The impact of general data protection regulation on software engineering practices
Information and Computer Security
ISSN: 2056-4961
Article publication date: 9 August 2021
Issue publication date: 31 January 2022
Abstract
Purpose
This paper aims to explore the changes imposed by the general data protection regulation (GDPR) on software engineering practices. The fundamental objective is to have a perception of the practices and phases that have experienced the greatest changes. Additionally, it aims to identify a set of good practices that can be adopted by software engineering companies.
Design/methodology/approach
This study uses a qualitative methodology through four case studies involving Portuguese software engineering companies. Two of these companies are small and medium enterprises (SMEs) while the other remaining two are micro-companies. The thematic analysis is adopted to identify patterns in the performed interviews.
Findings
The findings indicate that significant changes have occurred at all stages of software development. In particular, the initial stages of identifying requirements and modeling processes were the stages that experienced the greatest changes. On the opposite, the technical development phase has not noticeably changed but, nevertheless, it is necessary to look at the importance of training software developers for GDPR rules and practices.
Research limitations/implications
Two relevant limitations were identified as follows: only four case studies involving micro-companies and SMEs were considered, and only the traditional software development methodology was considered. The use of agile methodologies was not explored in this study and the findings can only be mainly applied to the waterfall model.
Originality/value
This study offers mainly practical contributions by identifying a set of challenges that are posed to software engineering companies by the implementation of GDPR. Through their knowledge, it is expected to help these companies to better prepare themselves and anticipate the challenges they will necessarily face.
Keywords
Citation
Leite, L., dos Santos, D.R. and Almeida, F. (2022), "The impact of general data protection regulation on software engineering practices", Information and Computer Security, Vol. 30 No. 1, pp. 79-96. https://doi.org/10.1108/ICS-03-2020-0043
Publisher
:Emerald Publishing Limited
Copyright © 2021, Emerald Publishing Limited