Abstract
In recent decades, Privacy Enhancing Technologies (PETs) have been gaining attention as a means to fulfill regulatory and user privacy requirements when processing personal data in software systems. Despite broad attention in research, support by regulators, contributions and adoption by large technological companies (like Google or Microsoft), and interest from software developers, adoption of PETs in practice is still challenging and lagging. For many years, existing research points to the same typical challenges to the adoption of PETs, such as complexity or absence of training; however, these challenges remain unresolved in practice despite the recent efforts.
In this industrial challenge paper, we take a deeper, practical requirements engineering-driven perspective on the challenges to PETs adoption across different stakeholders (namely, PETs developers and integrators, and PET adopters and users) and different disciplines (engineering, law, and business).
We suggest that the adoption of PETs should be facilitated with an in-depth understanding of engineering, business, and legal challenges to PETs, such as PETs' impact on software architecture, their business impact, and contribution to compliance. We suggest that requirements engineering research can play a crucial role in better exploring and modeling such viewpoints. In practice, requirements engineering could facilitate the coordination of the involved viewpoints to enable the adoption of existing and the development of new PETs.