{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,21]],"date-time":"2026-08-21T12:43:48Z","timestamp":1787316228612,"version":"build-2736575974"},"reference-count":99,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2022,11,4]],"date-time":"2022-11-04T00:00:00Z","timestamp":1667520000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2022,11,4]],"date-time":"2022-11-04T00:00:00Z","timestamp":1667520000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Requirements Eng"],"published-print":{"date-parts":[[2022,12]]},"DOI":"10.1007\/s00766-022-00391-7","type":"journal-article","created":{"date-parts":[[2022,11,4]],"date-time":"2022-11-04T06:03:37Z","timestamp":1667541817000},"page":"545-567","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":30,"title":["Guidelines adopted by agile teams in privacy requirements elicitation after the Brazilian general data protection law (LGPD) implementation"],"prefix":"10.1007","volume":"27","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2159-339X","authenticated-orcid":false,"given":"Edna Dias","family":"Canedo","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2783-4473","authenticated-orcid":false,"given":"Angelica Toffano Seidel","family":"Calazans","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8083-7278","authenticated-orcid":false,"given":"Ian Nery","family":"Bandeira","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8385-8314","authenticated-orcid":false,"given":"Pedro Henrique Teixeira","family":"Costa","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0409-058X","authenticated-orcid":false,"given":"Eloisa Toffano Seidel","family":"Masson","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,11,4]]},"reference":[{"key":"391_CR1","unstructured":"Regulation GDP (2018) Eu data protection rules. Eur Commission, Accessed in Oct 9, 2019. https:\/\/ec.europa.eu\/commission\/priorities\/justice-and-fundamental-rights\/data-protection\/2018-reform-eu-data-protection-rules_en"},{"key":"391_CR2","unstructured":"da Rep\u00fablica P (2018) Lei geral de prote\u00e7\u00e3o de dados pessoais (lgpd). Secretaria-Geral, Accessed in Oct 9, 2019. http:\/\/www.planalto.gov.br\/ccivil_03\/_ato2015-2018\/2018\/lei\/L13709.htm"},{"key":"391_CR3","doi-asserted-by":"crossref","unstructured":"Kalloniatis C, Kavakli E, Gritzalis S (2009) Methods for designing privacy aware information systems: a review. In: Panhellenic conference on informatics, pp 185\u2013194. IEEE computer society","DOI":"10.1109\/PCI.2009.45"},{"key":"391_CR4","doi-asserted-by":"publisher","unstructured":"Thomas K, Bandara AK, Price BA, Nuseibeh B (2014) Distilling privacy requirements for mobile applications. In: 36th international conference on software engineering, ICSE \u201914, Hyderabad, India - May 31 - Jun 07, 2014, pp 871\u2013882. https:\/\/doi.org\/10.1145\/2568225.2568240","DOI":"10.1145\/2568225.2568240"},{"issue":"1","key":"391_CR5","doi-asserted-by":"publisher","first-page":"259","DOI":"10.1007\/s10664-017-9517-1","volume":"23","author":"I Hadar","year":"2018","unstructured":"Hadar I, Hasson T, Ayalon O, Toch E, Birnhack M, Sherman S, Balissa A (2018) Privacy by designers: software developers\u2019 privacy mindset. Empir Softw Eng 23(1):259\u2013289. https:\/\/doi.org\/10.1007\/s10664-017-9517-1","journal-title":"Empir Softw Eng"},{"key":"391_CR6","doi-asserted-by":"crossref","unstructured":"Balebako R, Marsh A, Lin J, Hong J, Cranor L (2014) The privacy and security behaviors of smartphone. In: Workshop on usable security (USEC 2014), San Diego, 2014","DOI":"10.14722\/usec.2014.23006"},{"key":"391_CR7","unstructured":"Skinner G, Chang E (2005) Pp-sdlc the privacy protecting systems development life cycle. Proceedings of the IPSI-2005 France"},{"key":"391_CR8","unstructured":"Patil S, Kobsa A (2004) Preserving privacy in awareness systems. In: Wissen in Aktion, pp 119\u2013130"},{"key":"391_CR9","unstructured":"Christel MG, Kang KC (1992) Issues in requirements elicitation. Technical report CMU\/SEI-92-TR-012 \u2013 carnegie mellon university pittsburgh Pa software engineering institute. https:\/\/apps.dtic.mil\/sti\/pdfs\/ADA258932.pdf"},{"issue":"4","key":"391_CR10","doi-asserted-by":"publisher","first-page":"365","DOI":"10.1049\/iet-sen.2017.0144","volume":"12","author":"CL Pacheco","year":"2018","unstructured":"Pacheco CL, Garc\u00eda IA, Reyes M (2018) Requirements elicitation techniques: a systematic literature review based on the maturity of the techniques. IET Softw. 12(4):365\u2013378","journal-title":"IET Softw."