<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Usable Privacy: A Study of Norwegian Software Development Practices</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Synne Stokkevåg Berg</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Katrien De Moor</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>NTNU - Norwegian University of Science and Technology</institution>
          ,
          <addr-line>Trondheim</addr-line>
          ,
          <country country="NO">Norway</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>Despite the increased focus on privacy and adoption of comprehensive data privacy laws such as the GDPR, there is still a notable absence of developer guidelines with a focus on making privacy usable, and the related practices and challenges are still poorly understood. In this context, the present study explores the current landscape of usable privacy within software development, using Norway as a case study. By means of an online survey, insights were gathered from a sample consisting of 128 developers, designers, security specialists, and related professionals. It addresses aspects such as the awareness of privacy guidelines, implementation practices, as well as challenges related to efectively incorporating privacy into software development processes. The results indicate that knowledge gaps, complicated terminology, and a lack of easily accessible toolkits and guidelines persist as barriers. Additionally, cultural attitudes towards privacy and competing priorities further obstruct the efective integration of privacy measures. Better insights into usable privacy practices can help close the gap between the technical, legal, and user-centric dimensions of privacy, aiming for a digital landscape that is both transparent and oriented toward user needs.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;Privacy</kwd>
        <kwd>usability</kwd>
        <kwd>software development</kwd>
        <kwd>case study</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction and Motivation</title>
      <p>
        The evolving digital landscape and technological advancements have transformed how people
communicate, work, and live. However, this convenience comes at the cost of privacy, as every
online activity creates a digital trace, increasing the risk of data breaches and misuse. Navigating
and understanding complex privacy policies and settings can be challenging, often resulting in
uninformed consent [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. An underlying explanation for this is that few solutions efectively
address both privacy and usability at the same time [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. Saltarella et al.’s study [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ] systematically
reviews the translation of Privacy-By-Design and Privacy-By-Default principles into software
requirements and their integration with Human-Centered Design. On one hand, comprehensive
consumer data privacy laws have been developed to regulate the collection, use, and sharing
of personal data, such as the General Data Protection Regulation (GDPR) [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]. However, these
regulations often fall short in providing specific guidelines for developers, overlooking the
importance of usability in privacy protection [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. On the other hand, advancements in the field
of Human-Computer Interaction (HCI) help enhance user experience (UX) through intuitive
design and human-centered design processes. However, HCI experts are still not involved
enough in the development process of privacy solutions [
        <xref ref-type="bibr" rid="ref2 ref4">2, 4</xref>
        ]. Therefore, despite the progress
made in both the legal and the HCI domains, the convergence of privacy regulations and HCI
principles remains insuficient and may lead to a significant gap in the creation of software that
is both privacy-conscious and user-friendly.
      </p>
      <p>
        Ackerman and Mainwaring’s study [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ] revealed varied user privacy concerns, from
unauthorized information access and data misuse to discomfort with data collection. Mistrust towards
companies handling personal data is also a concern [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ], and Gundersen found that users often
struggle with managing privacy settings, indicating a gap in the design of user-friendly privacy
controls [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. Earlier research further suggests that a holistic approach to privacy in software
development can help bridge the gap between technical processes, users’ expectations, and
regulatory requirements, fostering a more transparent and protective digital environment [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ].
Research targeting a better understanding of how contributors within software development
perceive and respond to privacy-related issues can help identify the most pertinent challenges and
hurdles that might prevent user-centric and privacy-preserving actions from being practiced.
