Eprint diffusé en premier sur ORBilu (E-prints, Working papers et Carnets de recherche)
GDPR-Relevant Privacy Concerns in Mobile Apps Research: A Systematic Literature Review
AMARAL CEJAS, Orlando; SANNIER, Nicolas; ABUALHAIJA, Sallam et al.
2024
 

Documents


Texte intégral
ASACB-SLR.pdf
Preprint Auteur (636.14 kB)
Télécharger

Tous les documents dans ORBilu sont protégés par une licence d'utilisation.

Envoyer vers



Détails



Mots-clés :
Requirements Engineering; Regulatory Compliance; GDPR; Privacy Requirements; Mobile Apps; Systematic Literature Review
Résumé :
[en] The General Data Protection Regulation (GDPR) is considered as the benchmark in the European Union (EU) for privacy and data protection standards. Since before its entry into force in 2018, substantial research has been conducted in the requirements engineering (RE) literature investigating the elicitation, representation and verification of privacy requirements in GDPR. Software systems deployed anywhere in the world must comply with GDPR as long as they handle personal data of EU residents. Mobile applications (apps) are no different in that regard. With the growing pervasiveness of mobile apps and their increasing demand for personal data, privacy concerns have acquired further interest within the software engineering (SE) community at large. Despite the extensive literature on GDPR-relevant privacy concerns in mobile apps, there is no secondary study that describes, analyzes, and categorizes the current focus. Research gaps and persistent challenges are thus left unnoticed. In this article, we aim to systematically review existing primary studies highlighting various GDPR concepts and how these concepts are addressed in mobile apps research. The objective is to reconcile the existing work on GDPR in the RE literature with the research on GDPR-related privacy concepts in mobile apps in the SE literature. Our findings show that the current research landscape reflects a rather shallow understanding of GDPR requirements. The GDPR concepts investigated in the majority of the studies include: (i) the sharing of personal data with third-party libraries, mainly for the purpose of identifying data leaks; (ii) different mechanisms for acquiring explicit consent from users; and (iii) data collection involving various personal data categories that are often obtained directly from the users. While such GDPR concepts are indeed of significant importance, other topics such as data subject rights (i.e., the rights of individuals over their personal data) are fundamental to GDPR, yet under-explored in the literature. In this article, we highlight future directions to be pursued by the SE community for supporting the development of GDPR-compliant mobile apps.
Centre de recherche :
Interdisciplinary Centre for Security, Reliability and Trust (SnT) > SVV - Software Verification and Validation
NCER-FT - FinTech National Centre of Excellence in Research
Disciplines :
Sciences informatiques
Auteur, co-auteur :
AMARAL CEJAS, Orlando  
SANNIER, Nicolas  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > SVV
ABUALHAIJA, Sallam  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > SVV
CECI, Marcello  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > SVV
BIANCULLI, Domenico  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > SVV
Langue du document :
Anglais
Titre :
GDPR-Relevant Privacy Concerns in Mobile Apps Research: A Systematic Literature Review
Date de publication/diffusion :
2024
Nombre de pages :
23
Projet FnR :
FNR16570468 - 2021 (01/07/2022-30/06/2030) - Yves Le Traon
Organisme subsidiant :
FNR - Fonds National de la Recherche
N° du Fonds :
NCER22/IS/16570468/NCER-FT
Disponible sur ORBilu :
depuis le 29 novembre 2024

Statistiques


Nombre de vues
214 (dont 8 Unilu)
Nombre de téléchargements
160 (dont 2 Unilu)

Bibliographie


Publications similaires



Contacter ORBilu