},{"key":"391_CR11","doi-asserted-by":"crossref","unstructured":"Rzepka WE (1989) A requirements engineering testbed: concept, status and first results. In: Proceedings of the twenty-second annual hawaii international conference on system sciences. Volume II: software track, vol. 2, pp 339\u2013340. IEEE computer society","DOI":"10.1109\/HICSS.1989.48010"},{"issue":"3","key":"391_CR12","first-page":"212","volume":"2","author":"A De Lucia","year":"2010","unstructured":"De Lucia A, Qusef A (2010) Requirements engineering in agile software development. J Emerg Technol Web Intell 2(3):212\u2013220","journal-title":"J Emerg Technol Web Intell"},{"issue":"5","key":"391_CR13","doi-asserted-by":"publisher","first-page":"449","DOI":"10.1111\/j.1365-2575.2007.00259.x","volume":"20","author":"B Ramesh","year":"2010","unstructured":"Ramesh B, Cao L, Baskerville R (2010) Agile requirements engineering practices and challenges: an empirical study. Inf Syst J 20(5):449\u2013480","journal-title":"Inf Syst J"},{"issue":"3\u20134","key":"391_CR14","first-page":"137","volume":"9","author":"M Younas","year":"2017","unstructured":"Younas M, Jawawi D, Ghani I, Kazmi R (2017) Non-functional requirements elicitation guideline for agile methods. J Telecommun Electron Comput Eng (JTEC) 9(3\u20134):137\u2013142","journal-title":"J Telecommun Electron Comput Eng (JTEC)"},{"issue":"2","key":"391_CR15","doi-asserted-by":"publisher","first-page":"9:1","DOI":"10.1145\/3306607","volume":"28","author":"S Wagner","year":"2019","unstructured":"...Wagner S, Fern\u00e1ndez DM, Felderer M, Vetr\u00f2 A, Kalinowski M, Wieringa RJ, Pfahl D, Conte T, Christiansson M, Greer D, Lassenius C, M\u00e4nnist\u00f6 T, Nayebi M, Oivo M, Penzenstadler B, Prikladnicki R, Ruhe G, Schekelmann A, Sen S, Sp\u00ednola RO, Tuzcu A, de la Vara JL, Winkler D (2019) Status quo in requirements engineering: a theory and a global family of surveys. ACM Trans Softw Eng Method 28(2):9:1-9:48","journal-title":"ACM Trans Softw Eng Method"},{"key":"391_CR16","unstructured":"Li ZS, Werner C, Ernst NA, Damian DE (2020) GDPR compliance in the context of continuous integration. CoRR arXiv:2002.06830"},{"key":"391_CR17","doi-asserted-by":"publisher","unstructured":"Canedo ED, Calazans ATS, Cerqueira AJ, Costa PHT, Masson ETS (2021) Agile teams\u2019 perception in privacy requirements elicitation: Lgpd\u2019s compliance in brazil. In: 29th IEEE international requirements engineering conference, RE 2021, Notre Dame, IN, USA, September 20-24, 2021, pp 58\u201369. IEEE. https:\/\/doi.org\/10.1109\/RE51729.2021.00013","DOI":"10.1109\/RE51729.2021.00013"},{"key":"391_CR18","unstructured":"Experian S (2020) Pesquisa lgpd (lei geral de prote\u00e7\u00e3o a dados). Serasaexperian pp 01\u201316. https:\/\/www.serasaexperian.com.br\/images-cms\/wp-content\/uploads\/2020\/11\/03225812\/White-Paper-Serasa-Experian-LGPD-Como-as-Empresas-se-prepararam.pdf"},{"key":"391_CR19","unstructured":"c\u00e3o Nacional dos Profissionais de Privacidade de Dados AA (2021) Panorama de conscientiza\u00e7\u00e3o nacional sobre a lgpd 2021. Associa\u00e7\u00e3o Nacional dos Profissionais de Privacidade de Dados pp 01\u201315. https:\/\/www.convergenciadigital.com.br\/doc\/21\/cnppd2021_luizlima.pdf"},{"key":"391_CR20","unstructured":"Canedo ED, Calazans ATS, Cerqueira AJ, Costa PHT, Masson ETS (2020) Using the design thinking empathy phase as a facilitator in privacy requirements elicitation. In: AMCIS. association for information systems"},{"issue":"4","key":"391_CR21","doi-asserted-by":"publisher","first-page":"168","DOI":"10.3390\/info12040168","volume":"12","author":"S\u00c9R Ferr\u00e3o","year":"2021","unstructured":"Ferr\u00e3o S\u00c9R, Carvalho AP, Canedo ED, Mota APB, Costa PHT, Cerqueira AJ (2021) Diagnostic of data processing by brazilian organizations - a low compliance issue. Information 12(4):168","journal-title":"Information"},{"key":"391_CR22","doi-asserted-by":"publisher","unstructured":"Canedo ED, Cerqueira AJ, Gravina RM, Ribeiro VC, Cam\u00f5es R, dos Reis VE, de Mendon\u00e7a FLL, de Sousa Jr. RT (2021) Proposal of an implementation process for the brazilian general data protection law (LGPD). In: J. Filipe, M. Smialek, A. Brodsky, S. Hammoudi (eds.) Proceedings of the 23rd International Conference on Enterprise Information Systems, ICEIS 2021, Online Streaming, April 26-28, 2021, Scitepress, Vol 1, pp 19\u201330. https:\/\/doi.org\/10.5220\/0010398200190030","DOI":"10.5220\/0010398200190030"},{"key":"391_CR23","unstructured":"ISO B (2011) Iec 29100, 2011. bs iso\/iec29100: Information technology\u2014security techniques\u2014privacy framework. Tech rep, Technical report, British Standard and the International Organization"},{"key":"391_CR24","doi-asserted-by":"crossref","unstructured":"Ayala-Rivera V, Pasquale L (2018) The grace period has ended: an approach