      </p>
      <p>This study investigates how software developers in Norway integrate user-centric privacy,
addressing the gap in practice-oriented research. Using Norway as a case study is particularly
interesting due to its high level of digitization, strong emphasis on privacy, and strict data
protection laws. It examines professionals’ awareness of usable privacy, their strategies, practices,
and the obstacles to embedding privacy into development processes. Based on an overview of
the related work (Section 2), we conducted an online survey targeting developers, designers,
security specialists, and privacy experts (N=128), as briefly described in Section 3. Next, we
present the results in Section 4. Finally, Section 5 discusses the implications of the findings and
concludes the paper.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Background and Related Work</title>
      <p>
        The European General Data Protection Regulation (GDPR) sets the framework for collecting,
storing, and processing personal data, defining it as any information relating to an identifiable
person [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]. This includes identifiable, anonymous, and pseudonymous data, each posing unique
challenges for privacy and security. Despite the supposed anonymity, re-identifying individuals
from such data is often possible, underscoring the complexity of data protection and the
necessity for strict regulations [
        <xref ref-type="bibr" rid="ref6 ref7">6, 7</xref>
        ]. It is worth noting that there is a high bar for data to be
considered truly anonymous under the GDPR [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]. Addressing developer misconceptions about
what constitutes anonymous data is therefore crucial.
      </p>
      <p>
        At the research side, the evolution of digital technology has significantly expanded the scope
of personal data collection, leading to the era of Big Data. This paradigm shift, characterized by
the vast accumulation and analysis of digital information, has profound privacy implications [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ].
While Big Data presents new opportunities for business and operational improvements, it
also poses substantial risks to individual privacy, underscoring the important balance between
technological advancement and data protection [
        <xref ref-type="bibr" rid="ref6 ref7">6, 7</xref>
        ]. In this context, Birch et al. [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ], for
instance, highlighted how personal data has transitioned from mere information to a critical
asset and, correspondingly, how Big Tech’s economic interests may overshadow eforts to
enhance privacy management. While the GDPR applies broadly (partly in response to the above
developments) and demands legal basis for processing, such as consent, purpose limitation, and
minimization [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ], a key challenge remains, also years after GDPR’s implementation, in bridging
the gap between its legal requirements and their practical implementation in software. This
has e.g., been ascribed to the fact that developers often lack clear guidance, with the GDPR’s
content being mostly legal and bureaucratic in nature [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ].
      </p>
      <p>
        In this overall context with potentially conflicting stakes, balancing user experience with
privacy and security is challenging. Security and UI/UX improvements often occur after system
development, treating these critical elements as add-ons [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ]. This is problematic, as Yee [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ]
pointed to when stating that “Security and usability elements can’t be sprinkled on a product like
magic pixie dust”, emphasizing the need for their integration from the design phase to ensure
intuitive and accessible privacy solutions. In this regard, Article 25 of the GDPR, entitled “Data
protection by design and by default,” more specifically emphasizes the need for early integration
of privacy into the design and operation of information systems, promoting a proactive and
user-centric approach to privacy [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]. It highlights the concept of “Privacy by Design”, which
focuses on privacy protection throughout the development process, and “Privacy by Default”,
which ensures minimal personal data processing [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]. However, despite the inclusion of these
principles , challenges related to their practical implementation persist, often due to the GDPR’s
abstract nature [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ].
      </p>
      <p>
        Yet, various eforts have been made to operationalize the above principles, notably by Ann
Cavoukian’s “Privacy by Design”-framework [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ], which outlines seven core principles for
embedding privacy into system design from the start [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. Additionally, Hoepman’s “Privacy
Design Strategies” provide IT developers with concrete guidelines for integrating privacy into
their projects [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ]. In 2017, the Norwegian Data Protection Authority issued guidelines to
help organizations comply with the GDPR’s Article 25 [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ]. These guidelines outline a
sevenstep process for embedding data protection in development, from training developers in data
protection to maintenance, including incident response and updates [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ]. However, there’s
a noted lack of emphasis on usability and uncertainty regarding developers’ awareness of
these frameworks. Furthermore, recent studies indicated that translating the key principles
into practical software development requirements remains challenging [
        <xref ref-type="bibr" rid="ref14 ref2 ref8">8, 2, 14</xref>
        ]. Software
engineers may disregard methodologies that do not align with standard software practices,
facing limitations in privacy solutions and a lack of systematic feedback guidelines [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ]. Despite
various technical solutions for regulatory compliance, more work is needed to enhance user
experience [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ] and to make privacy usable for all.
