"Sorry for Bugging you so much." Exploring Developers' Behavior Towards Privacy-Compliant Implementation
Stefan Albert Horstmann, Sandy Hong, David Klein, Raphael Serafini, Martin Degeling, Martin Johns, Veelasha Moonsamy, Alena Naiakshina
摘要
While protecting user data is essential, software developers often fail to fulfill privacy requirements. However, the reasons why they struggle with privacy-compliant implementation remain unclear. Is it due to a lack of knowledge, or is it because of insufficient support? To provide foundational insights in this field, we conducted a qualitative 5-hour programming study with 30 professional software developers implementing 3 privacy-sensitive programming tasks that were designed with GDPR compliance in mind. To explore if and how developers implement privacy requirements, participants were divided into 3 groups: control, privacy prompted, and privacy expert-supported. After task completion, we conducted follow-up interviews. Alarmingly, almost all participants submitted non-GDPR-compliant solutions (79/90). In particular, none of the 3 tasks were solved privacy-compliant by all 30 participants, with the non-prompted group having the lowest number of 3 out of 30 privacy-compliant solution attempts. Privacy prompting and expert support only slightly improved participants' submissions, with 6/30 and 8/30 privacy-compliant attempts, respectively. In fact, all participants reported severe issues addressing common privacy requirements such as purpose limitation, user consent, or data minimization. Counterintuitively, although most developers exhibited minimal confidence in their solutions, they rarely sought online assistance or contacted the privacy expert, with only 4 out of 10 expert-supported participants explicitly asking for compliance confirmation. Instead, participants often relied on existing implementations and focused on implementing functionality and security first.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Tinker, Tailor, Trust: How Developers Create Privacy Policies With and Without AIShiva Mayahi, Noura Alomar, Nathan MalkinCHI 2026 · 被引用 1 次
- “I need to learn better searching tactics for privacy policy laws.” Investigating Software Developers’ Behavior When Using Sources on Privacy IssuesStefan Albert Horstmann, Sandy Hong, Maziar Niazian, Cristiana Santos 等ICSE 2026 · 被引用 1 次
它引用的顶会 Paper20
- You Get Where You're Looking for: The Impact of Information Sources on Code SecurityYasemin Acar, Michael Backes, Sascha Fahl, Doowon Kim 等S&P 2016 · 被引用 325 次
- Stack Overflow Considered Harmful? The Impact of Copy&Paste on Android Application SecurityFelix Fischer, Konstantin Böttinger, Huang Xiao, Christian Stransky 等S&P 2017 · 被引用 293 次
- Understanding Privacy-Related Questions on Stack OverflowMohammad Tahaei, Kami Vaniea, Naomi SaphraCHI 2020 · 被引用 93 次
- Share First, Ask Later (or Never?) Studying Violations of GDPR's Explicit Consent in Android AppsTrung Tin Nguyen, Michael Backes, Ninja Marnau, Ben StockUSENIX Security 2021 · 被引用 70 次
- Privacy Research with Marginalized Groups: What We Know, What's Needed, and What's NextShruti Sannon, Andrea ForteCSCW 2022 · 被引用 66 次
相关 Paper
- Encoding Privacy: Sociotechnical Dynamics of Data Protection Compliance WorkRohan GroverCHI 2024 · 被引用 8 次
- Privacy Champions in Software Teams: Understanding Their Motivations, Strategies, and ChallengesMohammad Tahaei, Alisa Frik, Kami VanieaCHI 2021 · 被引用 75 次
- Human-GDPR Interaction: Practical Experiences of Accessing Personal DataAlex Bowyer, Jack Holt, Josephine Go Jefferies, Rob Wilson 等CHI 2022 · 被引用 51 次
- Automating Cookie Consent and GDPR Violation DetectionDino Bollinger, Karel Kubicek, Carlos Cotrini, David A. BasinUSENIX Security 2022
- PolicyChecker: Analyzing the GDPR Completeness of Mobile Apps' Privacy PoliciesAnhao Xiang, Weiping Pei, Chuan YueCCS 2023 · 被引用 24 次
