Full text
Investigating Privacy by Design in Software Development: Insights from Brazilian Federal Higher Education Institutions Blind 1Blind Abstract. Research Context: The increasing digitalization of services in Brazilian Federal Higher Education Institutions (IFES) intensifies the processing of sensitive personal data, raising urgent concerns regarding compliance with the General Data Protection Law (LGPD) and the systematic adoption of Privacy by Design (PbD). Although privacy is recognized as a constitutional right and a central element of data governance, audits and prior studies reveal a lack of consolidated methods to assess and improve privacy maturity in software development within IFES. Practical Problem: Despite the existence of PbD principles and international frameworks, organizations still face difficulties in translating abstract legal requirements into concrete software engineering practices. This gap is particularly critical in IFES, where academic management systems store highly sensitive information and where deficiencies in privacy and security have been repeatedly identified by oversight bodies. Proposed Solution: This study investigates how IT professionals in IFES perceive, understand, and apply PbD principles in their daily work. Through a mixed-method survey, we diagnose the maturity of privacy practices across the software lifecycle, identifying adoption levels, barriers, and enablers of PbD implementation. Related IS Theory: The research is grounded in socio-technical perspectives of Information Systems, drawing on Privacy Engineering, Privacy Requirements Engineering, and adoption models such as the Unified Theory of Acceptance and Use of Technology (UTAUT). These theoretical lenses highlight the interplay between individual perceptions, organizational culture, and technical practices in shaping PbD maturity. Research Method: A survey instrument with 55 questions, including Likert-scale and open-ended items, was distributed to IT professionals in IFES. Responses from 58 participants across 15 Brazilian states were analyzed using descriptive statistics, correlation analysis, and qualitative coding based on Grounded Theory. Summary of Results: The findings reveal strong awareness of privacy as a fundamental right and recognition of shared responsibility, but also significant gaps in regulatory knowledge, structured training, and systematic adoption of advanced privacy strategies. While encryption and minimization are common, strategies such as decentralization, sovereignty, and proxies remain underutilized. Moreover, organizational structures are fragmented, tools are rarely adopted, and practices tend to be reactive rather than proactive. Contributions and Impact to IS area: This study provides empirical evidence of how PbD is understood and practiced in IFES, exposing maturity gaps and socio-technical barriers. It contributes a diagnostic perspective that informs both academia and practice, supporting the design of frameworks and instruments to foster PbD adoption in public-sector information systems, where sensitivity of data and regulatory pressures are particularly high.
Keywords: Privacy by Design; LGPD Compliance; Privacy Engineering; Software Development Lifecycle; Brazilian Federal Higher Education Institutions. 1. Tables The survey was designed to capture the perceptions and practices of IT professionals in Brazilian Federal Higher Education Institutions regarding data privacy in software development. It was structured into six sections, covering both demographic information and thematic aspects of privacy awareness, attitudes, behaviors, and organizational practices. The instrument contained a total of 55 questions, distributed as follows: 1. Participant Profile (Q1–Q10): This section collected demographic and professional background information, including age, education level, role, seniority, type of employment, and professional experience with data privacy. These questions were all closed-ended, except for one open-ended item (Q10) allowing participants to briefly describe their prior experience with data privacy. 2. Privacy Awareness – Knowledge (Q11–Q21): This section focused on participants’ conceptual understanding and knowledge of privacy. It included items about familiarity with privacy laws and standards (e.g., LGPD, ISO/IEC 29100, PbD), training, self-learning practices, and recognition of privacy-related risks. One open-ended question (Q13) asked participants to list five words that come to mind when thinking about privacy, while the remaining were closed-ended Likert scale items. 