      </p>
      <p>
        The underlying idea of “usable privacy” is to ensure that privacy settings are accessible to all
users, regardless of technical expertise. Usable systems enable users to manage their privacy
without understanding the system’s inner workings [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ]. The significance of usable privacy in
ensuring settings and policies are manageable by all is underlined, with Wong and Mulligan
noting usability’s positive impact on satisfaction and policy adherence, while also warning
against the risks of overlooking usability [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]. However, a complicating factor in realizing major
advancements in this respect is also the fragmentation of privacy responsibility across sectors
and roles, with Wong and Mulligan [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ] noting that these responsibilities get fragmented among
technology design, law, and social norms, preventing any single entity from fully ensuring
usable privacy. They mention that while many companies have skilled UX designers/HCI
experts, the latter are not always engaged in privacy eforts [
        <xref ref-type="bibr" rid="ref2 ref4">4, 2</xref>
        ]. Diferences in privacy
perspectives between designers and developers lead to varied implementation approaches [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ].
      </p>
      <p>
        The usability of privacy is further compromised by developers’ inadequate privacy knowledge,
as detailed by Saltarella et al., emphasizing the challenge of comprehending privacy’s legal and
technical dimensions [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. Wong and Mulligan also note a potential gap in designers’ knowledge
about security and privacy [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]. The integration of HCI into privacy eforts is challenged by the
need for stakeholders to understand system functionalities and legal implications
comprehensively [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. Saltarella et al., in this regard, point to the need for methodologies that blend privacy
with HCI to satisfy user preferences and legal requirements. They also highlight the dificulty in
translating user-focused frameworks into practical applications and the importance of
developing clear, user-centric guidelines [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. The potential under-utilization of HCI-skilled professionals
in privacy projects further underlines the need to improve collaboration between designers and
developers with difering privacy views and to address developers’ privacy knowledge gaps
through specialized education and training [
        <xref ref-type="bibr" rid="ref2 ref8">2, 8</xref>
        ].
      </p>
      <p>In summary, various challenges have already been identified in the literature, however,
empirical data supporting the above observations and assumptions and hypotheses they trigger,
is still sparse. There is still a large need for better insights into the current practices, strategies,
and the barriers and challenges at hand. Moreover, to the best of our knowledge, no studies
have explicitly investigated the practices around usable privacy in the Norwegian context.
Addressing the above knowledge gaps is, therefore, essential for defining concrete measures
toward the successful integration of usable privacy initiatives.</p>
    </sec>
    <sec id="sec-3">
      <title>3. Methodology</title>
      <sec id="sec-3-1">
        <title>3.1. Survey design and implementation</title>
        <p>
          A comprehensive approach is needed to explore the multifaceted perspectives, strategies, and
barriers involved in integrating usable privacy into software. While the overall project
underlying this work is based on a mixed-method methodology that also includes semi-structured
interviews, the findings presented in this paper are based on an online survey study that was
conducted. Online surveys facilitate eficient data gathering to address a specific research
question, in this case privacy practices, attitudes, strategies and concerns of professionals within
the Norwegian software development landscape. The survey was administered in “Nettskjema”,
a secure, privacy-preserving data collection tool in Norway [
          <xref ref-type="bibr" rid="ref16">16</xref>
          ]. The survey aimed to blend
insights from literature with personal experiences in the IT industry, drawing from academic
and professional backgrounds in security, development, and design. The survey was structured
as follows: (1) personal questions to identify the respondents, (2) a series of statements to map
the general attitudes and experiences of the respondents, before asking more specific questions
regarding (3) awareness and understanding of privacy, (4) being updated on privacy regulations,
(5) organizational practices, collaboration and integration of privacy in the development process,
(6) challenges of implementing usable privacy, (7) current solutions, and (8) future directions.
