{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,16]],"date-time":"2025-10-16T06:31:20Z","timestamp":1760596280148,"version":"build-2065373602"},"reference-count":55,"publisher":"MDPI AG","issue":"1","license":[{"start":{"date-parts":[[2017,3,9]],"date-time":"2017-03-09T00:00:00Z","timestamp":1489017600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Deutsche Forschungsgemeinschaft (DFG)","award":["GRK 2167"],"award-info":[{"award-number":["GRK 2167"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Information"],"abstract":"<jats:p>Privacy as a software quality is becoming more important these days and should not be underestimated during the development of software that processes personal data. The privacy goal of intervenability, in contrast to unlinkability (including anonymity and pseudonymity), has so far received little attention in research. Intervenability aims for the empowerment of end-users by keeping their personal data and how it is processed by the software system under their control. Several surveys have pointed out that the lack of intervenability options is a central privacy concern of end-users. In this paper, we systematically assess the privacy goal of intervenability and set up a software requirements taxonomy that relates the identi\ufb01ed intervenability requirements with a taxonomy of transparency requirements. Furthermore, we provide a tool-supported method to identify intervenability requirements from the functional requirements of a software system. This tool-supported method provides the means to elicit and validate intervenability requirements in a computer-aided way. Our combined taxonomy of intervenability and transparency requirements gives a detailed view on the privacy goal of intervenability and its relation to transparency. We validated the completeness of our taxonomy by comparing it to the relevant literature that we derived based on a systematic literature review. The proposed method for the identi\ufb01cation of intervenability requirements shall support requirements engineers to elicit and document intervenability requirements in compliance with the EU General Data Protection Regulation.<\/jats:p>","DOI":"10.3390\/info8010030","type":"journal-article","created":{"date-parts":[[2017,3,9]],"date-time":"2017-03-09T11:12:17Z","timestamp":1489057937000},"page":"30","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":11,"title":["Computer-Aided Identi\ufb01cation and Validation of Intervenability Requirements"],"prefix":"10.3390","volume":"8","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5274-0324","authenticated-orcid":false,"given":"Rene","family":"Meis","sequence":"first","affiliation":[{"name":"The Ruhr Institute for Software Technology, University of Duisburg-Essen, Duisburg 47057, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Maritta","family":"Heisel","sequence":"additional","affiliation":[{"name":"The Ruhr Institute for Software Technology, University of Duisburg-Essen, Duisburg 47057, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2017,3,9]]},"reference":[{"unstructured":"GSMA MOBILE PRIVACY: Consumer Research Insights and Considerations For Policymakers. Available online: http:\/\/www.gsma.com\/publicpolicy\/wp-content\/uploads\/2014\/02\/MOBILE_PRIVACY_Consumer_research_insights_and_considerations_for_policymakers-Final.pdf.","key":"ref_1"},{"unstructured":"Symantec State of Privacy Report 2015. Available online: https:\/\/www.symantec.com\/content\/en\/us\/about\/presskits\/b-state-of-privacy-report-2015.pdf.","key":"ref_2"},{"unstructured":"Quah, A.M.Y., and R\u00f6hm, U. (February, January 29). User Awareness and Policy Compliance of Data Privacy in Cloud Computing. Proceedings of the First Australasian Web Conference\u2013Volume 144, Adelaide, Australia.","key":"ref_3"},{"doi-asserted-by":"crossref","unstructured":"Ackerman, M.S., Cranor, L.F., and Reagle, J. (1999, January 3\u20135). Privacy in e-Commerce: Examining User Scenarios and Privacy Preferences. Proceedings of the 1st ACM Conference on Electronic Commerce (EC \u201999), Denver, CO, USA.","key":"ref_4","DOI":"10.1145\/336992.336995"},{"doi-asserted-by":"crossref","unstructured":"Camenisch, J., Crispo, B., Fischer-H\u00fcbner, S., Leenes, R., and Russello, G. (2012). Privacy and Identity