GDPR-Relevant Privacy Concerns in Mobile Apps Research: A Systematic Literature Review
Summary
A systematic literature review (SLR) analyzed 60 primary studies published between 2016 and 2023, investigating GDPR-relevant privacy concerns in mobile applications. The review, utilizing a comprehensive conceptual model with 56 information types, found that current research often reflects a shallow understanding of GDPR requirements. The majority of studies (49 out of 60) primarily focus on three areas: sharing personal data with third-party libraries to identify data leaks, mechanisms for acquiring explicit user consent, and direct collection of various personal data categories. Critically, fundamental GDPR concepts like data subject rights (e.g., right to access, erasure, withdraw consent) and legal bases beyond consent (e.g., legitimate interest) remain significantly under-explored. The SLR also noted that only 14 of the 60 studies (approximately 23%) made their research artifacts publicly available, indicating a need for improved open science practices within the software engineering community.
Key takeaway
For software engineers and legal professionals developing mobile applications, you must move beyond basic consent mechanisms and third-party data sharing. Focus on comprehensively implementing data subject rights, such as access and erasure, directly within your apps. Additionally, explore and integrate other legal bases for data processing beyond explicit consent to ensure full GDPR compliance and mitigate significant regulatory risks. Improve transparency by verifying app behavior against stated privacy policies.
Key insights
Mobile app privacy research under-explores critical GDPR aspects like data subject rights and diverse legal bases, focusing narrowly on consent and data sharing.
Principles
- GDPR compliance extends beyond explicit consent.
- Data subject rights are fundamental for app compliance.
- Data minimization is a core GDPR principle.
Method
A Systematic Literature Review (SLR) analyzed 60 primary studies (2016-2023) using Kitchenham and Charters guidelines. It involved paper extraction, selection, and data extraction, mapping findings to Amaral et al.'s 56-information-type GDPR conceptual model with 0.94 inter-rater agreement.
In practice
- Investigate indirect personal data collection.
- Implement data subject rights within mobile apps.
- Share research artifacts with appropriate licenses.
Topics
- GDPR Compliance
- Mobile App Privacy
- Data Subject Rights
- Requirements Engineering
- Systematic Literature Review
- Data Minimization
Code references
Best for: Research Scientist, Software Engineer, Legal Professional
Related on AIssential
See Counsel's argued verdicts on the open AI decisions leaders are weighing →
Editorial summary, takeaway, and curation by AIssential. Original article published by cs.SE updates on arXiv.org.