Encoding Privacy: Sociotechnical Dynamics of Data Protection Compliance Work

AI Ethics, Fairness & AccountabilityPrivacy by Design & User ControlPrivacy Perception & Decision-MakingSoftware Engineers & DevelopersCybersecurity EngineersPrivacy Policy Makers

Document Title

Encoding Privacy: Sociotechnical Dynamics of Data Protection Compliance Work

Document Information

  • Subject Area: Sociotechnical dynamics of data protection regulations and developers' compliance practices
  • Keywords: Data protection, user privacy, compliance, developer studies, GDPR, CCPA, personal data, technology and society, compliance work
  • Conference: CHI Conference on Human Factors in Computing Systems (CHI ’24)
  • Author: Rohan Grover
  • Date: May 11-16, 2024
  • DOI: https://doi.org/10.1145/3613904.3642872

Research Background and Problem

  • Identified Issues or Challenges:

    • The implementation of data protection regulations (e.g., GDPR and CCPA) is often carried out by technical teams, especially developers, but there is uncertainty in how these regulations are specifically executed, which may result in the failure to achieve regulatory goals.
    • The ambiguity of regulations grants developers significant interpretive power in translating regulatory requirements, leading to disputes over how these requirements should be implemented.
    • Practical development processes often face challenges such as resource constraints, lack of oversight, and developers' underestimation of compliance risks, which impact the effectiveness of user privacy protection.
  • Research Significance:

    • As pioneering global standards for data protection regulations, understanding how development teams implement GDPR and CCPA is crucial for exploring how policies are translated into technical practices and their impact on user privacy.
    • The implementation of data protection regulations represents a convergence of technology and society, and studying developers' work can reveal the dynamic interplay between policy, technology, and social forces.
  • Related Work and Motivation:

    • Previous privacy research has focused on "Privacy by Design" principles and how developers embed privacy values into applications.
    • However, existing studies often fail to adequately reveal the specific responsibilities of developers in organizational data protection compliance tasks and their interactions with organizational contexts.

Solution

  • Proposed Approach or Solution:

    • This study analyzes the roles and experiences of developers in data protection compliance through semi-structured interviews with 14 "data technologists" (including developers, data analysts, designers, etc.) involved in GDPR and CCPA compliance work.
    • It defines developers' compliance work as "Data Protection Compliance Work" (DPCW), emphasizing it as a sociotechnical process of translating data protection regulations from policy into code.
  • Innovations:

    • Highlights developers' influence on regulatory compliance through "creative interpretation of ambiguous regulatory requirements," "leveraging anticipated technical expertise and low accountability," and "simplifying compliance work into one-off projects."
    • Links data protection compliance to developers' attitudes and organizational interactions, emphasizing privacy as a "boundary concept" with definitions that vary among stakeholders.
  • Implementation Steps and Key Techniques:

    • Employs qualitative research methods, conducting semi-structured interviews covering developers' work practices, their roles within organizations, decision-making mechanisms, and overall perspectives on regulations.
    • Uses constructivist grounded theory to thematically code interview data, analyzing commonalities and differences in developers' sociotechnical practices.

Research Findings

  • Specific Findings:

    • Developers' subjective decisions and their interpretations of regulatory ambiguity or the "spirit of the law" are the primary factors influencing compliance outcomes.
    • High autonomy and limited oversight allow developers significant freedom in regulatory implementation, often resulting in delayed problem detection.
    • Data protection regulations have limited effectiveness in enhancing user privacy rights, as developers frequently treat regulations as mere "compliance tasks," neglecting ongoing maintenance and improvement.
  • Comparison with Existing Solutions and Advantages:

    • This study goes beyond prior work that emphasizes regulations themselves, shifting the focus to the specific processes through which regulations are implemented by developers.
    • Through cross-functional team data analysis, it highlights the central role of developers in regulatory compliance while also supplementing the understanding of the roles of other professionals (e.g., legal advisors, product managers).
  • Experimental or Evaluation Results:

    • Developers generally do not conduct or plan for long-term audits and rarely improve user privacy features unless driven by direct user feedback or policy changes.
    • Most developers hold negative views of GDPR and CCPA, perceiving their actual impact on user privacy as limited.
  • Limitations and Future Directions:

    • The data only covers GDPR and CCPA, with the study sample concentrated in North America and specific professional networks, lacking broader geographic or regulatory comparisons.
    • Future research is recommended to expand to other data protection regulations and compliance practices in more diverse regions or to conduct field studies tracking how development teams execute compliance tasks.

Conclusion

This study highlights the critical role of developers as "co-regulators" in data protection compliance, with their work directly influencing the implementation of regulations and the protection of user privacy. By examining developers' practices and their complex sociotechnical contexts, this research provides practical insights for policymakers and stakeholders involved in data protection.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/147127/2024

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://doi.org/10.1145/3613904.3642872
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2024
emoji_events
Award
No award tagged
group
Authors
1 authors
sell
Subtopics
AI Ethics, Fairness & Accountability, Privacy by Design & User Control, Privacy Perception & Decision-Making
work
Professions
Software Engineers & Developers, Cybersecurity Engineers, Privacy Policy Makers
article
Content Status
Full text indexed
hub
Related Papers
10 related papers