Social Sciences · Research topic

Open research questions in Privacy, Security, and Data Protection

94 unresolved questions extracted from the limitations and future-work sections of 2,908 Privacy, Security, and Data Protection papers in our library. Each links back to the study that raised it.

What the literature leaves open

  • Recommendation 1: Implement an Age-Specific Regulatory Framework India should contemplate establishing more detailed age classifications that acknowledge the developmental distinctions among: a) b) c) younger children; middle adolescents; older teenagers. A tiered strategy would more effectively balance: protection, autonomy, participation rights, d) evolving capacities. One of the primary drawbacks of the Digital Personal Data Protection Act, 2023 is its blanket definition of a "child" as anyone under the age of eighteen. Although this reflects a strong intent to protect, it does not sufficiently account for the developmental, psychological, and cognitive variations among children of different ages. A thirteen-year-old and a seventeen-year-old have significantly different levels of maturity, digital literacy, decision-making skills, and awareness of online dangers. Treating all minors the same could therefore lead to both practical and legal challenges. Implementing an age-specific or tiered regulatory framework would enable the law to offer tailored protections based on the evolving capacities and maturity levels of children. This approach is increasingly acknowledged internationally as a more balanced and effective way to regulate children's digital engagement and informational privacy. A. Necessity for an Age-Specific Framework Children's interactions with digital platforms vary based on their age, educational background, emotional growth, and social surroundings. Younger children often struggle to comprehend: • • • • • privacy policies; behavioral tracking; targeted marketing; data sharing risks; online manipulation. In contrast, older adolescents may have a higher level of digital literacy and actively use digital platforms for: learning, skill enhancement, professional networking, social engagement, creative pursuits, civic involvement. © Author(s). This work is peer-reviewed, openly published, and permanently archived This article is openly accessible and reusable with proper attribution. https://ijsmt.org/, Email: [email protected] 17 International Journal of Science, Strategic Management and Technology Volume 02 Issue 06 June-2026 | ISSN: 3108-1762 (Online) | Impact Factor: 3.8 An International, Peer-Reviewed, Open Access Scholarly Journal Indexed in recognized academic databases Thus, a strict regulatory framework that applies the same restrictions to everyone under eighteen could hinder adolescent autonomy and participation rights while imposing unnecessary compliance challenges on digital platforms.

    “Legal Protection of Children’s Data in the Digital Age: An Analysis of the DPDP Act, 2023” · 2026 · DOI
  • The methodology of this study is limited by multiple parameters, which affect the breadth of the study. First, it should be noted that the research is purely qualitative, using well-known models from architecture and criminology instead of actual quantitative data on the frequency of security breaches. Secondly, since the study utilizes metadata across the entire world, the individual experiences of certain social strata, specific to certain regions, are not taken into account. Finally, since the methods used in generative artificial intelligence, and data scraping technologies progress exponentially, cybercrime tactics may change much faster than defense mechanisms and academic literature.

    The Cost of Over-sharing: How Daily Facebook Posting Compromises Personal and Digital Security · 2026 · DOI
  • Findings The review concludes that while compliance-based approaches are necessary, they are insufficient to sustain trustworthiness in data-driven and AI-mediated settings characterised by information asymmetries, trans-border data flows and shifting notions of accountability.

    Trust-centred ethical data governance in artificial intelligence ecosystems · 2026 · DOI
  • Prior studies had underexplored the non-statical nature of OPC and the user privacy status quo, overlooking that the coping responses could switch over time.

    Revisiting online privacy concern in predicting user coping behavior: systematic review, conceptual framework, and research agenda · 2026 · DOI
  • Although this study reveals the internal logic of how flexible norms are designed to achieve intended effectiveness through structured document analysis, several limitations exist. First, static text focus. The analysis is primarily based on a static interpretation of texts, lacking direct empirical observation of dynamic implementation processes, the actual degree of participant compliance, and long-term effects. For instance, whether corporations truly implement training systems or whether user complaints receive effective responses requires empirical testing. Second, sample scope and generalizability. While the sample strives for diverse types, it predominantly consists of Chinese domestic regulations and does not exhaust all emerging governance forms. Moreover, as noted in the Section: Critical Discussion: Limits and Alternative Explanations, this study includes several non-tourism-specific documents and lacks negative cases. The generalizability of the conclusions needs verification in broader cultural, institutional, and sectoral contexts. Third, mechanism interaction vs. isolation. The study treats the three mechanisms as complementary and presents them in an analytical heuristic sequence. It does not examine conditions under which one mechanism dominates or backfires, nor does it empirically test interaction effects. Fourth, relationship with hard law and technical standards. The study focuses on the mechanism design of flexible norms themselves, with limited discussion on their interactive relationships with other governance tools like rigid norms and technical standards—a critical issue unavoidable in a complex governance ecosystem. In the future, the research directions will focus on: (a) conducting in-depth field investigations or questionnaire surveys to track the adoption, implementation, and effects of flexible norms within specific organizations, thereby validating and refining the mechanism model proposed in this study. (b) Employing qualitative comparative analysis (QCA) or fine-grained comparative case analysis to systematically compare flexible norms across types (e.g., national standards vs. corporate policies) and include negative cases to identify necessary and sufficient conditions for effectiveness. (c) Undertaking cross-national comparative research to test whether the mechanisms identified in China’s context operate similarly in other legal and cultural settings. (d) Examining the interplay between flexible norms, hard law, and technical standards to understand how hybrid governance systems can be optimized for sensitive personal information protection. Further, to validate the intended effectiveness claims, future research could adopt the following empirical strategies: (1) a survey measuring organizational compliance behaviors across firms that have adopted flexible norms with different mechanism configurations; (2) a difference-in-differences design comparing data breach incidents before and after the adoption of a specific flexible norm; (3) a qualitative comparative 155 Vol. 13, No. 2 Xu: How Do Flexible Norms Achieve Effectiveness for Sensitive Personal… analysis (QCA) with conditions such as presence/absence of role-driven mechanism, content-driven mechanism, and enforcement-driven mechanism, and outcome = demonstrable compliance.

