Translating Privacy Design Principles Into Human-Centered Software Lifecycle: A Literature Review
Published in International Journal of Human–Computer Interaction, 2023
Marco Saltarella, Giuseppe Desolda, Rosa Lanzilotti, Vita Santa Barletta
The explanation is a critical process for this strategy. Users must take an informed decision about their data. Indeed, users should always be explained the whole personal data process in a detailed but understandable and concise way (Colesky & Ghanavati, 2016), including any data collection and sharing that is taking place (Hatamian, 2020) and, eventually, how data from different sources is combined, and for what and for how long data will be stored (Mannhardt et al., 2018). Moreover, a list of third parties to which data may be forwarded should be provided (Butin & Le Métayer, 2015), and any other policy update must be notified to the user (Mohan et al., 2019). Furthermore, as explicitly mandated by the different privacy regulations, data breaches must be notified “without undue delay” (Ataei et al., 2018) and specifically within 72 h from the identification of the breach, according to the GDPR.