Privacy by Design Maturity in Software Development: An Empirical Study in Brazilian Federal Higher Education Institutions
DOI:
https://doi.org/10.5753/jserd.2026.7125Keywords:
Privacy By Design, Privacy Engineering, Software Development Lifecycle, LGPD, Public SectorAbstract
Context: Privacy by Design (PbD) has emerged as a key approach for embedding data protection into software systems from their inception, a pressing concern in Brazil after the enactment of the General Data Protection Law (LGPD). However, public organizations such as Brazilian Federal Higher Education Institutions (IFES) still struggle to translate legal requirements into concrete engineering practices and governance routines. Goal: This study investigates how IT professionals in IFES perceive, adopt, and operationalize PbD in software development, and which organizational, technical, and individual factors influence the maturity of privacy practices in this context. Method: We conducted a mixed-method survey with 58 IT professionals from IFES across 15 Brazilian states. The instrument combined 46 closed-ended and 9 open-ended questions covering privacy knowledge, attitudes, behaviors, strategies, and organizational conditions. Results: Respondents strongly recognize privacy as a fundamental right and frequently handle personal and sensitive data in their daily work. Core strategies such as encryption, data minimization, anonymization, risk management, and user control are perceived as very important and are more often applied, whereas decentralization, data sovereignty, and temporality remain uncommon and are more difficult to implement. Inferential analysis using Spearman’s rank correlation indicates that the adoption of privacy strategies is significantly associated with perceived importance (ρ = 0.37, p = 0.005), while organizational, social, and usability-related factors show no statistically significant associations. Conclusion: PbD maturity in IFES remains incipient, characterized by fragmented and reactive practices driven more by individual perceptions than by institutional structures. Advancing this maturity requires structured training, clearer roles and responsibilities, better tool support, and strategies that reinforce the perceived importance of privacy among practitioners.
Downloads
References
Al-Slais, Y. (2020). Privacy engineering methodologies: A survey. In 2020 International Conference on Innovation and Intelligence for Informatics, Computing and Technologies (3ICT), pages 1–6.
Alexey Andreev (2025). Rockyou2024 e as outras quatro maiores violações de dados da história. [link].
Alves, C. and Neves, M. (2021). Especificação de requisitos de privacidade em conformidade com a LGPD: resultados de um estudo de caso. In de Menezes Cruz, M. L. P., Hadad, G. D. S., and Marques, J. C., editors, Anais do WER21 - Workshop em Engenharia de Requisitos, Brasilia, BSB, Brasil, August 23-27, 2021. Editora PUC-Rio.
Andrade, V. C., Reinehr, S. S., Freitas, C. O. A., and Malucelli, A. (2023). Personal data privacy in software development processes: A practitioner’s point of view. In Hu, J., Min, G., Wang, G., and Georgalas, N., editors, 22nd IEEE International Conference on Trust, Security and Privacy in Computing and Communications, TrustCom 2024, Exeter, UK, November 1-3, 2023, pages 2727–2734. IEEE.
Andrade, V. C., Ribeiro, R. D., dos Passos Canteri, R., Reinehr, S. S., de A. Freitas, C. O., and Malucelli, A. (2024). Privacy in practice: Exploring concrete relationships between privacy patterns and privacy by design principles in software engineering. In OliveiraJr, E., de Guzmán, I. G. R., Ayala, C. P., Murta, L., Barcelos, M. P., Brito, I. S. S., Neto, A., Valderas, P., Paludo, M., Reinehr, S. S., Malucelli, A., and Cruz-Lemus, J. A., editors, 27th Iberoamerican Conference on Software Engineering, CIbSE 2024, Curitiba, Brazil, May 6-10, 2024, pages 271–285. Curran Associates.
Bryant, A. and Charmaz, K. (2007). The Sage handbook of grounded theory. Sage, [link].
Bu, F., Wang, N., Jiang, B., and Jiang, Q. (2021). Motivating information system engineers’ acceptance of privacy by design in china: An extended UTAUT model. Int. J. Inf. Manag., 60:102358.