3. Privacy Awareness – Attitudes and Sentiments (Q21–Q27): This block measured professionals’ personal attitudes and beliefs regarding privacy, such as distinguishing between security and privacy, concerns about monitoring, valuing informed consent, or perceiving privacy as a fundamental right. Most items were closedended Likert scales, with one optional open-ended question for participants to justify strong disagreements. 4. Privacy Behaviors and Actions (Q28–Q37): This section investigated concrete actions performed by participants in their professional context, such as recognizing data retention limits, identifying privacy problems, proposing solutions, or advocating privacy in their teams. These items were primarily closed-ended Likert scale questions, complemented by an optional open-ended question to explain disagreement. 5. Privacy Strategies and Practices (Q38–Q43): This part examined the frequency, importance, and ease of use of privacy strategies and techniques (e.g., encryption, minimization, anonymization, risk management, code reviews). Questions were closed-ended matrix items with Likert-type scales for frequency, importance, and perceived ease of use. An additional open-ended question (Q40, Q42) allowed participants to suggest other strategies or justify their assessments. 6. Organizational and Individual Factors (Q44–Q55): This final section addressed organizational dynamics and adoption factors, such as the existence of dedicated privacy teams, use of tools, prioritization of privacy, productivity impacts, incentives, sanctions, and perceptions about Privacy by Design. Most were closedended questions (Likert scales and categorical options), with one open-ended item (Q45, Q48) asking respondents to describe their organization’s privacy dynamics and identify major future challenges.
In total, the survey combined 46 closed-ended questions and 9 open-ended questions. The closed-ended items primarily used five-point Likert scales or multiple-choice options, ensuring comparability of responses, while the open-ended items enabled deeper qualitative insights into participants’ perceptions, experiences, and contextual practices, as shown in Table 1. Table 1. Survey questions, type, and associated Research Question (RQ) ID Question Type RQ Q1 What is your age group? Multiple choice Profile Q2 In which state is your institution located? Multiple choice Profile Q3 What is your highest completed level of formal education? Multiple choice Profile Q4 What is your work model (remote, hybrid, on-site)? Multiple choice Profile Q5 Which role best describes your current activities in software lifecycle projects? Multiple choice Profile Q6 Indicate the seniority level of your current position. Multiple choice Profile Q7 How many years of experience do you have in IT/software development roles? Multiple choice Profile Q8 What is your type of employment with the institution? Multiple choice Profile Q9 Do you have or have you ever had professional experience related to data privacy? Multiple choice Profile Q10 Briefly describe your experience with data privacy in software. If none, state that you have no experience. Open-ended Profile Q11 What are the main sources or methods you use to learn about data privacy in software? Multiple choice RQ1 Q12 What types of personal data do you handle in your work? Multiple choice RQ1 Q13 Provide at least five words that come to mind when you think of privacy. Open-ended RQ1 Q14 I am aware of privacy laws relevant to my field, such as ISO/IEC 29100 and Privacy by Design. Likert scale RQ1 Q15 I have solid knowledge of privacy laws and regulations that apply to my work and how they influence software development. Likert scale RQ1 Q16 I have participated in internal trainings or workshops on security and privacy, including internal privacy policies and sector-specific regulations. Likert scale RQ1 Continued on next page
