Privacy engineering map: 13 dimensions from 90 GDPR studies
New systematic review reveals how to embed privacy into every software lifecycle phase
A new systematic literature review by Borovits, Tamburri, and van den Heuvel (arXiv:2606.23696) distills 90 peer-reviewed studies from 2018-2025 into a comprehensive map of privacy engineering under GDPR. The authors use thematic synthesis to identify 13 recurring dimensions, which group into two cores: a technical core combining Privacy Enhancing Technologies (PETs), Privacy Metrics (PM), and Verification & Testing (VT); and an organizational core linking Governance & Accountability (GA), Transparency & Communication (TC), and Organizational Measures (OM). Modeling & Specification (MS) acts as a mediator between the two cores.
The lifecycle analysis reveals where each dimension is most active: requirements and design phases concentrate on MS and GA; implementation and verification focus on PETs, VT, PM, and TC; operations and decommissioning involve GA, OM, Data Subject Rights Management (DSRM), and Incident Response (IRM). Domain-specific weightings shift but don't break the structure—healthcare emphasizes GA with VT and PETs, IoT/edge prioritizes PETs with VT and PM, web measurement focuses on TC with VT, and AI/ML on PETs with PM. The authors flag IRM, Lifelong Management (LM), and Data Minimization as understudied, signaling future research priorities. This work provides a replication-ready scaffold for practitioners to assess and update their own privacy engineering efforts.
- 90 studies from 2018-2025 were synthesized to identify 13 privacy engineering dimensions
- Two core clusters emerged: technical (PETs, Metrics, Verification) and organizational (Governance, Transparency, Measures)
- Lifecycle mapping shows concentrations at requirements/design (MS, GA), implementation/verification (PETs, VT), and operation/decommissioning (GA, OM, IRM)
Why It Matters
Provides a practical, research-backed map for engineering GDPR-compliant software across the full lifecycle.