Bu, F., Wang, N., Jiang, B., and Liang, H. (2020). ”privacy by design” implementation: Information system engineers’ perspective. Int. J. Inf. Manag., 53:102124.
Canedo, E. D., Calazans, A. T. S., Masson, E. T. S., Costa, P. H. T., and Lima, F. (2020). Perceptions of ICT practitioners regarding software privacy. Entropy, 22(4):429.
Canedo, E. D. and Mendes, B. C. (2020). Software requirements classification using machine learning algorithms. Entropy, 22(9):1057.
Cavoukian, A. (2012). Privacy by design [leading edge]. IEEE Technol. Soc. Mag., 31(4):18–19.
Chander, A. and Land, M. (2014). United nations general assembly resolution on the right to privacy in the digital age. International Legal Materials, 53(4):727–731.
Confessore, N. (2018). Cambridge analytica and facebook: The scandal and the fallout so far. The New York Times, 4:2018.
de Chaves, S. A. and Benitti, F. B. V. (2023). Privacy by design in software engineering: An update of a systematic mapping study. In Hong, J., Lanperne, M., Park, J. W., Cerný, T., and Shahriar, H., editors, Proceedings of the 38th ACM/SIGAPP Symposium on Applied Computing, SAC 2023, Tallinn, Estonia, March 27-31, 2023, pages 1362–1369. ACM.
de Mello, R. M. and Travassos, G. H. (2016). Surveys in software engineering: Identifying representative samples. In Proceedings of the 10th ACM/IEEE International Symposium on Empirical Software Engineering and Measurement, ESEM 2016, Ciudad Real, Spain, September 8-9, 2016, pages 55:1–55:6. ACM.
Ferrão, S. É. R., Silva, G. R. S., Canedo, E. D., and Mendes, F. F. (2024). Towards a taxonomy of privacy requirements based on the LGPD and ISO/IEC 29100. Inf. Softw. Technol., 168:107396.
for Standardization (ISO), I. O. (2024). Iso/iec 29100:2024. information technology — security techniques — privacy framework.
Gonçalves, André Luiz Dias (2025). Tudo sobre o vazamento de dados de 223 milhões de brasileiros. [link].
Hadar, I., Hasson, T., Ayalon, O., Toch, E., Birnhack, M., Sherman, S., and Balissa, A. (2018). Privacy by designers: software developers’ privacy mindset. Empir. Softw. Eng., 23(1):259–289.
Kitchenham, B. A. and Pfleeger, S. L. (2002). Principles of survey research: part 5: populations and samples. ACM SIGSOFT Softw. Eng. Notes, 27(5):17–20.
Kitchenham, B. A. and Pfleeger, S. L. (2008). Personal opinion surveys. In Shull, F., Singer, J., and Sjøberg, D. I. K., editors, Guide to Advanced Empirical Software Engineering, pages 63–92. Springer.
Kosenkov, O., Zabardast, E., Fucci, D., Méndez, D., and Unterkalmsteiner, M. (2026). Privacy by design: Aligning GDPR and software engineering specifications with a requirements engineering approach. Inf. Softw. Technol., 190:107946.
Kuliamin, V. V., Petrenko, A. K., and Rudina, E. A. (2025). Software security by design. Program. Comput. Softw., 51(6):429–434.
Matos, A., Patrício, M., Nicolau, M. I., Canedo, E. D., Pereira, J. A., and Uchôa, A. G. (2025). Data privacy in software practice: Brazilian developers’ perspectives. J. Internet Serv. Appl., 16(1):299–319.
Menegazzi, D. and Silva, C. (2023). Conformidade com a LGPD por meio de requisitos de negócio e requisitos de solução. In Antonelli, L., Lucena, M., and Portugal, R. L. Q., editors, Anais do WER23 - Workshop em Engenharia de Requisitos, Porto Alegre, RS, Brasil, August 15-17, 2023. LFS (UFRN, Brasil).