ID Question Type RQ Q17 I seek to learn about privacy on my own initiative, including reading laws and regulations and consulting specialists. Likert scale RQ1 Q18 I recognize the risks and concerns related to data privacy in software systems, such as data leaks, unauthorized access, and lack of user control. Likert scale RQ1 Q19 I know best practices and techniques to protect user privacy in software systems, including data anonymization and access control practices. Likert scale RQ1 Q20 I understand the difference between security and privacy, recognizing that privacy goes beyond data protection and includes aspects such as control over data and informed consent. Likert scale RQ1 Q21 For statements with which you strongly disagreed, describe the reason for your assessment Open-ended RQ1 Q22 I worry about being monitored or manipulated when using apps, social networks, or browsing the internet. Likert scale RQ1 Q23 I believe personal privacy is a fundamental right and we must remain alert to privacy violations. Likert scale RQ1 Q24 I feel personally responsible for protecting user privacy in my work as an IT professional. Likert scale RQ1 Q25 I perceive that many people do not care about privacy, but I believe it is important to educate and raise awareness about privacy rights. Likert scale RQ1 Q26 I feel frustrated with the idea that privacy is unattainable in today’s digital society. Likert scale RQ1 Q27 I value users’ informed consent before data collection and believe it is essential for building trust between users and developers. Likert scale RQ1 Q28 I recognize that the retention of personal data must be limited and depends on the type of data and system purpose. Likert scale RQ2 Q29 I consider privacy a shared responsibility across the entire IT team. Likert scale RQ2 Continued on next page
ID Question Type RQ Q30 For statements with which you strongly disagreed, describe the reason for your assessment Open-ended RQ2 Q31 Identifying privacy issues during development activities is an important part of my professional routine. Likert scale RQ2 Q32 When I encounter privacy issues, I escalate them to project leaders, more experienced colleagues, or security operations teams. Likert scale RQ2 Q33 I propose solutions to privacy issues identified during software development or operation. Likert scale RQ2 Q34 I have played the role of privacy advocate in my team or organization. Likert scale RQ2 Q35 When dealing with privacy conflicts with clients, I try to negotiate the implementation of privacy controls. Likert scale RQ2 Q36 I have faced suspicious client requests for excessive data collection. Likert scale RQ2 Q37 For statements with which you strongly disagreed, describe the reason for your assessment Open-ended RQ2 Q38 How often do you use privacy techniques and strategies to protect personal data in the following activities: requirements analysis, design, coding, feasibility study, application installation, deployment, testing, maintenance, operation, support. Likert scale (matrix) RQ2 Q39 How often do you use or have you used the following privacy strategies: encryption, minimization of personal data collection, decentralization, data sovereignty, data temporality, user control, disabling data collection, anonymization, data classification tools, code and design reviews, risk management, data flow modeling, proxy. Likert scale (matrix) RQ2 Q40 Do you use any other implementation strategies to ensure privacy not mentioned in the previous question? Open-ended RQ2 Continued on next page
ID Question Type RQ Q41 In your opinion, what is the importance level of the following privacy strategies (encryption, minimization, anonymization, etc.)? Likert scale (matrix) RQ2 Q42 For the strategies you considered important, describe the reason for your assessment. Open-ended RQ2 Q43 Regarding these strategies, how would you characterize their ease of use? Likert scale (matrix) RQ2 Q44 In your organization, is there a team dedicated exclusively to privacy management? Multiple choice RQ3 Q45 In your organization, what is the working dynamic for privacy and data protection management? Open-ended RQ3 Q46 In your organization, are one or more tools used for managing private data? If yes, which ones? Multiple choice + open RQ3 Q47 What is your perception of your organization’s priority regarding privacy and data protection? Likert scale RQ3 Q48 In your opinion, what will be the biggest challenges for organizations in the coming years regarding practices and regulations to better protect users’ privacy rights? Open-ended RQ3 Q49 Compliance with privacy requirements harms my productivity. Likert scale RQ3 Q50 I will receive incentives/recognition for adopting privacy practices. Likert scale RQ3 Q51 I will receive some disapproval if I do not follow privacy rules. Likert scale RQ3 Q52 The adoption of Privacy by Design is not compatible with my activities. Likert scale RQ3 Q53 My peers/leaders think I should adopt privacy practices. Likert scale RQ3 Q54 It is easy to become skilled in the use of privacy. Likert scale RQ3 Q55 Privacy improves the performance of information security in software. Likert scale RQ3 References
