Encoding Privacy: Sociotechnical Dynamics of Data Protection Compliance Work
Document Title
Encoding Privacy: Sociotechnical Dynamics of Data Protection Compliance Work
Document Information
- Subject Area: Sociotechnical dynamics of data protection regulations and developers' compliance practices
- Keywords: Data protection, user privacy, compliance, developer studies, GDPR, CCPA, personal data, technology and society, compliance work
- Conference: CHI Conference on Human Factors in Computing Systems (CHI ’24)
- Author: Rohan Grover
- Date: May 11-16, 2024
- DOI: https://doi.org/10.1145/3613904.3642872
Research Background and Problem
-
Identified Issues or Challenges:
- The implementation of data protection regulations (e.g., GDPR and CCPA) is often carried out by technical teams, especially developers, but there is uncertainty in how these regulations are specifically executed, which may result in the failure to achieve regulatory goals.
- The ambiguity of regulations grants developers significant interpretive power in translating regulatory requirements, leading to disputes over how these requirements should be implemented.
- Practical development processes often face challenges such as resource constraints, lack of oversight, and developers' underestimation of compliance risks, which impact the effectiveness of user privacy protection.
-
Research Significance:
- As pioneering global standards for data protection regulations, understanding how development teams implement GDPR and CCPA is crucial for exploring how policies are translated into technical practices and their impact on user privacy.
- The implementation of data protection regulations represents a convergence of technology and society, and studying developers' work can reveal the dynamic interplay between policy, technology, and social forces.
-
Related Work and Motivation:
- Previous privacy research has focused on "Privacy by Design" principles and how developers embed privacy values into applications.
- However, existing studies often fail to adequately reveal the specific responsibilities of developers in organizational data protection compliance tasks and their interactions with organizational contexts.
Solution
-
Proposed Approach or Solution:
- This study analyzes the roles and experiences of developers in data protection compliance through semi-structured interviews with 14 "data technologists" (including developers, data analysts, designers, etc.) involved in GDPR and CCPA compliance work.
- It defines developers' compliance work as "Data Protection Compliance Work" (DPCW), emphasizing it as a sociotechnical process of translating data protection regulations from policy into code.
-
Innovations:
- Highlights developers' influence on regulatory compliance through "creative interpretation of ambiguous regulatory requirements," "leveraging anticipated technical expertise and low accountability," and "simplifying compliance work into one-off projects."
- Links data protection compliance to developers' attitudes and organizational interactions, emphasizing privacy as a "boundary concept" with definitions that vary among stakeholders.
-
Implementation Steps and Key Techniques:
- Employs qualitative research methods, conducting semi-structured interviews covering developers' work practices, their roles within organizations, decision-making mechanisms, and overall perspectives on regulations.
- Uses constructivist grounded theory to thematically code interview data, analyzing commonalities and differences in developers' sociotechnical practices.
Research Findings
-
Specific Findings:
- Developers' subjective decisions and their interpretations of regulatory ambiguity or the "spirit of the law" are the primary factors influencing compliance outcomes.
- High autonomy and limited oversight allow developers significant freedom in regulatory implementation, often resulting in delayed problem detection.
- Data protection regulations have limited effectiveness in enhancing user privacy rights, as developers frequently treat regulations as mere "compliance tasks," neglecting ongoing maintenance and improvement.
-
Comparison with Existing Solutions and Advantages:
- This study goes beyond prior work that emphasizes regulations themselves, shifting the focus to the specific processes through which regulations are implemented by developers.
- Through cross-functional team data analysis, it highlights the central role of developers in regulatory compliance while also supplementing the understanding of the roles of other professionals (e.g., legal advisors, product managers).
-
Experimental or Evaluation Results:
- Developers generally do not conduct or plan for long-term audits and rarely improve user privacy features unless driven by direct user feedback or policy changes.
- Most developers hold negative views of GDPR and CCPA, perceiving their actual impact on user privacy as limited.
-
Limitations and Future Directions:
- The data only covers GDPR and CCPA, with the study sample concentrated in North America and specific professional networks, lacking broader geographic or regulatory comparisons.
- Future research is recommended to expand to other data protection regulations and compliance practices in more diverse regions or to conduct field studies tracking how development teams execute compliance tasks.
Conclusion
This study highlights the critical role of developers as "co-regulators" in data protection compliance, with their work directly influencing the implementation of regulations and the protection of user privacy. By examining developers' practices and their complex sociotechnical contexts, this research provides practical insights for policymakers and stakeholders involved in data protection.
Research Questions / Practical Problems
Question signals indexed for this paper.
Research Questions
3- How do developers influence compliance practices when interpreting ambiguous data protection regulations such as GDPR and CCPA?Category: Data Sharing, Platform Rights, and Personal Data ControlSimilar questionsarrow_forward
- What major challenges and constraints do development teams face in organizing data protection compliance work?Category: Data Sharing, Platform Rights, and Personal Data ControlSimilar questionsarrow_forward
- How does the implementation of data protection regulations reflect dynamic interactions between technology and society?Category: Data Sharing, Platform Rights, and Personal Data ControlSimilar questionsarrow_forward
Practical Problems
1- Developers often lack clear guidance when implementing data protection compliance, making it difficult to effectively protect user privacy.Category: Data Sharing, Platform Rights, and Personal Data ControlSimilar questionsarrow_forward
- 71%
Sensor Illumination: Exploring Design Qualities and Ethical Implications of Smart Cameras and Image/Video Analytics
CHI '20· Privacy by Design & User Control +2
- 71%
"I'm Surprised So Much is Connected": A Study on Users' Online Account Security Connections
CHI '22· Privacy by Design & User Control +2
- 71%
Permission vs. App Limiters: Profiling Smartphone Users to Understand Differing Strategies for Mobile Privacy Management
CHI '22· Privacy by Design & User Control +2
- 71%
Deepfakes, Phrenology, Surveillance, and More! A Taxonomy of AI Privacy Risks
CHI '24· AI Ethics, Fairness & Accountability +2
- 71%
IoTBeholder: A Privacy Snooping Attack on User Habitual Behaviors from Smart Home Wi-Fi Traffic
UbiComp '23· Privacy by Design & User Control +2
- 67%
Contextualizing Privacy Decisions for Better Prediction (and Protection)
CHI '18· Privacy by Design & User Control +1
- 67%
A Field Study of Computer-Security Perceptions Using Anti-Virus Customer-Support Chats
CHI '19· Privacy by Design & User Control +1
- 67%
On the Usability of HTTPS Deployment
CHI '19· Privacy by Design & User Control +1
- 67%
Privacy Champions in Software Teams: Understanding Their Motivations, Strategies, and Challenges
CHI '21· Privacy by Design & User Control +1
- 67%
No Silver Bullet: Towards Demonstrating Secure Software Development for Small and Medium Enterprises in a Business-to-Business Model
CHI '25· Privacy by Design & User Control +1
Based on Jaccard similarity of research subtopics & professions (≥60%)