to operationalize GDPR requirements. In: RE, pp 136\u2013146. IEEE computer society","DOI":"10.1109\/RE.2018.00023"},{"key":"391_CR25","unstructured":"OneTrust D (2019) Comparing privacy laws: Gdpr versus lgpd. DataGuidance by OneTrust, Accessed in October 9, 2019. https:\/\/www.dataguidance.com\/comparing-privacy-laws-gdpr-v-lgpd\/"},{"issue":"4","key":"391_CR26","doi-asserted-by":"publisher","first-page":"429","DOI":"10.3390\/e22040429","volume":"22","author":"ED Canedo","year":"2020","unstructured":"Canedo ED, Calazans ATS, Masson ETS, Costa PHT, Lima F (2020) Perceptions of ICT practitioners regarding software privacy. Entropy 22(4):429","journal-title":"Entropy"},{"key":"391_CR27","doi-asserted-by":"publisher","unstructured":"Otto PN, Ant\u00f3n AI (2007) Addressing legal requirements in requirements engineering. In: 15th IEEE international requirements engineering conference, RE 2007, Oct 15-19th, 2007, New Delhi, India, pp 5\u201314. https:\/\/doi.org\/10.1109\/RE.2007.65","DOI":"10.1109\/RE.2007.65"},{"issue":"3","key":"391_CR28","doi-asserted-by":"publisher","first-page":"122","DOI":"10.1080\/01972243.2019.1583296","volume":"35","author":"K Bednar","year":"2019","unstructured":"Bednar K, Spiekermann S, Langheinrich M (2019) Engineering privacy by design: are engineers ready to live up to the challenge? Inf Soc 35(3):122\u2013142. https:\/\/doi.org\/10.1080\/01972243.2019.1583296","journal-title":"Inf Soc"},{"key":"391_CR29","doi-asserted-by":"publisher","unstructured":"Martins ADF, da Silva Barros PV, Monteiro JM, de Castro Machado J (2020) LGPD: a formal concept analysis and its evaluation. In: Anais do XXXV Simp\u00f3sio Brasileiro de Bancos de Dados, SBBD 2020, online, Sep 28 - -Oct 1, 2020, pp 259\u2013264. SBC. https:\/\/doi.org\/10.5753\/sbbd.2020.13651","DOI":"10.5753\/sbbd.2020.13651"},{"key":"391_CR30","unstructured":"Bax MP, Barbosa JLS (2020) Proposta de mecanismo de consentimento na lei geral de prote\u00e7\u00e3o a dados - LGPD (consent mechanism proposal in LGPD). In: da Silva Lemos DL, Sales TP, Campos MLM, Fiorini SR (eds), Proceedings of the XIII seminar on ontology research in Brazil and IV doctoral and masters consortium on ontologies (ONTOBRAS 2020), Vit\u00f3ria, Brazil, Nov 23-26, 2020, CEUR workshop proceedings, vol 2728, pp. 316\u2013321. CEUR-WS.org. http:\/\/ceur-ws.org\/Vol-2728\/doctorate4.pdf"},{"key":"391_CR31","doi-asserted-by":"publisher","unstructured":"Ara\u00fajo E, Vilela J, Silva C, Alves C (2021) Are my business process models compliant with lgpd? the LGPD4BP method to evaluate and to model LGPD aware business processes. In: Araujo RD, Dor\u00e7a FA, de Araujo RM, Siqueira SWM, Font\u00e3o AL (eds.), SBSI 2021: XVII Brazilian Symposium on Information Systems, Uberl\u00e2ndia, Brazil, June 7 - 10, 2021, pp. 46:1\u201346:9. ACM. https:\/\/doi.org\/10.1145\/3466933.3466982","DOI":"10.1145\/3466933.3466982"},{"key":"391_CR32","doi-asserted-by":"publisher","unstructured":"Ribeiro RC, Canedo ED (2020) Using MCDA for selecting criteria of LGPD compliant personal data security. In: Eom S, Lee J (eds) dg.o20: The 21st annual international conference on digital government research, Seoul, Republic of Korea, June 15\u201319. ACM, pp 175\u2013184 https:\/\/doi.org\/10.1145\/3396956.3398252","DOI":"10.1145\/3396956.3398252"},{"key":"391_CR33","doi-asserted-by":"publisher","unstructured":"Mendes J, Viana D, Rivero L (2021) Developing an inspection checklist for the adequacy assessment of software systems to quality attributes of the brazilian general data protection law: An initial proposal. In: Vasconcellos CD, Roggia KG, Collere V, Bousfield P (eds), SBES \u201921: 35th Brazilian symposium on software engineering, Joinville, Santa Catarina, Brazil, 27 Sept 2021 - 1 Oct 2021, pp 263\u2013268. ACM https:\/\/doi.org\/10.1145\/3474624.3477069","DOI":"10.1145\/3474624.3477069"},{"key":"391_CR34","doi-asserted-by":"publisher","unstructured":"Muncinelli G, de Lima E, Deschamps F, da Costa S, Cestari JMAP (2020) Components of the preliminary conceptual model for process capability in lgpd (brazilian data protection regulation) context. In: Pokojski J, et al. (ed), T.E. for complex socio-technical systems \u2013 real-life applications. computer science https:\/\/doi.org\/10.3233\/ATDE200125","DOI":"10.3233\/ATDE200125"},{"key":"391_CR35","doi-asserted-by":"publisher","unstructured":"Sakamoto LS, Alves D, Abe JM, de Souza JS, de Souza, NA, Martinez AAG (2021) Software optimization for LGPD compliance using paraconsistent evidential annotated logic e$$\\tau$$. In: Watr\u00f3bski J, Salabun W, Toro C, Zanni-Merk C, Howlett RJ, Jain LC (eds), Knowledge-based and intelligent information & engineering