论文标题
在连续集成的背景下,GDPR合规性
GDPR Compliance in the Context of Continuous Integration
论文作者
论文摘要
2018年,《通用数据保护法规》(GDPR)的制定迫使收集和/或基于欧盟的个人数据的任何组织遵守严格的隐私法规。在GDPR截止日期之前和之后,软件组织一直在努力实现GDPR合规性。尽管一些研究依赖于调查或访谈来发现GDPR的一般影响,但缺乏深入的研究来研究软件组织的合规性实践和合规性挑战。特别是,没有关于中小企业(中小企业)的信息,这些信息代表了欧盟中大多数组织,也没有关于持续集成的组织。使用设计科学方法论,我们在20个月中就与小型初创组织合作进行了有关GDPR合规实践和挑战的深入研究。我们首先确定了我们的合作者的业务问题,然后迭代地开发了两个工件来解决这些问题:一组操作的GDPR原则,以及一个自动化的GDPR工具,该工具测试了这些GDPR衍生的隐私要求。这种设计科学方法对研究和实践产生了四个影响。例如,我们的研究表明,GDPR法规可以通过自动手段进行部分运行和测试,从而改善了合规性实践,但是需要更多的研究来创造更有效的手段来传播和管理软件开发人员之间的GDPR知识。
The enactment of the General Data Protection Regulation (GDPR) in 2018 forced any organization that collects and/or processes EU-based personal data to comply with stringent privacy regulations. Software organizations have struggled to achieve GDPR compliance both before and after the GDPR deadline. While some studies have relied on surveys or interviews to find general implications of the GDPR, there is a lack of in-depth studies that investigate compliance practices and compliance challenges of software organizations. In particular, there is no information on small and medium enterprises (SMEs), which represent the majority of organizations in the EU, nor on organizations that practice continuous integration. Using design science methodology, we conducted an in-depth study over the span of 20 months regarding GDPR compliance practices and challenges in collaboration with a small, startup organization. We first identified our collaborator's business problems and then iteratively developed two artifacts to address those problems: a set of operationalized GDPR principles, and an automated GDPR tool that tests those GDPR-derived privacy requirements. This design science approach resulted in four implications for research and for practice. For example, our research reveals that GDPR regulations can be partially operationalized and tested through automated means, which improves compliance practices, but more research is needed to create more efficient and effective means to disseminate and manage GDPR knowledge among software developers.