To read this content please select one of the options below:

The impact of general data protection regulation on software engineering practices

Luís Leite (Gaya Higher Polytechnic Institute, Vila Nova de Gaia, Portugal)
Daniel Rodrigues dos Santos (Gaya Higher Polytechnic Institute, Vila Nova de Gaia, Portugal)
Fernando Almeida (INESC TEC R&D Centre, University of Porto, Porto, Portugal)

Information and Computer Security

ISSN: 2056-4961

Article publication date: 9 August 2021

Issue publication date: 31 January 2022

611

Abstract

Purpose

This paper aims to explore the changes imposed by the general data protection regulation (GDPR) on software engineering practices. The fundamental objective is to have a perception of the practices and phases that have experienced the greatest changes. Additionally, it aims to identify a set of good practices that can be adopted by software engineering companies.

Design/methodology/approach

This study uses a qualitative methodology through four case studies involving Portuguese software engineering companies. Two of these companies are small and medium enterprises (SMEs) while the other remaining two are micro-companies. The thematic analysis is adopted to identify patterns in the performed interviews.

Findings

The findings indicate that significant changes have occurred at all stages of software development. In particular, the initial stages of identifying requirements and modeling processes were the stages that experienced the greatest changes. On the opposite, the technical development phase has not noticeably changed but, nevertheless, it is necessary to look at the importance of training software developers for GDPR rules and practices.

Research limitations/implications

Two relevant limitations were identified as follows: only four case studies involving micro-companies and SMEs were considered, and only the traditional software development methodology was considered. The use of agile methodologies was not explored in this study and the findings can only be mainly applied to the waterfall model.

Originality/value

This study offers mainly practical contributions by identifying a set of challenges that are posed to software engineering companies by the implementation of GDPR. Through their knowledge, it is expected to help these companies to better prepare themselves and anticipate the challenges they will necessarily face.

Keywords

Citation

Leite, L., dos Santos, D.R. and Almeida, F. (2022), "The impact of general data protection regulation on software engineering practices", Information and Computer Security, Vol. 30 No. 1, pp. 79-96. https://doi.org/10.1108/ICS-03-2020-0043

Publisher

:

Emerald Publishing Limited

Copyright © 2021, Emerald Publishing Limited

Related articles