{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,28]],"date-time":"2025-12-28T02:25:04Z","timestamp":1766888704769,"version":"build-2065373602"},"reference-count":32,"publisher":"MDPI AG","issue":"2","license":[{"start":{"date-parts":[[2016,5,26]],"date-time":"2016-05-26T00:00:00Z","timestamp":1464220800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Deutsche Forschungsgemeinschaft (DFG)","award":["GRK 2167"],"award-info":[{"award-number":["GRK 2167"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Information"],"abstract":"<jats:p>Privacy is a software quality that is closely related to security. The main difference is that security properties aim at the protection of assets that are crucial for the considered system, and privacy aims at the protection of personal data that are processed by the system. The identification of privacy protection needs in complex systems is a hard and error prone task. Stakeholders whose personal data are processed might be overlooked, or the sensitivity and the need of protection of the personal data might be underestimated. The later personal data and the needs to protect them are identified during the development process, the more expensive it is to fix these issues, because the needed changes of the system-to-be often affect many functionalities. In this paper, we present a systematic method to identify the privacy needs of a software system based on a set of functional requirements by extending the problem-based privacy analysis (ProPAn) method. Our method is tool-supported and automated where possible to reduce the effort that has to be spent for the privacy analysis, which is especially important when considering complex systems. The contribution of this paper is a semi-automatic method to identify the relevant privacy requirements for a software-to-be based on its functional requirements. The considered privacy requirements address all dimensions of privacy that are relevant for software development. As our method is solely based on the functional requirements of the system to be, we enable users of our method to identify the privacy protection needs that have to be addressed by the software-to-be at an early stage of the development. As initial evaluation of our method, we show its applicability on a small electronic health system scenario.<\/jats:p>","DOI":"10.3390\/info7020028","type":"journal-article","created":{"date-parts":[[2016,5,26]],"date-time":"2016-05-26T12:13:20Z","timestamp":1464264800000},"page":"28","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":11,"title":["Computer-Aided Identification and Validation of Privacy Requirements"],"prefix":"10.3390","volume":"7","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5274-0324","authenticated-orcid":false,"given":"Rene","family":"Meis","sequence":"first","affiliation":[{"name":"paluno\u2014The Ruhr Institute for Software Technology, University of Duisburg-Essen, Duisburg 47057, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Maritta","family":"Heisel","sequence":"additional","affiliation":[{"name":"paluno\u2014The Ruhr Institute for Software Technology, University of Duisburg-Essen, Duisburg 47057, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2016,5,26]]},"reference":[{"key":"ref_1","unstructured":"European Commission Proposal for a Regulation of the European Parliament and of the Council on the Protection of Individuals with Regard to the Processing of Personal Data and on the Free Movement of Such Data (General Data Protection Regulation). Available online: http:\/\/ec.europa.eu\/justice\/data-protection\/document\/review2012\/com_2012_11_en.pdf."},{"key":"ref_2","unstructured":"Verizon 2016 Data Breach Investigations Report. Available online: http:\/\/www.verizonenterprise.com\/verizon-insights-lab\/dbir\/2016\/."},{"key":"ref_3","unstructured":"Ponemon Institute 2015 Cost of Data Breach Study: Global Analysis. Available online: http:\/\/www-03.ibm.com\/security\/data-breach\/."},{"key":"ref_4","unstructured":"GSMA MOBILE PRIVACY: Consumer Research Insights and Considerations for Policymakers. Available online: http:\/\/www.gsma.com\/publicpolicy\/wp-content\/uploads\/2014\/02\/MOBILE_PRIVACY_Consumer_research_insights_and_considerations_for_policymakers-Final.pdf."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Hansen, M., Jensen, M., and Rost, M. (2015, January 21\u201322). Protection Goals for Privacy Engineering. Proceedings of the 2015 IEEE Symposium on Security and Privacy Workshops, SPW 2015, San Jose, CA, USA.","DOI":"10.1109\/SPW.2015.13"},{"key":"ref_6","unstructured":"Meis, R., Heisel, M., and Wirtz, R. (2015). Trust, Privacy, and Security in Digital Business, Springer."},{"key":"ref_7","unstructured":"Cavoukian, A. The 7 Foundational Principles. Available online: https:\/\/www.ipc.on.ca\/images\/resources\/7foundationalprinciples.pdf."},{"key":"ref_8","unstructured":"Jackson, M. (2001). Problem Frames: Analyzing and Structuring Software Development Problems, Addison-Wesley."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Beckers, K., Fa\u00dfbender, S., Heisel, M., and Meis, R. (2014). A Problem-based Approach for Computer Aided Privacy Threat Identification, Springer.","DOI":"10.1007\/978-3-642-54069-1_1"},{"key":"ref_10","unstructured":"ProPAn: A UML4PF Extension. Available online: http:\/\/www.uml4pf.org\/ext-propan\/index.html."