The survey was pre-tested with software developers pre-launch (February 2024).
        </p>
      </sec>
      <sec id="sec-3-2">
        <title>3.2. Sample description and recruitment</title>
        <p>Targeting a diverse audience within the software development lifecycle, from developers to legal
advisors, was essential for gathering comprehensive insights. The distribution strategy involved
direct contacts, social media platforms like LinkedIn, and specialized groups such as Slack
channels for security champions, maximizing reach and diversity in responses. This multifaceted
approach facilitated broad participation and enriched the study with varied perspectives on
integrating privacy into software development.</p>
        <p>In total, 128 professionals from the Norwegian software development landscape with
different backgrounds and professional experiences participated. In terms of gender, 75% of the
participants identify as male, 23% as female, and 2% preferred not to say. The average age is 36
(S.D. 10.32), and 68.8% of the respondents are in the age group of 25-44. In terms of education,
28% of the participants hold a bachelor’s degree, and 66% a master’s or higher.</p>
        <p>IT consultancy firms are the most represented organization type (59%), followed by in-house
IT firms (23%), and IT startups (6%). Regarding further employment characteristics, 62% works
in the private sector and 38% in the public sector. The employment sectors represented are also
diverse, including 16% in healthcare and welfare, 13% in media and entertainment, and 12% in
energy and oil, among others. Participants further difer in their roles within their companies,
with 58% serving as software developers, 13% as security specialists, and 8% as designers, among
other positions. Respondents’ experience levels within software development vary widely, from
up to 2 years (14%), 2-4 years (31%), 5 to 10 years (13%), 10 to 19 years (20%), and more than 19
years of experience (22%), hence assuring that diverse perspectives were captured.</p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>4. Results</title>
      <p>Awareness and understanding. First, we consider the respondents’ awareness and
understanding of privacy, as visualized in Figure 1. In this respect, nearly 7 out of 10 respondents agreed
that they have a good understanding of privacy regulations related to software development.
Additionally, more than half of the respondents agreed that they are aware of the challenges
associated with integrating usable privacy.</p>
      <p>Organizational practices and collaboration. When it comes to organizational practices and
collaboration, only 54% agreed that diferent roles in their organization collaborate efectively to
address privacy issues. Further, less than one-third of the respondents indicated that they are
provided with adequate organizational support for integrating privacy in software development
(Figure 1), and 1 out of 2 respondents disagreed that there are uniform privacy approaches across
teams and clearly defined responsibilities concerning usable privacy within their organization.</p>
      <p>Integration of privacy in the development process. As illustrated in Figure 1, more than
1 out of 2 respondents agreed that their team’s privacy eforts meet only minimal requirements.
Privacy concerns being prioritized and addressed early in the development cycle yielded more
mixed opinions: 38% agreed, and 38% disagreed. Finally, when asked about challenges of
implementing usable privacy, 52% indicated facing challenges in implementing usable privacy, and
56% agreed that privacy often conflicts with usability/UX goals.</p>
      <p>Design frameworks and compliance with guidelines. Among those respondents who
utilize design frameworks (representing 52% of the respondents), only 23% acknowledge the
incorporation of privacy considerations into these methodologies. Others are unsure (39%) or
indicated that privacy is not integrated and evaluated in these design processes (38%). Regarding
the guidelines developed by the Norwegian Data Protection Authority, 38% reported familiarity
with the guidelines but hadn’t read them, while only 23% reported having read and occasionally
or regularly used them in their work.</p>
      <p>Main barriers. Figure 2 shows the responses regarding the main barriers to implementing
usable privacy in software as reported by practitioners. The findings indicate that insuficient
knowledge constitutes a significant obstacle, identified by more than half of the respondents.