    How Do Flexible Norms Achieve Effectiveness for Sensitive Personal Information Governance in Tourism Big Data Commercialization? · 2026 · DOI
  • Therefore, future research should examine how these dynamics play out among individuals of different vulnerable socio-demographic characteristics or less digitally en- gaged, as well as in different cultural settings. Furthermore, the dynamic rela- tionships between surveillance, disability, and digital subjectivity should be further explored through larger samples and interdisciplinary approaches.

    Disabled Individuals’ Experiences with Surveillance: Privacy, Security, and Accessibility Perspectives · 2026 · DOI
  • Future research should consider qualitative approaches that could reveal more subtle mechanisms of digital self-presentation management, such as the use of algospeak, account rotation, or deliberate content “banalization. One of the limitations of this study is the use of self-report scales—respondents may have underreported their level of exposure or overestimated their coping efforts.

    Privacy or Self-Censorship? Coping Strategies of Young Polish Job Candidates under Cybervetting · 2026 · DOI
  • VRD_Influence General (VRD_Influence_other) Personal (VRD_Influence_self) VRD_Harm General (VRD_Harm_other) Personal (VRD_Harm_self) VRD_Concern General (VRD_Concern_other) Personal (VRD_Harm_other) Median Mode Mean SD Min Max Wilcoxon test 4 3 3 3 3 2 4 4 2 2 2 2 3.34 3.20 2.84 2.82 2.77 2.64 1.08 1.11 1.19 1.16 1.18 1.17 1 1 1 1 1 1 5 W = 11081, 5 P = .001, r=-.15 5 W = 8849, 5 P = .931, r=-.004 5 W = 11528, 5 P = .003, r=-.13 Note. *P adjusted with Bonferroni correction. SD=Standard Deviation, W=test statistic, r=effect size. Table 8: Descriptive statistics of participants’ (𝑁 = 481) perceptions of VR design mechanisms’ benefits for users like themselves, for application developers or publishers, and for third party stakeholders (e.g., marketing, legal services, analytical vendors), on a scale from “1-strongly disagree” to “5-strongly agree”.

    Rushed by Discomfort, Trapped by Immersion: Users’ Experiences and Responses to Privacy Deceptive Design in Commercial VR Applications · 2026 · DOI
  • This SLR explored and analyzed existing solutions, including tools, guidelines, methods, methodologies, and frameworks in the current literature to address the challenges that developers face in integrating privacy into software development while supporting them in the privacy integration process. Through this extensive review, we identified that the existing developer-supporting solutions have been proposed aiming to address a primary set of common developer challenges such as lack of privacy expertise among developers [17, 52, 65, 66, 68, 100], difficulties in translating privacy principles into technical implementations [14, 26, 64, 83, 95, 97], inadequate regulatory guidance [17, 83, 95, 97], and the increasing privacy and security risks associated with third-party libraries and SDKs [44, 54, 77]. In Section 4.1, we discussed tools and methods to support developers in embedding privacy in the early stage of software development. It included tools like PCM-tool, RMCM, LINDUNN-Go, and a method called ThreatPoker. For design and development, tools like Parrot and Canella provide interactive environments for embedding privacy into IoT applications, while POSD (Privacy-Oriented Software Development) offers structured guidelines to facilitate privacy integration. Additionally, methodologies and frameworks have also been proposed to help developers in the software design and development process. It included frameworks such as CIA-level driven SDLC, secD4CloudMobile, and Hails, and methodologies such as PbE, CryptSDLC, and UML-based MDD. To enforce privacy in coding, tools like FixDroid and PrivacyCAT help detect vulnerabilities and suggest fixes to improve privacy in Android applications, and specifically in the WhatsApp application. Managing third-party dependencies is supported by tools like Up2Dep and DataAvalanche.io, which help developers avoid insecure or non-compliant SDKs and libraries. Further, PrivacyStreams and Platys are tools and frameworks, respectively, that have been proposed to help developers manage and secure personal data when developing software applications. Furthermore, to assist developers in understanding privacy principles, regulations, and secure development practices, approaches like Privacy Ideation Cards (PICs) and a workshop-based intervention have been proposed. Finally, generating privacy statements and policies is made easier with tools like Matcha, Privacy Label Wiz, PrivacyFlash Pro, Coconut, and Honeysuckle which assist developers in generating accurate privacy labels, policies, and notices to align with compliance requirements. However, the identified tools, guidelines, methods, methodologies, and frameworks discussed in the results section (i.e., Section 4) offer only partial solutions because of the limitations we discussed in the discussion section (i.e., Section 5). Many solutions require prior expertise in privacy and security [28, 65, 72], and require developers’ manual intervention [26, 58, 59, 65, 68, 83, 100], posing a barrier for developers with limited knowledge in these areas to use these solutions, as well as the possibility of human errors. Some solutions do not provide seamless integration with agile and real-world development workflows [26, 83], which causes difficulties in adoption for rapid software development environments. Additionally, many solutions are designed for specific environments (e.g., Android) or programming languages (e.g., Java) [26, 52, 54, 64, 66, 69, 78, 100], limiting their applicability across diverse software development ecosystems.

