Bridging the Privacy Gap: Developers' Practices and the Missing Role of Privacy Engineers
Authors/Creators
Description
Context: Privacy has become a first order concern in software engineering, yet organizations still struggle to translate legal mandates into actionable engineering practices. Goal: This study investigates how Brazilian software practitioners perceive and operationalize privacy standards/practices, identifying challenges and actionable opportunities. Method: We conduct a conceptual replication of prior work, adapting it to the Brazilian context via survey (31 practitioners). The instrument maps privacy-related perceptions and practices, the use of standards, frameworks, and techniques, organizational responsibility allocation, perceived challenges, and improvement opportunities. Results: Practitioners consistently distinguish privacy from security, but formalization is limited. Although 60.7% report considering privacy across the software development, half do not use privacy-focused methods, and a substantial portion (46.4%) report being unaware of such approaches. Practices skew toward classic security controls (e.g., access control, 85.7%) rather than dedicated privacy engineering artifacts. The Brazilian General Data Protection Law (LGPD) is the dominant compliance driver (82.1%), with low uptake of ISO 27701/NIST. Key barriers include unclear legal guidance (53.6%), insufficient training (42.9%), and late integration of privacy (39.3%). Automation remains incipient (14.3% fully automated; 42.9% manual). Organizational support is uneven (39.3% sufficient; 39.3% partial; 21.4% insufficient). Applying the Spearman correlation test revealed strong relationships (ρ up to 0.63) between experience, training, and integration practices, indicating that professional maturity and capacity building are strongly associated with privacy-by-design adoption. Conclusion: Results indicate a persistent gap between awareness and effective governance. We recommend (i) targeted training and curricular inclusion, (ii) clearer role/accountability assignments, and (iii) investment in tooling/automation to operationalize privacy-by-design. These actions can help shift privacy from reactive compliance to a sustained dimension in Brazilian organizations.
Files
Privacy-related perceptions, practices and challenges Survey - Google Forms.pdf
Additional details
Dates
- Accepted
-
2025-11-14