Norman, G. (2010). Likert scales, levels of measurement and the ”laws” of statistics. Advances in Health Sciences Education, 15(5):625–632.
Pallas, F., Koerner, K., Barberá, I., Hoepman, J., Jensen, M., Narla, N. R., Samarin, N., Ulbricht, M., Wagner, I., Wuyts, K., and Zimmermann, C. (2024). Privacy engineering from principles to practice: A roadmap. IEEE Secur. Priv., 22(2):86–92.
Presidência da República do Brasil (2018). Lei no 13.709, de 14 de agosto de 2018. lei geral de proteção de dados pessoais (LGPD). [link].
Ribak, R. (2019). Translating privacy: Developer cultures in the global world of practice. Information, Communication & Society, 22(6):838–853.
Rocha, L. D. and Canedo, E. D. (2025). Optimizing compliance: Comparative study of data laws and privacy frameworks. J. Internet Serv. Appl., 16(1):431–452.
Rocha, L. D., Silva, G. R. S., and Canedo, E. D. (2023). Privacy compliance in software development: A guide to implementing the LGPD principles. In Hong, J., Lanperne, M., Park, J. W., Cerný, T., and Shahriar, H., editors, Proceedings of the 38th ACM/SIGAPP Symposium on Applied Computing, SAC 2023, Tallinn, Estonia, March 27-31, 2023, pages 1352–1361. ACM.
Rodrigues, G. A. P., Fernandes, P. A. G., Serrano, A. L. M., Filho, G. P. R., Vergara, G. F., Bispo, G. D., de Oliveira Albuquerque, R., and Gonçalves, V. P. (2025). From rockyou to rockyou2024: Analyzing password patterns across generations, their use in industrial systems and vulnerability to password guessing attacks. J. Internet Serv. Appl., 16(1):69–86.
Rodrigues, G. A. P., Serrano, A. L. M., Lemos, A. N. L. E., Canedo, E. D., de Mendonça, F. L. L., de Oliveira Albuquerque, R., Orozco, A. L. S., and García-Villalba, L. J. (2024). Understanding data breach from a global perspective: Incident visualization and data protection law review. Data, 9(2):27.
Sangaroonsilp, P., Dam, H. K., Choetkiertikul, M., Ragkhitwetsagul, C., and Ghose, A. (2023). A taxonomy for mining and classifying privacy requirements in issue reports. Inf. Softw. Technol., 157:107162.
Secretaria de Governo Digital (28 de março de 2023). Portaria nº 852 sgd/mgi. [link].
Spiekermann, S. (2012). The challenges of privacy by design. Commun. ACM, 55(7):38–40.
Spósito, S., Alves, K., Nunes, R., Ferreira, L., and Canedo, E. (2025a). Structuring privacy and information security competencies for public sector roles: A framework for enhancing software quality and lgpd compliance. In Anais do XXIV Simpósio Brasileiro de Qualidade de Software, pages 365–375, Porto Alegre, RS, Brasil. SBC.
Spósito, S. L., Targino, J. F. G., Silva, G. R. S., Peotta, L., Porto, D. d. P., Mendonça, F. L. L., and Canedo, E. D. (2025b). A comprehensive review of techniques, methods, processes, frameworks, and tools for privacy requirements. Journal of Internet Services and Applications, 16(1):508–529.
Tribunal de Contas da União (2025). TCU verifica risco alto à privacidade de dados pessoais coletados pelo governo. [link].
Union, E. (2018). General data protection regulation (GDPR). Intersoft Consulting, 1(1):1–100.
United Nations (ONU) (2025). Universal declaration of human rights at 70: 30 articles on 30 articles - article 12. [link].
Wohlin, C., Runeson, P., Höst, M., Ohlsson, M. C., Regnell, B., and Wesslén, A. (2012). Experimentation in Software Engineering. Springer.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Fernando Elias de Oliveira, Stefano Luppi Spósito, Fabiana Freitas Mendes, Edna Dias Canedo

This work is licensed under a Creative Commons Attribution 4.0 International License.

