Engineering privacy in smartphone apps: a technical guideline catalog for app developers

  • With the rapid growth of technology in recent years, we are surrounded by or even dependent on the use of technological devices such as smartphones as they are now an indispensable part of our life. Smartphone applications (apps) provide a wide range of utilities such as navigation, entertainment, fitness, etc. To provide such context-sensitive services to users, apps need to access users' data including sensitive ones, which in turn, can potentially lead to privacy invasions. To protect users against potential privacy invasions in such a vulnerable ecosystem, legislation such as the European Union General Data Protection Regulation (EU GDPR) demands best privacy practices. Therefore, app developers are required to make their apps compatible with legal privacy principles enforced by law. However, this is not an easy task for app developers to comprehend purely legal principles to understand what needs to be implemented. Similarly, bridging the gap between legal principles and technical implementations to understand how legal principles need to be implemented is another barrier to develop privacy-friendly apps. To this end, this paper proposes a privacy and security design guide catalog for app developers to assist them in understanding and adopting the most relevant privacy and security principles in the context of smartphone apps. The presented catalog is aimed at mapping the identified legal principles to practical privacy and security solutions that can be implemented by developers to ensure enhanced privacy aligned with existing legislation. Through conducting a case study, it is confirmed that there is a significant gap between what developers are doing in reality and what they promise to do. This paper provides researchers and developers of privacy-related technicalities an overview of the characteristics of existing privacy requirements needed to be implemented in smartphone ecosystems, on which they can base their work.
Metadaten
Author:Majid Hatamian
URN:urn:nbn:de:hebis:30:3-552757
DOI:https://doi.org/10.1109/ACCESS.2020.2974911
ISSN:2169-3536
Parent Title (English):IEEE Access
Publisher:Institute of Electrical and Electronics Engineers (IEEE)
Place of publication:Los Alamitos
Document Type:Article
Language:English
Date of Publication (online):2020/02/28
Date of first Publication:2020/02/28
Publishing Institution:Universitätsbibliothek Johann Christian Senckenberg
Release Date:2020/08/06
Tag:App; Ecosystems; GDPR; Guidelines; Law; Privacy; Security; developers; guideline catalog; privacy engineering; smart phones; smartphone apps
Volume:8
Page Number:17
First Page:35429
Last Page:35445
Note:
This work is licensed under a Creative Commons Attribution 4.0 License. For more information, see http://creativecommons.org/licenses/by/4.0/
HeBIS-PPN:470987537
Institutes:Wirtschaftswissenschaften
Dewey Decimal Classification:0 Informatik, Informationswissenschaft, allgemeine Werke / 00 Informatik, Wissen, Systeme / 004 Datenverarbeitung; Informatik
Sammlungen:Universitätspublikationen
Open-Access-Publikationsfonds:Wirtschaftswissenschaften
Licence (German):License LogoCreative Commons - Namensnennung 4.0