Management for Life, Springer.","key":"ref_5","DOI":"10.1007\/978-3-642-31668-5"},{"unstructured":"Meis, R., and Heisel, M. (2016). Trust, Privacy, and Security in Digital Business, Springer.","key":"ref_6"},{"unstructured":"Meis, R., Heisel, M., and Wirtz, R. (2015). Trust, Privacy, and Security in Digital Business, Springer.","key":"ref_7"},{"doi-asserted-by":"crossref","unstructured":"Meis, R., and Heisel, M. (2016). Computer-Aided Identification and Validation of Privacy Requirements. Information, 7.","key":"ref_8","DOI":"10.3390\/info7020028"},{"unstructured":"International Organization for Standardization and International Electrotechnical Commission (ISO\/IEC) ISO\/IEC 29100:2011 Information Technology\u2013Security Techniques\u2013Privacy Framework. Available online: https:\/\/www.iso.org\/standard\/45123.html.","key":"ref_9"},{"unstructured":"European Commission Regulation (EU) 2016\/679 of the European Parliament and of the Council of 27 April 2016 on the Protection of Natural Persons with Regard to the Processing of Personal Data and on the Free Movement of such Data, and Repealing Directive 95\/46\/EC (General Data Protection Regulation). Available online: http:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX:32016R0679.","key":"ref_10"},{"unstructured":"Organisation for Economic Co-operation and Development (OECD) OECD Guidelines on the Protection of Privacy and Transborder Flows of Personal Data. Available online: https:\/\/www.oecd.org\/sti\/ieconomy\/oecdguidelinesontheprotectionofprivacyandtransborderflowsofpersonaldata.htm.","key":"ref_11"},{"unstructured":"US Federal Trade Commission Privacy Online: Fair Information Practices in the Electronic Marketplace: A Federal Trade Commission Report to Congress, Available online: https:\/\/www.ftc.gov\/reports\/privacy-online-fair-information-practices-electronic-marketplace-federal-trade-commission.","key":"ref_12"},{"doi-asserted-by":"crossref","unstructured":"Jalali, S., and Wohlin, C. (2012, January 19\u201320). Systematic Literature Studies: Database Searches vs. Backward Snowballing. Proceedings of the ACM-IEEE International Symposium on Empirical Software Engineering and Measurement, Lund, Sweden.","key":"ref_13","DOI":"10.1145\/2372251.2372257"},{"unstructured":"CORE2014. Available online: http:\/\/www.core.edu.au\/conference-portal.","key":"ref_14"},{"doi-asserted-by":"crossref","unstructured":"Bier, C. (2013, January 23\u201324). How Usage Control and Provenance Tracking Get Together\u2014A Data Protection Perspective. Presented at 2013 IEEE Security and Privacy Workshops (SPW), San Diego, CA, USA.","key":"ref_15","DOI":"10.1109\/SPW.2013.24"},{"unstructured":"Hoepman, J.H. (2014). ICT Systems Security and Privacy Protection, Springer.","key":"ref_16"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"2276","DOI":"10.1016\/j.jss.2013.03.011","article-title":"A framework to support selection of cloud providers based on security and privacy requirements","volume":"86","author":"Mouratidis","year":"2013","journal-title":"J. Syst. Softw."},{"doi-asserted-by":"crossref","unstructured":"Miyazaki, S., Mead, N., and Zhan, J. (2008, January 9\u201312). Computer-Aided Privacy Requirements Elicitation Technique. Presented at IEEE 2008 Asia-Pacific Services Computing Conference (APSCC \u201908), Yilan, Taiwan.","key":"ref_18","DOI":"10.1109\/APSCC.2008.263"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"759","DOI":"10.1016\/j.csi.2013.12.010","article-title":"Towards the design of secure and privacy-oriented information systems in the cloud: Identifying the major concepts","volume":"36","author":"Kalloniatis","year":"2014","journal-title":"Comput. Stand. Interfaces"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"113","DOI":"10.1007\/978-3-319-22906-5_9","article-title":"Designing Privacy-Aware Systems in the Cloud","volume":"Volume 9264","author":"Kalloniatis","year":"2015","journal-title":"Trust, Privacy and Security in Digital Business"},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"67","DOI":"10.1109\/TSE.2008.88","article-title":"Engineering Privacy","volume":"35","author":"Spiekermann","year":"2009","journal-title":"IEEE Trans. Softw. Eng."