Privacy Flashcards

1
Q

Problem for developers - Privacy

A

Privacy legislation is written by lawyers, developers have problems understanding
=> problems as developers need to implement legislation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
1
Q

Data subject, Data controller, Personal Data, Personal Identifyable Information

A

Data subject: User
Data controler: company
Personal data: Data of an Identifiable user
Personal Identifyable Information: Data that allows to identify user

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

“Mapping Communication Gap” Goal

A

RQ1: What are developers’, team coordinators’, and privacy experts’
perceptions of privacy requirements?
RQ2: How does the communication of privacy requirements between
developers, team coordinators, and privacy experts look like?
RQ3: How do privacy experts create, and team coordinators and developers
implement privacy requirements?

Map process of privacy in companies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

“Mapping Communication Gap” Approach

A

Qualitative semi structured interviews, Grounded theory according to Charmaz
First: Examine knowledge on Privacy Concepts
Second: Ask Participants on Privacy in their companies
Third: Participants were presented with hypothetical requirements

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

“Mapping Communication Gap” Analysis

A

Reqruitment: Upwork, No screening
GT by Charmaz: Initial Coding: incident by incident
Focused coding: selecting categories from codes
Theoretical coding: specify relationships between categories
Multiple coders (two per interview)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

“Mapping Communication Gap” Results

A

Privacy Expert designs approach, Developer implements, Team Coordinator used for communication
Both parties feel they lack informationl and wish for more direct communication
Experts feel that developers dont care for privacy
Developers feel that experts lack technical knowledge

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

“Mapping Communication Gap” Motivation for Privacy

A

Companies are not motivated by default but by fines, image loss etc

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Common Ground Theory

A

Communication between privacy experts and developers has become adversarial.
More direct communications need. Implement privacy champion with knowledge of both. Include experts early in development.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

“Sorry for bugging you so much’’ Setup

A

Lab in which developers complete privacy relevant tasks
Provide access to privacy expert chat
RQ1: How do developers implement privacy measures in their software?
RQ2: How do developers behave if they require information on privacy during
implementation?
RQ3: What issues do developers encounter during privacy measures
implementation?
Health app which contained private data of subjects. Four tasks and exit interview.
Task1: Warmup task backup (not privacy relevant)
Task2: Deletion request (needs to be deleted in database and backup)
Task3: Search function for doctor (are only the doctors patients shown? how much data does the doctor get?)
Task4: Advertisment emails (subject have not given consent before, so ask first)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

“Sorry for bugging you so much’’ Groups

A

Control: No input
Prompted: Told that all solutions need to be compliant
Prompted + Expert Chat: Told that all solutions need to be compliant + expert chat

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

“Sorry for bugging you so much’’ Recruitment

A

Recruitment of past participants also snowballing and kleinanzeigen and screening.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

“Sorry for bugging you so much’’ Analysis

A

Code analyzed by two researches indepently with third as a tiebreak
Qualitative analysis of interview with thematic analysis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

“Sorry for bugging you so much’’ Results

A

Very little privacy consideration from all groups
Confidence in compliance was low
Very little searches or questions to experts
Based solution on existing solution (no rewrite) => privacy by design
Functionality was implemented first
However they can identify issues
Prompted groups not significantly better than not prompted
Experts didnt help to much

How well did you know this?
1
Not at all
2
3
4
5
Perfectly