systems: proceedings of the 25th international conference KES-2021, virtual event \/ Szczecin, Poland, 8-10 September 2021, Procedia Computer Science, vol 192, pp 3049\u20133059. Elsevier. https:\/\/doi.org\/10.1016\/j.procs.2021.09.077","DOI":"10.1016\/j.procs.2021.09.077"},{"issue":"5","key":"391_CR36","doi-asserted-by":"publisher","first-page":"879","DOI":"10.1007\/s00779-021-01544-1","volume":"25","author":"A Alhazmi","year":"2021","unstructured":"Alhazmi A, Arachchilage NAG (2021) I\u2019m all ears! listening to software developers on putting GDPR principles into software development practice. Pers Ubiquitous Comput 25(5):879\u2013892. https:\/\/doi.org\/10.1007\/s00779-021-01544-1","journal-title":"Pers Ubiquitous Comput"},{"key":"391_CR37","doi-asserted-by":"crossref","unstructured":"Smith HJ, Dinev T, Xu H (2011) Information privacy research: an interdisciplinary review. MIS Q. 35(4): 989\u20131015. http:\/\/misq.org\/catalog\/product\/view\/id\/1518\/s\/information-privacy-research-an-interdisciplinary-review\/","DOI":"10.2307\/41409970"},{"issue":"3","key":"391_CR38","doi-asserted-by":"publisher","first-page":"241","DOI":"10.1007\/s00766-008-0067-3","volume":"13","author":"C Kalloniatis","year":"2008","unstructured":"Kalloniatis C, Kavakli E, Gritzalis S (2008) Addressing privacy requirements in system design: the pris method. Requir Eng 13(3):241\u2013255. https:\/\/doi.org\/10.1007\/s00766-008-0067-3","journal-title":"Requir Eng"},{"issue":"2","key":"391_CR39","doi-asserted-by":"publisher","first-page":"40","DOI":"10.1109\/MSP.2016.37","volume":"14","author":"S Gurses","year":"2016","unstructured":"Gurses S, del \u00c1lamo JM (2016) Privacy engineering: Shaping an emerging field of research and practice. IEEE Secur Privacy 14(2):40\u201346. https:\/\/doi.org\/10.1109\/MSP.2016.37","journal-title":"IEEE Secur Privacy"},{"key":"391_CR40","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4302-6356-2","volume-title":"The privace engineer\u2019s manifest","author":"MF Dennedy","year":"2014","unstructured":"Dennedy MF, Fox J, Finneran T (2014) The privace engineer\u2019s manifest. Apress open, New York"},{"key":"391_CR41","doi-asserted-by":"crossref","unstructured":"Peixoto M, Silva C, Lima R, Ara\u00fajo J, Gorschek T, Silva J (2019) Pcm tool: privacy requirements specification in agile software development. In: Anais Estendidos da X Confer\u00eancia Brasileira de Software: Teoria e Pr\u00e1tica, pp 108\u2013113. SBC","DOI":"10.5753\/cbsoft_estendido.2019.7666"},{"issue":"1","key":"391_CR42","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/s00766-010-0115-7","volume":"16","author":"M Deng","year":"2011","unstructured":"Deng M, Wuyts K, Scandariato R, Preneel B, Joosen W (2011) A privacy threat analysis framework: supporting the elicitation and fulfillment of privacy requirements. Requir Eng 16(1):3\u201332. https:\/\/doi.org\/10.1007\/s00766-010-0115-7","journal-title":"Requir Eng"},{"issue":"3","key":"391_CR43","doi-asserted-by":"publisher","first-page":"1","DOI":"10.4018\/jsse.2012070101","volume":"3","author":"S Islam","year":"2012","unstructured":"Islam S, Mouratidis H, Kalloniatis C, Hudic A, Zechner L (2012) Model based process to support security and privacy requirements engineering. IJSSE 3(3):1\u201322. https:\/\/doi.org\/10.4018\/jsse.2012070101","journal-title":"IJSSE"},{"key":"391_CR44","first-page":"356","volume-title":"Research challenges in information science - 15th international conference, RCIS 2021, limassol, Cyprus, May 11\u201314, 2021, proceedings lecture notes in business information processing","author":"K Tsilionis","year":"2021","unstructured":"Tsilionis K, Maene J, Heng S, Wautelet Y, Poelmans S (2021) Conceptual modeling versus user story mapping: Which is the best approach to agile requirements engineering? In: Cherfi SS, Perini A, Nurcan S (eds) Research challenges in information science - 15th international conference, RCIS 2021, limassol, Cyprus, May 11\u201314, 2021, proceedings lecture notes in business information processing, vol 415. Springer, New york, pp 356\u2013373"},{"key":"391_CR45","doi-asserted-by":"crossref","unstructured":"Lin J, Yu H, Shen Z, Miao C (2014) Using goal net to model user stories in agile software development. In: SNPD, pp 1\u20136. IEEE computer society","DOI":"10.1109\/SNPD.2014.6888731"},{"key":"391_CR46","doi-asserted-by":"crossref","unstructured":"Lucassen G, Dalpiaz F, van der Werf JMEM, Brinkkemper S (2016) The use and effectiveness of user stories in practice. In: REFSQ, lecture notes in computer science, vol 9619, pp 205\u2013222. Springer","DOI":"10.1007\/978-3-319-30282-9_14"},{"key":"391_CR47","doi-asserted-by":"crossref","unstructured":"Lombriser