},{"key":"ref_11","unstructured":"Network of Excellence (NoE) on Engineering Secure Future Internet Software Services and Systems. Available online: http:\/\/www.nessos-project.eu."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"C\u00f4t\u00e9, I., Hatebur, D., Heisel, M., and Schmidt, H. (September, January 29). UML4PF\u2014A Tool for Problem-Oriented Requirements Analysis. Proceedings of the 2011 IEEE 19th International Requirements Engineering Conference, Trento, Italy.","DOI":"10.1109\/RE.2011.6051670"},{"key":"ref_13","unstructured":"Meis, R. (2014). Privacy and Identity Management for Emerging Services and Technologies, Springer."},{"key":"ref_14","unstructured":"Beckers, K., Fa\u00dfbender, S., Gritzalis, S., Heisel, M., Kalloniatis, C., and Meis, R. (2014). Trust, Privacy, and Security in Digital Business, Springer."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Lorenz, P., Cardoso, J., Maciaszek, L.A., and van Sinderen, M. (2015, January 20\u201322). Supporting Privacy Impact Assessments Using Problem-Based Privacy Analysis. Software Technologies, Proceedings of the 10th International Joint Conference, ICSOFT 2015, Colmar, France. Communications in Computer and Information Science.","DOI":"10.1007\/978-3-319-30142-6"},{"key":"ref_16","unstructured":"Pfitzmann, A., and Hansen, M. A Terminology for Talking About Privacy by Data Minimization: Anonymity, Unlinkability, Undetectability, Unobservability, Pseudonymity, and Identity Management. Available online: http:\/\/www.maroki.de\/pub\/dphistory\/2010_Anon_Terminology_v0.34.pdf."},{"key":"ref_17","unstructured":"Sabit, S. (2015). Consideration of Intervenability Requirements in Software Development. [Master\u2019s Thesis, University of Duisburg-Essen]."},{"key":"ref_18","unstructured":"UML4PF Tool. Available online: http:\/\/www.uml4pf.org."},{"key":"ref_19","unstructured":"Papyrus. Available online: https:\/\/eclipse.org\/papyrus\/."},{"key":"ref_20","unstructured":"Eclipse IDE. Available online: http:\/\/www.eclipse.org."},{"key":"ref_21","unstructured":"Epsilon Platform. Available online: http:\/\/www.eclipse.org\/epsilon."},{"key":"ref_22","unstructured":"EMF-Based Models Available online: http:\/\/www.eclipse.org\/modeling\/emf\/."},{"key":"ref_23","unstructured":"GMF-Based Models Available online: http:\/\/www.eclipse.org\/modeling\/gmp\/."},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1007\/s00766-010-0115-7","article-title":"A privacy threat analysis framework: Supporting the elicitation and fulfillment of privacy requirements","volume":"16","author":"Deng","year":"2011","journal-title":"Requir. Eng."},{"key":"ref_25","unstructured":"Howard, M., and Lipner, S. (2006). The Security Development Lifecycle, Microsoft Press."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"241","DOI":"10.1007\/s00766-008-0067-3","article-title":"Addressing privacy requirements in system design: The PriS method","volume":"13","author":"Kalloniatis","year":"2008","journal-title":"Requir. Eng."},{"key":"ref_27","unstructured":"Liu, L., Yu, E., and Mylopoulos, J. (2003, January 8\u201312). Security and Privacy Requirements Analysis within a Social Setting. Proceedings of the 11th IEEE International Conference on Requirements Engineering, Monterey Bay, CA, USA."},{"key":"ref_28","unstructured":"Yu, E. (1997, January 6\u201310). Towards Modeling and Reasoning Support for Early-Phase Requirements Engineering. Proceedings of the 3rd IEEE International Symposium on Requirements Engineering, Annapolis, MD, USA."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Omoronyia, I., Cavallaro, L., Salehie, M., Pasquale, L., and Nuseibeh, B. (2013, January 18\u201326). Engineering Adaptive Privacy: On the Role of Privacy Awareness Requirements. Proceedings of the 2013 International Conference on Software Engineering, ICSE \u201913, San Francisco, CA, USA.","DOI":"10.1109\/ICSE.2013.6606609"},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"126","DOI":"10.1057\/ejis.2013.18","article-title":"A systematic methodology for privacy impact assessments: A design science approach","volume":"23","author":"Oetzel","year":"2014","journal-title":"Eur. J. Inf. Syst."},{"key":"ref_31","first-page":"169","article-title":"A requirements taxonomy for reducing Web site privacy vulnerabilities","volume":"9","author":"Earp","year":"2004","journal-title":"Requir. Eng."},{"key":"ref_32","unstructured":"Hoepman, J. (2014, January 2\u20134). Privacy Design Strategies (Extended Abstract). Proceedings of the 29th IFIP TC 11 International Conference on ICT Systems Security and Privacy Protection, Marrakech, Morocco."}],"container-title":["Information"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2078-2489\/7\/2\/28\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T19:24:31Z","timestamp":1760210671000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2078-2489\/7\/2\/28"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016,5,26]]},"references-count":32,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2016,6]]}},"alternative-id":["info7020028"],"URL":"https:\/\/doi.org\/10.3390\/info7020028","relation":{},"ISSN":["2078-2489"],"issn-type":[{"type":"electronic","value":"2078-2489"}],"subject":[],"published":{"date-parts":[[2016,5,26]]}}}