“I need to learn better searching tactics for privacy policy laws.” Investigating Software Developers’ Behavior When Using Sources on Privacy Issues
Stefan Albert Horstmann, Sandy Hong, Maziar Niazian, Cristiana Santos, Alena Naiakshina
Abstract
Since the introduction of the European General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), software developers increasingly have to make privacy-related decisions during system design and implementation. However, past research showed that they often lack legal expertise and struggle with privacy-compliant development. To shed light on how effective current information sources are in supporting them with privacysensitive implementation, we conducted a qualitative study with 30 developers. Participants were presented with a privacy-sensitive scenario and asked to identify privacy issues and suggest measures using their knowledge, online resources, and an AI assistant. We observed developers' decision-making in think-aloud sessions and discussed it in follow-up interviews. We found that participants struggled with all three sources: personal knowledge was insufficient, web content was often too complex, and while AI assistants provided clear and user-tailored responses, they lacked contextual relevance and failed to identify scenario-specific issues. Our study highlights major shortcomings in existing support for privacy-related development tasks. Based on our findings, we discuss the need for more accessible, understandable, and actionable privacy resources for developers.
• Security and privacy → Usability in security and privacy.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 562f1e7c-7d21-4675-bbfd-6ef08cce2d4fBuilds on22
- Asleep at the Keyboard? Assessing the Security of GitHub Copilot's Code ContributionsHammond Pearce, Baleegh Ahmad, Benjamin Tan, Brendan Dolan-Gavitt et al.S&P 2022 · 725 citations
- You Get Where You're Looking for: The Impact of Information Sources on Code SecurityYasemin Acar, Michael Backes, Sascha Fahl, Doowon Kim et al.S&P 2016 · 325 citations
- Stack Overflow Considered Harmful? The Impact of Copy&Paste on Android Application SecurityFelix Fischer, Konstantin Böttinger, Huang Xiao, Christian Stransky et al.S&P 2017 · 293 citations
- Do Users Write More Insecure Code with AI Assistants?Neil Perry, Megha Srivastava, Deepak Kumar, Dan BonehCCS 2023 · 150 citations
- Is Stack Overflow Obsolete? An Empirical Study of the Characteristics of ChatGPT Answers to Stack Overflow QuestionsSamia Kabir, David N. Udo-Imeh, Bonan Kou, Tianyi ZhangCHI 2024 · 149 citations
Related papers
- "Sorry for Bugging you so much." Exploring Developers' Behavior Towards Privacy-Compliant ImplementationStefan Albert Horstmann, Sandy Hong, David Klein, Raphael Serafini et al.S&P 2025
- Encoding Privacy: Sociotechnical Dynamics of Data Protection Compliance WorkRohan GroverCHI 2024 · 8 citations
- Privacy Champions in Software Teams: Understanding Their Motivations, Strategies, and ChallengesMohammad Tahaei, Alisa Frik, Kami VanieaCHI 2021 · 75 citations
- Tinker, Tailor, Trust: How Developers Create Privacy Policies With and Without AIShiva Mayahi, Noura Alomar, Nathan MalkinCHI 2026 · 1 citation
- "The AI tool can't make it any worse." Investigating Developers' Security Behavior with AI Assistants in a Password Storage StudyAsli Yardim, Raphael Serafini, Nadine Jost, Anna-Marie Ortloff et al.CHI 2026 · 1 citation
