among the main findings, this study provides many insights about the state-of-the-practice of privacy engineering, pointing to a positive influence of privacy laws (e.g., EU General Data Protection Regulation) on practitioners' behaviours and organisations' cultures. Aspects such as organisational privacy culture and climate were also confirmed to [...]
翻译:作为新兴的研究和实践领域,隐私工程是一个新兴的研究和实践领域,包括实施、部署和操作工作系统中的隐私特征和控制所需的技术能力和管理程序。为此,软件公司软件从业人员和其他利益相关者需要合作开展工作,以建立隐私保护企业和工程解决方案。已经进行了大量研究,以了解软件从业人员对信息隐私的看法,但应更加重视具体隐私工程组成部分的采用。这一研究深入到软件从业人员的观点和心态、组织方面以及当前关于隐私及其工程流程的做法。对来自不同国家和背景的30名从业人员进行了访谈,分享了他们的经验,并就广泛的隐私专题发表了他们的意见。采用了专题分析方法,对访谈数据进行质量规范,并构建了丰富和细微的专题框架。结果,我们确定了三个相互关联的关键主题,构成我们“野生”的隐私工程主题框架:(1) 个人隐私思维和立场,并分解了从业人员的隐私知识、态度和行为。(2) 组织隐私文化文化文化,如决定力和积极和消极组织对隐私环境的监管实例;以及采用专题分析方法,如欧盟的隐私工程组织、对具体行为法的监管、对总体的监管,提供了各种隐私研究。