Additionally, both challenges of balancing privacy concerns with other requirements and budget
constraints were highlighted by around 4 out of 10 participants. Additional barriers highlighted
in an open question included: complicated terminology, leaving much of the implementation to
individual interpretation, overly specific regulations hindering UX, poor collaboration between
lawyers and designers, minimal consequences for non-compliance, insuficient support tools
for privacy by design in agile environments, complex regulations leading to user click-fatigue,
and conflicting customer interests.</p>
      <p>Training or resources. Training or resources to enhance usable privacy can play an important
role in this respect. Figure 2 shows the practitioners’ preferences: nearly 6 out of 10 prefer
technical guides and toolkits for developing and testing privacy features. Further, nearly half
of the respondents want hands-on workshops on privacy integration, and 4 out of 10 want
collaboration with privacy experts or legal advisors for legal insights.</p>
      <p>Additional feedback. In the survey’s open-ended section, many respondents provided
additional comments. Here, one respondent suggested that the dichotomy between user
experience and privacy is false and that both can be harmoniously integrated. In addition, cultural
issues, including a systemic disregard for privacy in software development, were mentioned
to contribute to viewing privacy as peripheral. Further, it was put forward that challenges in
prioritizing privacy in client projects, especially startups, arise due to a focus on legal
minimums over substantial privacy considerations. Overall, several respondents also called for more
practical resources, such as case studies and pattern descriptions, and accessible templates or
checklists from regulatory entities (such as the Norwegian Data Protection Authority) to aid
development. Finally, a lack of leadership support for user-friendly privacy options was noted,
stemming from misconceptions about data collection limitations and cost implications.</p>
    </sec>
    <sec id="sec-5">
      <title>5. Discussion and Conclusion</title>
      <p>
        In this study, we investigated the current practices around usable privacy in Norwegian software
development, focusing on uncovering practitioners (N=128) attitudes, practices, and encountered
challenges. Although a significant percentage of participants (68%) believe that they understand
privacy regulations well, this self-reported proficiency appears to contrast with prior studies ,
which shows a general lack of privacy knowledge among developers [
        <xref ref-type="bibr" rid="ref2 ref4 ref8">8, 2, 4</xref>
        ]. This discrepancy
suggests that developers might overestimate their understanding of privacy laws. Interestingly,
“a limited understanding of privacy” was identified as a major barrier to implementing efective
privacy measures, indicating a gap in privacy education and a potential area for future research
and tailored measures.
      </p>
      <p>Figure 1: Self-reported attitudes and experiences (percentages, N=128).</p>
      <p>The findings also reveal that respondents are aware of (52%) and have experienced (52%)
challenges in applying privacy in practice, suggesting a gap between knowledge about privacy
principles and the ability to apply them efectively. Additionally, many respondents agreed
that their team’s approach to privacy is primarily focused on meeting minimal requirements,
underscoring compliance-first mindsets rather than comprehensive privacy strategies (see
Figure 1). The preference for “Technical guides and toolkits” (59%) highlights the need for
practical tools to help integrate privacy into development work, such as case studies, pattern
descriptions, and easily accessible templates or checklists from regulatory bodies (such as the
Norwegian Data Protection Authority). Implicitly, the findings also illustrate the gap between
academic research and actual real-world practice when it comes to usable privacy.</p>
      <p>
        The data from Figure 2 further highlight the key challenges in implementing usable privacy
in Norway, with insuficient knowledge marked as a significant barrier by many respondents.
This issue, alongside balancing privacy with other demands and budget limits, points to the
complex hurdles in privacy-centric software development. Interest in workshops and expert
collaboration suggests a desire for experiential learning and deeper legal understanding. In
line with [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ], additional barriers such as unclear terminology and regulatory challenges stress
the need for better education. Through the open-ended responses, it was also suggested that
the culture around privacy plays an important role, next to knowledge, tools and skills. This
perspective, particularly prevalent in client projects and startups, may lead to challenges in
prioritizing comprehensive privacy considerations, with a tendency to focus on meeting legal
minimums rather than embedding substantive privacy measures.