P, Dalpiaz F, Lucassen G, Brinkkemper S (2016) Gamified requirements engineering: model and experimentation. In: REFSQ, lecture notes in computer science, vol 9619, pp 171\u2013187. Springer","DOI":"10.1007\/978-3-319-30282-9_12"},{"key":"391_CR48","doi-asserted-by":"publisher","unstructured":"Bartolini C, Daoudagh S, Lenzini G, Marchetti E (2019) Gdpr-based user stories in the access control perspective. In: Quality of information and communications technology - 12th international conference, QUATIC 2019, ciudad real, spain, September 11-13, 2019, Proceedings, pp. 3\u201317. https:\/\/doi.org\/10.1007\/978-3-030-29238-6_1","DOI":"10.1007\/978-3-030-29238-6_1"},{"key":"391_CR49","doi-asserted-by":"crossref","unstructured":"Rygge H, J\u00f8sang A (2018) Threat poker: solving security and privacy threats in agile software development. In: NordSec, lecture notes in computer science, vol 11252, pp 468\u2013483. Springer","DOI":"10.1007\/978-3-030-03638-6_29"},{"issue":"6","key":"391_CR50","doi-asserted-by":"publisher","first-page":"618","DOI":"10.1007\/s10664-010-9134-8","volume":"15","author":"BA Kitchenham","year":"2010","unstructured":"Kitchenham BA, Brereton P, Turner M, Niazi M, Linkman SG, Pretorius R, Budgen D (2010) Refining the systematic literature review process - two participant-observer case studies. Empir Softw Eng 15(6):618\u2013653","journal-title":"Empir Softw Eng"},{"issue":"1","key":"391_CR51","first-page":"74","volume":"9","author":"V Wilson","year":"2014","unstructured":"Wilson V (2014) Research methods: triangulation. Evid Lib Inform Pract 9(1):74\u201375","journal-title":"Evid Lib Inform Pract"},{"key":"391_CR52","volume-title":"An introduction to qualitative research","author":"U Flick","year":"2018","unstructured":"Flick U (2018) An introduction to qualitative research. Sage Publications Limited, Beverley Hills, CA"},{"issue":"1","key":"391_CR53","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1177\/107780049500100103","volume":"1","author":"S Kvale","year":"1995","unstructured":"Kvale S (1995) The social construction of validity. Qualit Inquiry 1(1):19\u201340","journal-title":"Qualit Inquiry"},{"key":"391_CR54","unstructured":"Kitchenham B, Charters S (2007) Guidelines for performing systematic literature reviews in software engineering. Department of computer science University of Durham Durham, UK"},{"key":"391_CR55","unstructured":"Peixoto MM (2020) Privacy requirements engineering in agile software development: a specification method. In: REFSQ workshops, CEUR workshop proceedings, vol 2584. CEUR-WS.org"},{"key":"391_CR56","doi-asserted-by":"publisher","first-page":"32","DOI":"10.1016\/j.jss.2018.01.036","volume":"139","author":"K Curcio","year":"2018","unstructured":"Curcio K, Navarro T, Malucelli A, Reinehr SS (2018) Requirements engineering: a systematic mapping study in agile software development. J Syst Softw 139:32\u201350","journal-title":"J Syst Softw"},{"key":"391_CR57","doi-asserted-by":"crossref","unstructured":"Zamudio L, Aguilar JA, Barba CT, Misra S (2017) A requirements engineering techniques review in agile software development methods. In: ICCSA (5), lecture notes in computer science, vol 10408, pp 683\u2013698. Springer","DOI":"10.1007\/978-3-319-62404-4_50"},{"key":"391_CR58","unstructured":"Viitaniemi M (2017) Privacy by design in agile software development. Master\u2019s thesis, master\u2019s degree programme in information technology, Tampere University of Technology"},{"key":"391_CR59","doi-asserted-by":"crossref","unstructured":"Loser K, Degeling M (2014) Security and privacy as hygiene factors of developer behavior in small and agile teams. In: HCC, IFIP advances in information and communication technology, vol 431, pp 255\u2013265. Springer","DOI":"10.1007\/978-3-662-44208-1_21"},{"key":"391_CR60","doi-asserted-by":"publisher","unstructured":"Wagner TJ, Ford TC (2020) Metrics to meet security & privacy requirements with agile software development methods in a regulated environment. In: International conference on computing, networking and communications, ICNC 2020, Big Island, HI, USA, Feb 17-20, 2020, pp 17\u201323. https:\/\/doi.org\/10.1109\/ICNC47757.2020.9049681","DOI":"10.1109\/ICNC47757.2020.9049681"},{"key":"391_CR61","doi-asserted-by":"crossref","unstructured":"Calazans ATS, Cerqueira AJ, Canedo ED (2020) Empathy and criativity in privacy requirements elicitation: systematic literature review. In: WER. Editora PUC-Rio","DOI":"10.29327\/1298730.23-17"},{"key":"391_CR62","doi-asserted-by":"publisher","unstructured":"Oliver I (2016) Experiences in the development and usage of a privacy requirements framework. In: 24th IEEE international