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"219","DOI":"10.1007\/978-3-319-22906-5_17","article-title":"Privacy Principles: Towards a Common Privacy Audit Methodology","volume":"Volume 9264","author":"Makri","year":"2015","journal-title":"Trust, Privacy and Security in Digital Business"},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"72","DOI":"10.1109\/MSP.2013.86","article-title":"Gone in 15 Seconds: The Limits of Privacy Transparency and Control","volume":"11","author":"Acquisti","year":"2013","journal-title":"IEEE Secur. Priv."},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"68","DOI":"10.1109\/MSP.2009.88","article-title":"Deconstructing the Privacy Experience","volume":"7","author":"Masiello","year":"2009","journal-title":"IEEE Secur. Priv."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"88","DOI":"10.1109\/MSP.2015.51","article-title":"Effortless Privacy Negotiations","volume":"13","author":"Krol","year":"2015","journal-title":"IEEE Secur. Priv."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1007\/s00766-010-0115-7","article-title":"A privacy threat analysis framework: Supporting the elicitation and fulfillment of privacy requirements","volume":"1","author":"Deng","year":"2011","journal-title":"Requir. Eng."},{"unstructured":"Komanduri, S., Shay, R.G., Norcie, B.U., and Cranor, L.F. AdChoices? Compliance with Online Behavioral Advertising Notice and Choice Requirements. Available online: http:\/\/moritzlaw.osu.edu\/students\/groups\/is\/files\/2012\/02\/Komanduir.Final_.pdf.","key":"ref_27"},{"key":"ref_28","first-page":"273","article-title":"Necessary But Not Sufficient: Standardized Mechanisms for Privacy Notice and Choice","volume":"10","author":"Cranor","year":"2012","journal-title":"J. Telecomm. High Tech. L."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"330","DOI":"10.1109\/JPROC.2010.2073670","article-title":"Privacy-Aware Design Principles for Information Networks","volume":"99","author":"Wicker","year":"2011","journal-title":"Proc. IEEE"},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"221","DOI":"10.1002\/asi.20122","article-title":"Technology, Security, and Individual Privacy: New Tools, New Threats, and New Public Perceptions","volume":"56","author":"Strickland","year":"2005","journal-title":"J. Assoc. Inf. Sci. Technol."},{"doi-asserted-by":"crossref","unstructured":"Sheth, S., Kaiser, G., and Maalej, W. (June, January 31). Us and Them: A Study of Privacy Requirements Across North America, Asia, and Europe. Proceedings of the 36th International Conference on Software Engineering (ICSE 2014), Hyderabad, India.","key":"ref_31","DOI":"10.1145\/2568225.2568244"},{"doi-asserted-by":"crossref","unstructured":"Fhom, H., and Bayarou, K. (2011, January 16\u201318). Towards a Holistic Privacy Engineering Approach for Smart Grid Systems. Presented at 2011 IEEE 10th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), Changsha, China.","key":"ref_32","DOI":"10.1109\/TrustCom.2011.32"},{"unstructured":"Ant\u00f3n, A.I., Earp, J.B., and Reese, A. (2002, January 9\u201313). Analyzing Website Privacy Requirements Using a Privacy Goal Taxonomy. Proceedings of the IEEE Joint International Conference on Requirements Engineering, Essen, Germany.","key":"ref_33"},{"key":"ref_34","first-page":"169","article-title":"A requirements taxonomy for reducing Web site privacy vulnerabilities","volume":"9","author":"Earp","year":"2004","journal-title":"Requir. Eng."},{"doi-asserted-by":"crossref","unstructured":"Van Der Sype, Y.S., and Seigneur, J.M. (2014, January 24\u201328). Case study: Legal requirements for the use of social login features for online reputation updates. Proceedings of the 29th Annual ACM Symposium on Applied Computing (SAC \u201914), Gyeongju, Korea.","key":"ref_35","DOI":"10.1145\/2554850.2554857"},{"doi-asserted-by":"crossref","unstructured":"Basso, T., Moraes, R., Jino, M., and Vieira, M. (2015, January 13\u201317). Requirements, design and evaluation of a privacy reference architecture for web applications and services. Proceedings of the 30th Annual ACM Symposium on Applied Computing (SAC \u201915), Salamanca, Spain.","key":"ref_36","DOI":"10.1145\/2695664.2695774"},{"doi-asserted-by":"crossref","unstructured":"Lobato, L., Fernandez, E., and Zorzo, S. (2009, January 16\u201319). Patterns to Support the Development of Privacy Policies. Presented at International Conference on Availability, Reliability and Security, 2009 (ARES \u201909), Fukuoka, Japan.","key":"ref_37","DOI":"10.1109\/ARES.2009.114"},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"4","DOI":"10.1016\/j.clsr.2015.12.001","article-title":"The Internet of Things (IoT) and its impact on individual privacy: An Australian perspective","volume":"32","author":"Caron","year":"2016","journal-title":"Comput. Law Secur. Rev."