Privacy by Design: A qualitative study to explore privacy by design adaptation in reducing privacy breaches
Esther Nampiina, Mandukhai Lkhagvasuren, Arman Madjidian
Abstract
Esther Nampiina, Mandukhai Lkhagvasuren, Arman Madjidian
Abstract
Privacy by Design is a methodology that enables privacy to be built into the design and architecture of information systems and business processes. Rather than bolting on protection at the end of a design process, care for privacy needs to be one of the foundational concerns of any implementation. Traditionally, privacy policies have been largely approached reactively, and only triggered once a breach occurs. However, to comply with new privacy data protection laws, companies are now obliged to implement the principles of PbD and take data privacy into the account during the design stage of all projects. Therefore, this study aims to explore the practices that have been adopted by companies to implement PbD. To achieve this aim, empirical data from semi-structured interviews conducted with UI/UX designers worldwide were analysed and insightful findings were found. Overall, the concept of PbD is a relatively unknown concept among most respondents. Several companies have adopted practices in accordance with the principle of data minimization, and the principle of visibility and transparency.
OpenAlex reports 1 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Privacy by Design is a methodology that enables privacy to be built into the design and architecture of information systems and business processes. Rather than bolting on protection at the end of a design process, care for privacy needs to be one of the foundational concerns of any implementation. Traditionally, privacy policies have been largely approached reactively, and only triggered once a breach occurs. However, to comply with new privacy data protection laws, companies are now obliged to implement the principles of PbD and take data privacy into the account during the design stage of all projects. Therefore, this study aims to explore the practices that have been adopted by companies to implement PbD. To achieve this aim, empirical data from semi-structured interviews conducted with UI/UX designers worldwide were analysed and insightful findings were found. Overall, the concept of PbD is a relatively unknown concept among most respondents. Several companies have adopted practices in accordance with the principle of data minimization, and the principle of visibility and transparency.
Key concepts: Privacy by Design, Transparency (behavior), Information privacy, Privacy software, Internet privacy, Computer science, Computer security, Privacy policy