Article (Scientific journals)
Understanding the GDPR from a requirements engineering perspective—a systematic mapping study on regulatory data protection requirements
NEGRI RIBALTA, Claudia Sofia; LOMBARD-PLATET, Marius; Salinesi, Camille
2024In Requirements Engineering
Peer Reviewed verified by ORBi Dataset
 

Files


Full Text
s00766-024-00423-4.pdf
Publisher postprint (996.1 kB)
Download

All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
Compliance; Data protection; GDPR; Requirements; Systematic mapping; Engineering perspective; General data protection regulations; Protection requirements; Regulatory datum; Requirement; Requirement engineering; Software development life-cycle; Systematic mapping studies; Software; Information Systems
Abstract :
[en] Data protection compliance is critical from a requirements engineering (RE) perspective, both from a software development lifecycle (SDLC) perspective and regulatory compliance. Not including these requirements from the early phases of the SDLC can prove costly and challenging afterward. The general data protection regulation (GDPR) from the European Union (EU) sets a list of requirements that organizations working within its scope should satisfy. However, these requirements are complex to work with, as legal prose tends to be vague and imprecise, and not all requirements have received the same attention from researchers. This study aims to identify the research published in RE for helping compliance with regulatory data protection requirements. We gathered and analyzed 90 articles from 2016 to 2022 through a systematic mapping study. We analyzed key trends in the sample, such as year of publication, publication venue, type of research, interdisciplinarity in the author’s background, GDPR focus of compliance element, and type of proposal. Our main findings show ongoing interest, mostly published in conferences, in achieving overall compliance with the GDPR and consent as the most popular topics. Other topics, such as cookies or children’s data, did not receive significant attention. Research over the whole RE process has been done. 20 (22%) of the papers have authors affiliated with non-computer science; however, most research seems not interdisciplinary. We finally discuss gaps in the literature, possible future areas of research, and the importance of interdisciplinary research for regulatory data protection requirements in RE.
Research center :
NCER-FT - FinTech National Centre of Excellence in Research
Disciplines :
Computer science
Author, co-author :
NEGRI RIBALTA, Claudia Sofia  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > IRiSC
LOMBARD-PLATET, Marius ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > APSIA
Salinesi, Camille;  Centre de Recherche en Informatique, Université Paris 1 Panthéon-Sorbonne, Paris, France
External co-authors :
yes
Language :
English
Title :
Understanding the GDPR from a requirements engineering perspective—a systematic mapping study on regulatory data protection requirements
Publication date :
2024
Journal title :
Requirements Engineering
ISSN :
0947-3602
eISSN :
1432-010X
Publisher :
Springer Science and Business Media Deutschland GmbH
Peer reviewed :
Peer Reviewed verified by ORBi
FnR Project :
NCER22/IS/16570468/NCER-FT
Funders :
FNR - Fonds National de la Recherche
Funding number :
NCER22/IS/16570468/NCER-FT
Funding text :
This project has received funding from the Luxembourg National Research Fund (FNR), grant NCER22/IS/16570468/NCER-FT. The authors have no other interests to disclose.
Available on ORBilu :
since 09 September 2024

Statistics


Number of views
131 (23 by Unilu)
Number of downloads
30 (4 by Unilu)

Scopus citations®
 
14
Scopus citations®
without self-citations
14
OpenCitations
 
0
OpenAlex citations
 
14
WoS citations
 
10

Bibliography


Similar publications



Contact ORBilu