requirements engineering conference, RE 2016, Beijing, China, September 12-16, 2016, pp 293\u2013302. https:\/\/doi.org\/10.1109\/RE.2016.59","DOI":"10.1109\/RE.2016.59"},{"key":"391_CR63","doi-asserted-by":"publisher","unstructured":"Katsuno Y, Kundu A, Das KK, Takahashi H, Schloss R, Dey P, Mohania MK (2016) Security, compliance, and agile deployment of personal identifiable information solutions on a public cloud. In: 9th IEEE international conference on cloud computing, CLOUD 2016, San Francisco, CA, USA, June 27 - July 2, 2016, pp 359\u2013366. https:\/\/doi.org\/10.1109\/CLOUD.2016.0055","DOI":"10.1109\/CLOUD.2016.0055"},{"key":"391_CR64","doi-asserted-by":"publisher","unstructured":"Galvez R, Gurses S (2018) The odyssey: modeling privacy threats in a brave new world. In: 2018 IEEE European symposium on security and privacy workshops, EuroS &P workshops 2018, London, United Kingdom, April 23-27, 2018, pp 87\u201394. https:\/\/doi.org\/10.1109\/EuroSPW.2018.00018","DOI":"10.1109\/EuroSPW.2018.00018"},{"key":"391_CR65","doi-asserted-by":"publisher","unstructured":"Rindell K, Hyrynsalmi S, Lepp\u00e4nen V (2018) Aligning security objectives with agile software development. In: Proceedings of the 19th international conference on agile software development, XP 2019, companion, Porto, Portugal, May 21-25, 2018, pp. 3:1\u20133:9. https:\/\/doi.org\/10.1145\/3234152.3234187","DOI":"10.1145\/3234152.3234187"},{"key":"391_CR66","doi-asserted-by":"publisher","unstructured":"van der Heijden A, Broasca C, Serebrenik A (2018) An empirical perspective on security challenges in large-scale agile software development. In: Proceedings of the 12th ACM\/IEEE international symposium on empirical software engineering and measurement, ESEM 2018, Oulu, Finland, October 11-12, 2018, pp 45:1\u201345:4. https:\/\/doi.org\/10.1145\/3239235.3267426","DOI":"10.1145\/3239235.3267426"},{"key":"391_CR67","doi-asserted-by":"publisher","unstructured":"Maier P, Ma Z, Bloem R (2017) Towards a secure SCRUM process for agile web application development. In: Proceedings of the 12th international conference on availability, reliability and security, Reggio Calabria, Italy, Aug 29 - Sep 01, 2017, pp 73:1\u201373:8. https:\/\/doi.org\/10.1145\/3098954.3103171","DOI":"10.1145\/3098954.3103171"},{"key":"391_CR68","doi-asserted-by":"publisher","unstructured":"Netto D, Silva C, Ara\u00fajo J (2019) Identifying how the brazilian software industry specifies legal requirements. In: Proceedings of the XXXIII Brazilian symposium on software engineering, SBES 2019, Salvador, Brazil, Sep 23-27, 2019, pp 181\u2013186. https:\/\/doi.org\/10.1145\/3350768.3352730","DOI":"10.1145\/3350768.3352730"},{"key":"391_CR69","doi-asserted-by":"crossref","unstructured":"Newton N, Anslow C, Drechsler A (2019) Information security in agile software development projects: a critical success factor perspective. In: ECIS","DOI":"10.26686\/wgtn.13088357"},{"key":"391_CR70","doi-asserted-by":"crossref","unstructured":"T\u00f8ndel IA, Cruzes DS, Jaatun MG, Rindell K (2019) The security intention meeting series as a way to increase visibility of software security decisions in agile development projects. In: ARES, pp 59:1\u201359:8. ACM","DOI":"10.1145\/3339252.3340337"},{"key":"391_CR71","doi-asserted-by":"crossref","unstructured":"Ionita D, van der Velden C, Ikkink HK, Neven E, Daneva M, Kuipers M (2019) Towards risk-driven security requirements management in agile software development. In: CAiSE forum, lecture notes in business information processing, vol 350, pp 133\u2013144. Springer","DOI":"10.1007\/978-3-030-21297-1_12"},{"issue":"4","key":"391_CR72","doi-asserted-by":"publisher","first-page":"508","DOI":"10.1108\/ICS-12-2018-0138","volume":"27","author":"IA T\u00f8ndel","year":"2019","unstructured":"T\u00f8ndel IA, Jaatun MG, Cruzes DS, Williams L (2019) Collaborative security risk estimation in agile software development. Inf Comput Secur 27(4):508\u2013535","journal-title":"Inf Comput Secur"},{"key":"391_CR73","doi-asserted-by":"crossref","unstructured":"Bernsmed K, Jaatun MG (2019) Threat modelling and agile software development: Identified practice in four norwegian organisations. In: Cyber Security, pp 1\u20138. IEEE","DOI":"10.1109\/CyberSecPODS.2019.8885144"},{"key":"391_CR74","doi-asserted-by":"publisher","unstructured":"Pessoa CR, Nunes BC, de Oliveira C, Marques ME (2021) Effects and projections of the brazilian general data protection law (lgpd) application and the role of the dpo. In: Digital transformation and challenges to data security and privacy, pp 195\u2013208. IGI Global. https:\/\/doi.org\/10.4018\/978-1-7998-4201-9.ch011","DOI":"10.4018\/978-1-7998-4201-9.ch011"},{"key":"391_CR75","doi-asserted-by":"publisher","unstructured":"Palhares