      </p>
      <p>Overall, this study illustrated the nuanced challenges and perceptions surrounding privacy
within Norwegian software development. It underscores the existence of knowledge gaps.
Despite developers’ awareness of privacy challenges, there seems to be a notable gap in
applying privacy principles efectively, driven by a compliance-first mindset rather than a holistic
approach to privacy. The demand for practical tools, such as technical guides and workshops,
underscores the need for improved privacy education and resources to bridge the gap
between theoretical knowledge and its practical application. Addressing these needs is crucial for
enhancing usable privacy in software development.</p>
      <p>In future work, we plan to analyze the potential diferences between professional roles,
companies, and domains, as well as conduct in-depth interviews to deepen the insights from the
survey. Additionally, follow-up work should consider a larger sample, include other countries
and diverse perspectives, and explore which tools, strategies, and collaborative eforts can
contribute to the creation of both regulatory-compliant and user-friendly privacy solutions in
practice.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <surname>I. Gundersen</surname>
          </string-name>
          ,
          <article-title>Privacy Management and Preservation in the Era of Targeted Advertising, Master's thesis</article-title>
          , Norwegian University of Science and Technology,
          <year>2022</year>
          . URL: https:// hdl.handle.net/11250/3026224.
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>M.</given-names>
            <surname>Saltarella</surname>
          </string-name>
          , G. Desolda,
          <string-name>
            <given-names>R.</given-names>
            <surname>Lanzilotti</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V. S.</given-names>
            <surname>Barletta</surname>
          </string-name>
          ,
          <article-title>Translating privacy design principles into human-centered software lifecycle: A literature review</article-title>
          ,
          <source>International Journal of Human-Computer Interaction</source>
          (
          <year>2023</year>
          ). doi:
          <volume>10</volume>
          .1080/10447318.
          <year>2023</year>
          .
          <volume>2219964</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3] EU regulation
          <year>2016</year>
          /679 (
          <article-title>General Data Protection Regulation) on personal data protection</article-title>
          ,
          <year>2016</year>
          . URL: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:
          <fpage>32016R0679</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>R. Y.</given-names>
            <surname>Wong</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D. K.</given-names>
            <surname>Mulligan</surname>
          </string-name>
          ,
          <article-title>Bringing design to the privacy table broadening "design" in "privacy by design" through the lens of HCI</article-title>
          ,
          <source>in: ACM Conference on Human Factors in Computing Systems</source>
          ,
          <year>2019</year>
          . doi:
          <volume>10</volume>
          .1145/3290605.3300492.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>M. S.</given-names>
            <surname>Ackerman</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S. D.</given-names>
            <surname>Mainwaring</surname>
          </string-name>
          ,
          <article-title>Privacy issues and human-computer interaction</article-title>
          ,
          <year>2008</year>
          . URL: https://api.semanticscholar.org/CorpusID:14493572.
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>N.</given-names>
            <surname>Gruschka</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Mavroeidis</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Vishi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Jensen</surname>
          </string-name>
          ,
          <article-title>Privacy issues and data protection in big data: A case study analysis under gdpr</article-title>
          ,
          <source>in: 2018 IEEE International Conference on Big Data (Big Data)</source>
          ,
          <year>2018</year>
          , pp.
          <fpage>5027</fpage>
          -
          <lpage>5033</lpage>
          . doi:
          <volume>10</volume>
          .1109/BigData.
          <year>2018</year>
          .
          <volume>8622621</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>K.</given-names>
            <surname>Birch</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Cochrane</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Ward</surname>
          </string-name>
          ,
          <article-title>Data as asset? the measurement, governance, and valuation of digital personal data by big tech</article-title>
          ,
          <source>Big Data &amp; Society</source>
          <volume>8</volume>
          (
          <year>2021</year>
          ). doi:
          <volume>10</volume>
          .1177/ 20539517211017308.
