KIT | KIT-Bibliothek | Impressum | Datenschutz

The whos, whats, and whys of issues related to personal data and data protection in open-source projects on GitHub

Hennig, Anne ORCID iD icon 1; Schulte, Lukas; Herbold, Steffen; Kulyk, Oksana; Mayer, Peter ORCID iD icon 1
1 Institut für Angewandte Informatik und Formale Beschreibungsverfahren (AIFB), Karlsruher Institut für Technologie (KIT)

Abstract:

Data protection regulations such as the General Data Protection Regulation (GDPR) in the European Union and the California Consumer Privacy Act (CCPA) in the US affect how software may handle the personal data of its users. Prior literature focused on how data protection regulations are discussed for software in operation, or how this topic is discussed in various channels outside of the software development process. Yet, what is missing, is a perspective on the impact of such regulations on the software development process. In our work, we address this gap, and explore how discussions during the development of software are impacted by regulations, who reports and discusses issues related to personal data and data protection, and how developers react to those issues. To that end, we used inductive coding to analyze 652 issues from Open Source GitHub projects and used the codes to quantitatively analyze the relation between the roles, resolutions, and data protection issues to understand correlations and predict resolutions of issues. Most notably we observed a significant increase in reporting when GDPR came into effect. The most common issue types were feature requests for privacy enhancement, which were mainly reported and discussed by frequent reporters and frequent committers. ... mehr


Verlagsausgabe §
DOI: 10.5445/IR/1000187808
Veröffentlicht am 02.12.2025
Cover der Publikation
Zugehörige Institution(en) am KIT Institut für Angewandte Informatik und Formale Beschreibungsverfahren (AIFB)
Kompetenzzentrum für angewandte Sicherheitstechnologie (KASTEL)
Publikationstyp Zeitschriftenaufsatz
Publikationsmonat/-jahr 11.2025
Sprache Englisch
Identifikator ISSN: 1382-3256, 1573-7616
KITopen-ID: 1000187808
HGF-Programm 46.23.01 (POF IV, LK 01) Methods for Engineering Secure Systems
Erschienen in Empirical Software Engineering
Verlag Springer
Band 31
Heft 1
Seiten 9
Vorab online veröffentlicht am 04.11.2025
Nachgewiesen in OpenAlex
Dimensions
Web of Science
Scopus
KIT – Die Universität in der Helmholtz-Gemeinschaft
KITopen Landing Page