Published April 10, 2026 | Version v2

Bridging the Privacy Gap: Developers' Practices and the Missing Role of Privacy Engineers

  • 1. EDMO icon Universidade Federal de Pernambuco
  • 2. ROR icon Universidade de Brasília

Description

Context: Privacy has become a first order concern in software engineering, yet organizations still struggle to translate legal mandates into actionable engineering practices. Goal: This study investigates how Brazilian software practitioners perceive and operationalize privacy standards/practices, identifying challenges and actionable opportunities. Method: We conduct a conceptual replication of prior work, adapting it to the Brazilian context via survey (31 practitioners). The instrument maps privacy-related perceptions and practices, the use of standards, frameworks, and techniques, organizational responsibility allocation, perceived challenges, and improvement opportunities. Results: Practitioners consistently distinguish privacy from security, but formalization is limited. Although 60.7% report considering privacy across the software development, half do not use privacy-focused methods, and a substantial portion (46.4%) report being unaware of such approaches. Practices skew toward classic security controls (e.g., access control, 85.7%) rather than dedicated privacy engineering artifacts. The Brazilian General Data Protection Law (LGPD) is the dominant compliance driver (82.1%), with low uptake of ISO 27701/NIST. Key barriers include unclear legal guidance (53.6%), insufficient training (42.9%), and late integration of privacy (39.3%). Automation remains incipient (14.3% fully automated; 42.9% manual). Organizational support is uneven (39.3% sufficient; 39.3% partial; 21.4% insufficient). Applying the Spearman correlation test revealed strong relationships (ρ up to 0.63) between experience, training, and integration practices, indicating that professional maturity and capacity building are strongly associated with privacy-by-design adoption. Conclusion: Results indicate a persistent gap between awareness and effective governance. We recommend (i) targeted training and curricular inclusion, (ii) clearer role/accountability assignments, and (iii) investment in tooling/automation to operationalize privacy-by-design. These actions can help shift privacy from reactive compliance to a sustained dimension in Brazilian organizations.

Files

Privacy-related perceptions, practices and challenges Survey - Google Forms.pdf

Files (318.2 kB)

Name Size Download all
md5:ceba5d895ece6d8e141ec5b242723d6f
51.2 kB Preview Download
md5:fa60b6ed16eeb67598d2abcffee12206
258.7 kB Preview Download
md5:18f0589f9eed82b6bf3ce1c9a1b8969a
8.3 kB Download

Additional details

Dates

Accepted
2025-11-14