The General Data Protection Regulation (GDPR) is considered as the benchmark in the European Union (EU) for privacy and data protection standards. Since before its entry into force in 2018, substantial research has been conducted in the software engineering (SE) literature investigating the elicitation, representation, and verification of GDPR privacy requirements. Software systems deployed anywhere in the world must comply with GDPR as long as they handle personal data of EU residents. Mobile applications (apps) are no different in that regard. With the growing pervasiveness of mobile apps and their increasing demand for personal data, privacy concerns have acquired further interest within the SE community. Despite the extensive literature on GDPR-relevant privacy concerns in mobile apps, there is no secondary study that describes, analyzes, and categorizes the current focus. Research gaps and persistent challenges are thus left unnoticed. This article aims to provide a comprehensive overview of the existing research on GDPR privacy concerns in the context of mobile apps. To do so, we conducted a systematic literature review of 60 primary studies. Our findings show that existing studies predominantly address three key GDPR-related privacy concerns: (i) the direct collection of personal data from users, (ii) the sharing of personal data with external entities (e.g., third parties) beyond the mobile apps, and (iii) the analysis of user consent as a legal basis for collecting personal data. Our study highlighted research gaps, calling for further research to better understand: (i) the indirect collection of personal data, e.g., data exposed to mobile apps through, e.g., permission requests, (ii) the impact of legal bases beyond consent and how they may affect the development of mobile apps, and (iii) the required implementation details pertinent to data subject rights.
翻译:《通用数据保护条例》(GDPR)被视为欧盟(EU)隐私与数据保护标准的基准。自其于2018年生效之前,软件工程(SE)文献中已开展了大量研究,探讨GDPR隐私需求的获取、表示与验证。只要处理欧盟居民的个人数据,部署于世界任何地方的软件系统都必须遵守GDPR。移动应用程序(apps)在这方面亦无例外。随着移动应用的日益普及及其对个人数据需求的增长,隐私关切在SE领域引起了更多关注。尽管已有大量关于移动应用中GDPR相关隐私关切的文献,但尚无次级研究对当前研究焦点进行描述、分析与分类。因此,研究空白与持续存在的挑战尚未被察觉。本文旨在全面概述移动应用背景下GDPR隐私关切的现有研究。为此,我们对60项原始研究进行了系统性文献综述。我们的研究结果表明,现有研究主要关注三个关键的GDPR相关隐私关切:(i)直接从用户处收集个人数据,(ii)将个人数据共享给移动应用之外的外部实体(例如第三方),以及(iii)将用户同意作为收集个人数据的法律依据进行分析。我们的研究揭示了研究空白,呼吁进一步研究以更好地理解:(i)个人数据的间接收集,例如通过权限请求等方式向移动应用暴露的数据,(ii)同意之外的其他法律依据的影响及其如何可能影响移动应用的开发,以及(iii)与数据主体权利相关的必要实施细节。