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>V.</given-names>
            <surname>Barletta</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G.</given-names>
            <surname>Desolda</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Gigante</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Lanzilotti</surname>
          </string-name>
          ,
          <string-name>
            <surname>M.</surname>
          </string-name>
          <article-title>Saltarella, From GDPR to privacy design patterns: The MATERIALIST framework (</article-title>
          <year>2022</year>
          )
          <fpage>642</fpage>
          -
          <lpage>648</lpage>
          . doi:
          <volume>10</volume>
          .5220/ 0011305900003283.
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>M.</given-names>
            <surname>Alshamari</surname>
          </string-name>
          ,
          <article-title>A review of gaps between usability</article-title>
          and security/privacy,
          <source>International Journal of Communications, Network and System Sciences</source>
          <volume>9</volume>
          (
          <year>2016</year>
          )
          <fpage>413</fpage>
          -
          <lpage>429</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <surname>K.-P. Yee</surname>
          </string-name>
          ,
          <article-title>Aligning security and usability</article-title>
          ,
          <source>IEEE Security &amp; Privacy</source>
          <volume>2</volume>
          (
          <year>2004</year>
          )
          <fpage>48</fpage>
          -
          <lpage>55</lpage>
          . doi:
          <volume>10</volume>
          .1109/MSP.
          <year>2004</year>
          .
          <volume>64</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>A.</given-names>
            <surname>Cavoukian</surname>
          </string-name>
          ,
          <article-title>Privacy by design: the 7 foundational principles</article-title>
          ,
          <source>Information and privacy commissioner of Ontario, Canada</source>
          <volume>5</volume>
          (
          <year>2009</year>
          )
          <fpage>12</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <surname>J.-H. Hoepman</surname>
          </string-name>
          ,
          <article-title>Privacy Design Strategies (The Little Blue Book)</article-title>
          , Nijmegen : Radboud University,
          <year>2018</year>
          . URL: https://www.cs.ru.nl/~jhh/publications/pds-booklet.pdf.
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>Norwegian</given-names>
            <surname>Data Protection Authority</surname>
          </string-name>
          ,
          <article-title>Software development with data protection by design and by default</article-title>
          ,
          <year>2017</year>
          . URL: https://www.datatilsynet.no/en/about-privacy/
          <article-title>virksomhetenes-plikter/data-protection-by-design-and-by-default/.</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>J. C.</given-names>
            <surname>Caiza</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.-S.</given-names>
            <surname>Martín</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D. S.</given-names>
            <surname>Guamán</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J. M.</given-names>
            <surname>Del Alamo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J. C.</given-names>
            <surname>Yelmo</surname>
          </string-name>
          ,
          <article-title>Reusable elements for the systematic design of privacy-friendly information systems: A mapping study</article-title>
          ,
          <source>IEEE Access 7</source>
          (
          <year>2019</year>
          )
          <fpage>66512</fpage>
          -
          <lpage>66535</lpage>
          . doi:
          <volume>10</volume>
          .1109/ACCESS.
          <year>2019</year>
          .
          <volume>2918003</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>A.</given-names>
            <surname>Pattakou</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.-G.</given-names>
            <surname>Mavroeidi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Diamantopoulou</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Kalloniatis</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Gritzalis</surname>
          </string-name>
          ,
          <article-title>Towards the design of usable privacy by design methodologies</article-title>
          ,
          <source>in: 2018 IEEE 5th International Workshop on Evolving Security &amp; Privacy Requirements Engineering (ESPRE)</source>
          ,
          <year>2018</year>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>8</lpage>
          . doi:
          <volume>10</volume>
          .1109/ESPRE.
          <year>2018</year>
          .
          <volume>00007</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <surname>Nettskjema's website</surname>
          </string-name>
          ,
          <year>2024</year>
          . URL: https://nettskjema.no/.
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>