F (2021) Brazil\u2019s data protection law: Putting brazil on the map of data privacy frameworks. In: Digital transformation and challenges to data security and privacy, pp 98\u2013118. IGI Global, https:\/\/doi.org\/10.4018\/978-1-7998-4201-9.ch006","DOI":"10.4018\/978-1-7998-4201-9.ch006"},{"key":"391_CR76","doi-asserted-by":"publisher","unstructured":"Silva J, Calegari N, Gomes E (2019) After brazil\u2019s general data protection law: Authorization in decentralized web applications. In: Amer-Yahia S, Mahdian M, Goel A, Houben G, Lerman K, McAuley JJ, Baeza-Yates R, Zia L (eds), Companion of The 2019 World Wide Web Conference, WWW 2019, San Francisco, CA, USA, May 13-17, 2019, pp 819\u2013822. ACM. https:\/\/doi.org\/10.1145\/3308560.3316461","DOI":"10.1145\/3308560.3316461"},{"issue":"7","key":"391_CR77","first-page":"64","volume":"40","author":"IE Allen","year":"2007","unstructured":"Allen IE, Seaman CA (2007) Likert scales and data analyses. Qual Prog 40(7):64\u201365","journal-title":"Qual Prog"},{"issue":"4","key":"391_CR78","doi-asserted-by":"publisher","first-page":"364","DOI":"10.1097\/00006199-196807000-00014","volume":"17","author":"BG Glaser","year":"1968","unstructured":"Glaser BG, Strauss AL, Strutzel E (1968) The discovery of grounded theory; strategies for qualitative research. Nursing Res 17(4):364","journal-title":"Nursing Res"},{"issue":"6","key":"391_CR79","doi-asserted-by":"publisher","first-page":"654","DOI":"10.1016\/j.infsof.2007.02.011","volume":"49","author":"G Coleman","year":"2007","unstructured":"Coleman G, O\u2019Connor R (2007) Using grounded theory to understand software process improvement: a study of irish software product companies. Inf Softw Technol 49(6):654\u2013667","journal-title":"Inf Softw Technol"},{"key":"391_CR80","doi-asserted-by":"publisher","unstructured":"Luz WP, Pinto G, Bonif\u00e1cio R (2018) Building a collaborative culture: a grounded theory of well succeeded devops adoption in practice. In: ESEM, pp 6:1\u20136:10. ACM. https:\/\/doi.org\/10.1145\/3239235.3240299","DOI":"10.1145\/3239235.3240299"},{"issue":"4","key":"391_CR81","doi-asserted-by":"publisher","first-page":"487","DOI":"10.1007\/s10664-010-9152-6","volume":"16","author":"S Adolph","year":"2011","unstructured":"Adolph S, Hall W, Kruchten P (2011) Using grounded theory to study the experience of software development. Empir Softw Eng 16(4):487\u2013513","journal-title":"Empir Softw Eng"},{"key":"391_CR82","unstructured":"GLASER B (2002) Constructivist grounded theory? forum: qualitative social research. On line J 3(3)"},{"key":"391_CR83","doi-asserted-by":"crossref","unstructured":"Stol K, Ralph P, Fitzgerald B (2016) Grounded theory in software engineering research: a critical review and guidelines. In: ICSE, pp 120\u2013131. ACM","DOI":"10.1145\/2884781.2884833"},{"key":"391_CR84","unstructured":"Macedo PN (2018) Brazilian general data protection law (lgpd). Nartional congress, accessed in Oct 18, 2019 . https:\/\/www.pnm.adv.br\/wp-content\/uploads\/2018\/08\/Brazilian-General-Data-Protection-Law.pdf"},{"key":"391_CR85","unstructured":"Bourque P, Fairley RE (2014) Swebok v3.0, guide to the software engineering body of knowledge"},{"key":"391_CR86","unstructured":"He Q, Ant\u00f3n AI, et al (2003) A framework for modeling privacy requirements in role engineering. In: Procedures of REFSQ, vol 3, pp 137\u2013146. REFSQ. https:\/\/core.ac.uk\/display\/21027630"},{"key":"391_CR87","unstructured":"Kalloniatis C, Kavakli E, Kontellis E (2009) Pris tool: A case tool for privacy-oriented requirements engineering. In: MCIS, p 71. Athens University of economics and business \/ AISeL"},{"key":"391_CR88","doi-asserted-by":"crossref","unstructured":"Dashti S, Ranise S (2019) Tool-assisted risk analysis for data protection impact assessment. In: Privacy and identity management, IFIP advances in information and communication technology, vol 576, pp 308\u2013324. Springer","DOI":"10.1007\/978-3-030-42504-3_20"},{"key":"391_CR89","unstructured":"Pavlidis M, Islam S (2011) Sectro: A CASE tool for modelling security in requirements engineering using secure tropos. In: CAiSE forum, CEUR workshop proceedings, vol 734, pp 89\u201396. CEUR-WS.org"},{"key":"391_CR90","doi-asserted-by":"publisher","unstructured":"Mohammadi NG, Leicht J, Ulfat-Bunyadi N, Heisel M (2019) Privacy policy specification framework for addressing end-users\u2019 privacy requirements. In: Trust, privacy and security in digital business - 16th international conference, TrustBus 2019, Linz, Austria, August 26-29, 2019, proceedings, pp 