Age group # % 25–34 years 10 17.2 35–44 years 28 48.3 45–54 years 14 24.1 55–64 years 6 10.3 Region (Brazil) # % Southeast (MG, SP, ES, RJ) 23 39.6 Center-West (DF, GO, MT, MS) 13 22.4 South (PR, SC, RS) 6 10.4 Northeast (BA, MA, SE, CE, AL, PI, PE, RN, PB) 9 15.5 North (AC, TO, RO, RR, AM, PA, AP) 7 12.1 Education Level # % Graduated 4 6.9 Specialization 21 36.2 Master’s degree 29 50.0 PhD 4 6.9 Work Model # % Remote (full) 18 31.0 Hybrid (partial) 14 24.1 On-site 26 44.8 Professional Role # % Developer (backend/frontend/fullstack) 19 32.9 Analyst (requirements/business) 7 12.1 Project Leader 7 12.1 Operations/Support 8 13.7 Architect (solutions, DB, etc.) 4 6.9 Security Engineer 3 5.2 Privacy Engineer 2 3.4 Others (Data Engineer, Data Scientist, Tester, IT Auditor, Database Administrator) 8 13.7 Seniority in Current Role # % Up to 5 years 16 27.6 6–9 years 12 20.6 10–15 years 15 25.9 16+ years 15 25.9 Experience in IT/Software # % Less than 1 year 4 6.9 1–6 years 16 27.6 7–14 years 14 24.1 15+ years 24 41.4 Employment Type # % Federal Public Servant 56 96.6 Outsourced 2 3.4 Privacy Experience # % No experience 25 43.1 Direct experience 17 29.3 Indirect experience 16 27.6 Table 2. Demographic profile of survey respondents (dataset, n= 58).
Category # Examples of Terms Security and Protection 47 security, protection, defense, reliability, integrity Confidentiality, Secrecy, Anonymity 35 confidentiality, secrecy, anonymity, hidden, restriction Personal and Sensitive Data 28 personal data, CPF, address, income, sensitive data Legislation and Compliance 25 LGPD, law, regulation, compliance, audit Control and Access Management 22 access, control, permission, governance, authorization Ethical and Social Values 20 rights, freedom, citizenship, intimacy, dignity, trust Risks, Incidents, and Sanctions 18 data breach, fraud, scam, risk, incident, fine, embarrassment Table 3. Categories of words associated with privacy based on responses (Q13).
Table 4. Categories of organizational dynamics for privacy and data protection (Q45, open-ended responses). Category # Examples (translated) No knowledge / Cannot describe 14 “I do not know the dynamics of privacy and data protection in my organization.” No formal structure 11 “There is no defined dynamic yet.” / “There is no formal role or team.” Shared responsibility (distributed across IT teams) 9 “Responsibilities are shared among IT teams.” / “Each team deals with it separately, without a protocol.” DPO responsibility (with or without support) 8 “The DPO and their staff are in charge.” / “There is a DPO named, but no support team.” Committees or commissions 6 “There is a committee that is activated when a vulnerability is found.” / “A commission was appointed but with little productivity.” Reactive / On-demand approach 7 “It is reactive, handled only when incidents occur.” / “TI responds to demands when requested.” Internal policies and guidelines (POSIC, LGPD) 8 “Follow institutional POSIC.” / “Based on LGPD and institutional policies.” Technical controls (access, minimization, backups, monitoring) 7 “Adoption of minimum necessary principle in each system.” / “Authentication, access control, monitoring of systems.” Integration with software processes (requirements, permissions, dev cycle) 4 “We evaluate privacy points in requirements gathering and module access permissions.” Awareness and training efforts 3 “Annual training courses are offered.” / “User awareness activities are being developed.” Table 5. Categories of responses regarding the use of tools for managing personal data (Q46). Category # Examples of Terms/Responses No knowledge/None 46 “I have no knowledge”, “None”, “There is no” Specialized Tools (Privacy/DLP) 6 OneTrust, TrustArc, DPOnet (pilot), IBM Guardium, Varonis (DLP/monitoring), SECURAMDATA Institutional Policies / General Mechanisms 2 Authentication (LDAP), institutional data protection policies Restricted/Unclear Information 1 “Restricted information”