Eprint first made available on ORBilu (E-prints, Working papers and Research blog)
GDPR-Relevant Privacy Concerns in Mobile Apps Research: A Systematic Literature Review
AMARAL CEJAS, Orlando; SANNIER, Nicolas; ABUALHAIJA, Sallam et al.
2024
 

Files


Full Text
ASACB-SLR.pdf
Author preprint (636.14 kB)
Download

All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
Requirements Engineering; Regulatory Compliance; GDPR; Privacy Requirements; Mobile Apps; Systematic Literature Review
Abstract :
[en] The General Data Protection Regulation (GDPR) is considered as the benchmark in the European Union (EU) for privacy and data protection standards. Since before its entry into force in 2018, substantial research has been conducted in the requirements engineering (RE) literature investigating the elicitation, representation and verification of privacy requirements in GDPR. Software systems deployed anywhere in the world must comply with GDPR as long as they handle personal data of EU residents. Mobile applications (apps) are no different in that regard. With the growing pervasiveness of mobile apps and their increasing demand for personal data, privacy concerns have acquired further interest within the software engineering (SE) community at large. Despite the extensive literature on GDPR-relevant privacy concerns in mobile apps, there is no secondary study that describes, analyzes, and categorizes the current focus. Research gaps and persistent challenges are thus left unnoticed. In this article, we aim to systematically review existing primary studies highlighting various GDPR concepts and how these concepts are addressed in mobile apps research. The objective is to reconcile the existing work on GDPR in the RE literature with the research on GDPR-related privacy concepts in mobile apps in the SE literature. Our findings show that the current research landscape reflects a rather shallow understanding of GDPR requirements. The GDPR concepts investigated in the majority of the studies include: (i) the sharing of personal data with third-party libraries, mainly for the purpose of identifying data leaks; (ii) different mechanisms for acquiring explicit consent from users; and (iii) data collection involving various personal data categories that are often obtained directly from the users. While such GDPR concepts are indeed of significant importance, other topics such as data subject rights (i.e., the rights of individuals over their personal data) are fundamental to GDPR, yet under-explored in the literature. In this article, we highlight future directions to be pursued by the SE community for supporting the development of GDPR-compliant mobile apps.
Research center :
Interdisciplinary Centre for Security, Reliability and Trust (SnT) > SVV - Software Verification and Validation
NCER-FT - FinTech National Centre of Excellence in Research
Disciplines :
Computer science
Author, co-author :
AMARAL CEJAS, Orlando  
SANNIER, Nicolas  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > SVV
ABUALHAIJA, Sallam  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > SVV
CECI, Marcello  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > SVV
BIANCULLI, Domenico  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > SVV
Language :
English
Title :
GDPR-Relevant Privacy Concerns in Mobile Apps Research: A Systematic Literature Review
Publication date :
2024
Number of pages :
23
FnR Project :
FNR16570468 - 2021 (01/07/2022-30/06/2030) - Yves Le Traon
Funders :
FNR - Fonds National de la Recherche
Funding number :
NCER22/IS/16570468/NCER-FT
Available on ORBilu :
since 29 November 2024

Statistics


Number of views
211 (8 by Unilu)
Number of downloads
151 (2 by Unilu)

Bibliography


Similar publications



Contact ORBilu