46\u201362. Springer. https:\/\/doi.org\/10.1007\/978-3-030-27813-7_4, https:\/\/dblp.org\/rec\/conf\/trustbus\/MohammadiLUH19.bib","DOI":"10.1007\/978-3-030-27813-7_4"},{"key":"391_CR91","unstructured":"Jensen C, Tullio J, Potts C, Mynatt ED (2005) Strap: a structured analysis framework for privacy. Tech rep, Georgia Institute of Technology"},{"key":"391_CR92","doi-asserted-by":"publisher","first-page":"189","DOI":"10.1007\/978-3-319-72817-9_13","volume-title":"Computer security - ESORICS 2017 international workshops, CyberICPS 2017 and SECPRE 2017, Oslo, Norway, september 14\u201315, 2017, revised selected papers, lecture notes in computer science","author":"M Alshammari","year":"2017","unstructured":"Alshammari M, Simpson A (2017) A UML profile for privacy-aware data lifecycle models. In: Katsikas SK, Cuppens F, Cuppens N, Lambrinoudakis C, Kalloniatis C, Mylopoulos J, Ant\u00f3n AI, Gritzalis S (eds) Computer security - ESORICS 2017 international workshops, CyberICPS 2017 and SECPRE 2017, Oslo, Norway, september 14\u201315, 2017, revised selected papers, lecture notes in computer science, vol 10683. Springer, New york, pp 189\u2013209. https:\/\/doi.org\/10.1007\/978-3-319-72817-9_13"},{"key":"391_CR93","volume-title":"Qualitative research: a guide to design and implementation","author":"SB Merriam","year":"2015","unstructured":"Merriam SB, Tisdell EJ (2015) Qualitative research: a guide to design and implementation. Wiley, New york"},{"key":"391_CR94","doi-asserted-by":"publisher","first-page":"110851","DOI":"10.1016\/j.jss.2020.110851","volume":"172","author":"R Kasauli","year":"2021","unstructured":"Kasauli R, Knauss E, Horkoff J, Liebel G, de Oliveira Neto FG (2021) Requirements engineering challenges and practices in large-scale agile system development. J Syst Softw 172:110851","journal-title":"J Syst Softw"},{"issue":"12","key":"391_CR95","doi-asserted-by":"publisher","first-page":"371","DOI":"10.3390\/info10120371","volume":"10","author":"HF Martins","year":"2019","unstructured":"Martins HF, de Oliveira Junior AC, Canedo ED, Kosloski RAD, Pald\u00eas R\u00c1, Oliveira EC (2019) Design thinking: challenges for software requirements elicitation. Information 10(12):371","journal-title":"Information"},{"key":"391_CR96","doi-asserted-by":"publisher","first-page":"87","DOI":"10.1016\/j.jss.2016.06.013","volume":"119","author":"K Dikert","year":"2016","unstructured":"Dikert K, Paasivaara M, Lassenius C (2016) Challenges and success factors for large-scale agile transformations: a systematic literature review. J Syst Softw 119:87\u2013108. https:\/\/doi.org\/10.1016\/j.jss.2016.06.013","journal-title":"J Syst Softw"},{"key":"391_CR97","doi-asserted-by":"publisher","unstructured":"Raharjo T, Purwandari B (2020) Agile project management challenges and mapping solutions: a systematic literature review. In: ICSIM \u201920: The 3rd international conference on software engineering and information management, Sydney, NSW, Australia, Jan 12-15, 2020, pp 123\u2013129. ACM. https:\/\/doi.org\/10.1145\/3378936.3378949","DOI":"10.1145\/3378936.3378949"},{"key":"391_CR98","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-29044-2","volume-title":"Experimentation in software engineering","author":"C Wohlin","year":"2012","unstructured":"Wohlin C, Runeson P, H\u00f6st M, Ohlsson MC, Regnell B (2012) Experimentation in software engineering. Springer, Newyork"},{"key":"391_CR99","doi-asserted-by":"crossref","unstructured":"Kitchenham BA, Pfleeger SL (2008) Personal opinion surveys. In: Guide to advanced empirical software engineering, pp 63\u201392. Springer","DOI":"10.1007\/978-1-84800-044-5_3"}],"container-title":["Requirements Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00766-022-00391-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s00766-022-00391-7\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00766-022-00391-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,4,9]],"date-time":"2025-04-09T10:07:45Z","timestamp":1744193265000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s00766-022-00391-7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,11,4]]},"references-count":99,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2022,12]]}},"alternative-id":["391"],"URL":"https:\/\/doi.org\/10.1007\/s00766-022-00391-7","relation":{},"ISSN":["0947-3602","1432-010X"],"issn-type":[{"value":"0947-3602","type":"print"},{"value":"1432-010X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,11,4]]},"assertion":[{"value":"21 January 2022","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"7 October 2022","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"4 November 2022","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflicts of Interest"}}]}}