},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"103","DOI":"10.1109\/MSP.2015.34","article-title":"Informed Consent: We Can Do Better to Defend Privacy","volume":"13","author":"Borgesius","year":"2015","journal-title":"IEEE Secur. Priv."},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"24","DOI":"10.1109\/MS.2014.118","article-title":"Privacy Requirements in an Age of Increased Sharing","volume":"31","author":"Breaux","year":"2014","journal-title":"IEEE Softw."},{"unstructured":"Langheinrich, M. (2001). Ubicomp 2001: Ubiquitous Computing, Springer. LNCS 2201.","key":"ref_41"},{"unstructured":"Feigenbaum, J., Freedman, M., Sander, T., and Shostack, A. (2002). Security and Privacy in Digital Rights Management, Springer. LNCS 2320.","key":"ref_42"},{"key":"ref_43","doi-asserted-by":"crossref","first-page":"277","DOI":"10.1080\/13600869.2014.913874","article-title":"Privacy principles, risks and harms","volume":"28","author":"Wright","year":"2014","journal-title":"Int. Rev. Law Comput. Technol."},{"key":"ref_44","doi-asserted-by":"crossref","first-page":"337","DOI":"10.1016\/j.infsof.2008.04.004","article-title":"Towards the Development of Privacy-aware Systems","volume":"51","author":"Guarda","year":"2009","journal-title":"Inf. Softw. Technol."},{"unstructured":"Hedbom, H. (2009). The Future of Identity in the Information Society, Springer. IFIP AICT 298.","key":"ref_45"},{"key":"ref_46","doi-asserted-by":"crossref","first-page":"989","DOI":"10.2307\/41409970","article-title":"Information Privacy Research: An Interdisciplinary Review","volume":"35","author":"Smith","year":"2011","journal-title":"MIS Q."},{"unstructured":"ProPAn Tool. Available online: http:\/\/www.uml4pf.org\/ext-propan\/.","key":"ref_47"},{"unstructured":"Jackson, M. (2001). Problem Frames: Analyzing and Structuring Software Development Problems, Addison-Wesley.","key":"ref_48"},{"unstructured":"Meis, R. (2014). Privacy and Identity Management for Emerging Services and Technologies, Springer. IFIP AICT 421.","key":"ref_49"},{"unstructured":"Beckers, K., Fa\u00dfbender, S., Gritzalis, S., Heisel, M., Kalloniatis, C., and Meis, R. (2014). Trust, Privacy, and Security in Digital Business, Springer. LNCS 8647.","key":"ref_50"},{"unstructured":"Beckers, K., Fa\u00dfbender, S., Heisel, M., and Meis, R. (2014). Privacy Technologies and Policy, Springer. LNCS 8319.","key":"ref_51"},{"key":"ref_52","doi-asserted-by":"crossref","first-page":"79","DOI":"10.1007\/978-3-319-30142-6_5","article-title":"Supporting Privacy Impact Assessments using Problem-based Privacy Analysis","volume":"586","author":"Meis","year":"2016","journal-title":"Softw. Technol."},{"unstructured":"Network of Excellence on Engineering Secure Future Internet Software Services and Systems (NESSoS). Available online: http:\/\/www.nessos-project.eu\/.","key":"ref_53"},{"unstructured":"European Data Protection Authorities. Available online: http:\/\/ec.europa.eu\/justice\/data-protection\/article-29\/structure\/data-protection-authorities\/index_en.htm.","key":"ref_54"},{"unstructured":"Sabit, S. (2015). Consideration of Intervenability Requirements in Software Development. [Master Thesis, University of Duisburg-Essen].","key":"ref_55"}],"container-title":["Information"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2078-2489\/8\/1\/30\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T18:30:07Z","timestamp":1760207407000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2078-2489\/8\/1\/30"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,3,9]]},"references-count":55,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2017,3]]}},"alternative-id":["info8010030"],"URL":"https:\/\/doi.org\/10.3390\/info8010030","relation":{},"ISSN":["2078-2489"],"issn-type":[{"type":"electronic","value":"2078-2489"}],"subject":[],"published":{"date-parts":[[2017,3,9]]}}}