Skip to main content
QUICK REVIEW

[論文レビュー] GDPR Compliance in the Context of Continuous Integration

Ze Shi Li, Colin Werner|arXiv (Cornell University)|Feb 17, 2020
Privacy, Security, and Data Protection参考文献 29被引用数 12
ひとこと要約

本研究では、小規模なソフトウェアスターター企業の継続的インテグレーション(CI)パイプラインに統合された自動GDPR準拠ツールの開発と評価が行われた。データ最小化、完全性/機密性、保存期間制限といった主要なGDPR原則を、検証可能な要件へと具体化することで、プライバシー準拠の自動的かつ継続的検証が可能であることが示されたが、開発チーム全体での知識共有およびツール統合の面で課題が残っている。

ABSTRACT

The enactment of the General Data Protection Regulation (GDPR) in 2018 forced any organization that collects and/or processes EU-based personal data to comply with stringent privacy regulations. Software organizations have struggled to achieve GDPR compliance both before and after the GDPR deadline. While some studies have relied on surveys or interviews to find general implications of the GDPR, there is a lack of in-depth studies that investigate compliance practices and compliance challenges of software organizations. In particular, there is no information on small and medium enterprises (SMEs), which represent the majority of organizations in the EU, nor on organizations that practice continuous integration. Using design science methodology, we conducted an in-depth study over the span of 20 months regarding GDPR compliance practices and challenges in collaboration with a small, startup organization. We first identified our collaborator's business problems and then iteratively developed two artifacts to address those problems: a set of operationalized GDPR principles, and an automated GDPR tool that tests those GDPR-derived privacy requirements. This design science approach resulted in four implications for research and for practice. For example, our research reveals that GDPR regulations can be partially operationalized and tested through automated means, which improves compliance practices, but more research is needed to create more efficient and effective means to disseminate and manage GDPR knowledge among software developers.

研究の動機と目的

  • 小規模でCIを実施する組織におけるGDPR準拠の課題を調査すること。
  • 主要なGDPR原則を検証可能なプライバシー要件へと特定および具体化すること。
  • ソフトウェアビルドにおけるGDPR準拠を継続的にチェックする自動化ツールの開発および評価すること。
  • 自動化された準拠ツールが、リソース制約のあるスタートアップにおける意識向上とリスク低減にどのように寄与できるかを検討すること。

提案手法

  • 20か月にわたり、単一のスタートアップ(DataCorp)を共同研究者として協働し、応用的デザインサイエンス手法を用いた。
  • 参加者観察、インタビュー、コードおよびイシュートラッカーの分析を含むエトノグラフィー的手法を実施し、準拠課題を同定した。
  • GDPR原則(データ最小化、完全性/機密性、保存期間制限)を、具体的かつ検証可能なソフトウェア要件へとマッピングした。
  • CIパイプラインに統合された自動GDPRテストツールを設計し、段階的な開発を実施した。
  • インタビュー、観察、アンケート、コード分析の三角測定を通じて、発見事項および生成物の妥当性を検証した。
  • ツールが準拠意識および潜在的なGDPR違反の特定に与える影響を評価した。

実験結果

リサーチクエスチョン

  • RQ1小規模でCIを実施する組織は、GDPR準拠の課題をどのように経験しているか?
  • RQ2GDPR原則はどの程度、検証可能なソフトウェア要件へと具体化可能か?
  • RQ3自動化されたツールは、継続的インテグレーションの段階で潜在的なGDPR違反をどの程度効果的に検出できるか?
  • RQ4CIパイプラインへの自動GDPR準拠の統合に、実務的および学術的意義は何か?

主な発見

  • 本研究では、主に3つのGDPR準拠の課題を同定した:手作業によるテストに依存していること、開発者におけるプライバシー知識の不足、進化するコードベースにおける準拠管理の難しさ。
  • データ最小化、完全性/機密性、保存期間制限といったGDPR原則は、部分的に具体的かつ検証可能なソフトウェア要件へと具体化可能である。
  • CIパイプラインに統合された自動GDPRツールは、潜在的な準拠問題を正常に検出でき、プライバシーリスクに対する意識が向上した。
  • ツールは継続的準拠検証の実現可能性を示したが、開発者らがアラートを解釈し対応するためのガイダンスが必要であることが判明した。
  • 手作業によるテストは依然として大きな負担であり、より良いツール化および知識共有メカニズムの必要性が浮き彫りになった。
  • 組織は、GDPR原則を要件として具体化し、自動化ツールによる継続的検証を活用することで恩恵を受けることができるが、第三者プライバシー責任が新たなリスクをもたらす。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。