    Enhancing Privacy-Preserving Software Development from a Developers' Perspective: A Survey · 2026 · DOI
  • This SLR was conducted to offer a comprehensive overview of the topic while ensuring the reproducibility of the reported results in the literature. First, the returned articles for the search query were filtered using their titles and abstracts according to our inclusion and exclusion criteria. In that study selection phase, relevant articles may be overlooked.

    Enhancing Privacy-Preserving Software Development from a Developers' Perspective: A Survey · 2026 · DOI
  • THARAKA WIJESUNDARA, RMIT, Australia MATTHEW WARREN, RMIT, Australia NALIN ARACHCHILAGE, RMIT, Australia In software development, privacy preservation has become essential with the rise of privacy concerns and regulations such as GDPR and CCPA. While several tools, guidelines, methods, methodologies, and frameworks have been proposed to support developers embedding privacy into software applications, most of them are proofs-of-concept without empirical evaluations, making their practical applicability uncertain. These solutions should be evaluated for different types of scenarios (e.g., industry settings such as rapid software development environments, teams with different privacy knowledge, etc.) to determine what their limitations are in various industry settings and what changes are required to refine current solutions before putting them into industry and developing new developer-supporting approaches. For that, a thorough review of empirically evaluated current solutions will be very effective. However, the existing secondary studies that examine the available developer support provide broad overviews but do not specifically analyze empirically evaluated solutions and their limitations. Therefore, this Systematic Literature Review (SLR) aims to identify and analyze empirically validated solutions that are designed to help developers in privacy-preserving software development. The findings will provide valuable insights for researchers to improve current privacy-preserving solutions and for practitioners looking for effective and validated solutions to embed privacy into software development. CCS Concepts: • Security and privacy → Software and application security; Software security engineering; Additional Key Words and Phrases: privacy awareness, embed privacy, software application, support developers, tools, guidelines, methods, methodologies, frameworks ACM Reference Format: Tharaka Wijesundara, Matthew Warren, and Nalin Arachchilage. 2025. SoK: Enhancing Privacy-Preserving Software Development from a Developers’ Perspective. J. ACM 37, 4, Article 111 (April 2025), 35 pages. https://doi.org/XXXXXXX.XXXXXXX 1 INTRODUCTION In the recent past, various tools, guidelines, methods, methodologies, and frameworks have been proposed, providing different types of support for developers embedding privacy into software applications, including privacy requirement specification, improving privacy awareness, privacy-preserving coding, etc. [73, 78, 83, 95, 97]. Despite the availability of these solutions, developers still face challenges when embedding privacy into software applications. For example, developers struggle to comply with regulations because of a lack of actionable technical guidelines [37, 41, 91, 95, 97]. Additionally, developers often lack privacy awareness, and due to that, they face difficulties in translating privacy principles into software requirements, which leads to deprioritizing privacy in software development [17, 26, 32, 82]. Authors’ Contact Information: Tharaka Wijesundara, [email protected], RMIT, Melbourne, Victoria, Australia; Matthew Warren, RMIT, Melbourne, Victoria, Australia, [email protected]; Nalin Arachchilage, RMIT, Melbourne, Victoria, Australia, [email protected]. Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than the author(s) must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]. © 2025 Copyright held by the owner/author(s). Publication rights licensed to ACM.

    Enhancing Privacy-Preserving Software Development from a Developers' Perspective: A Survey · 2026 · DOI
  • For E-commerce Platforms (E-tailers):  Privacy-by-Design: Instead of burying data practices in legal jargon, platforms should use "Privacy Nutrition Labels"—simple, visual icons that explain what data is being harvested and why.  Ethical AI Incentives: Retailers should offer "Privacy-First" tiers where users can opt-out of deep tracking without losing access to basic personalisation features.

    THE PRIVACY PARADOX IN DIGITAL RETAIL: EVALUATING CONSUMER TRUST AND ATTITUDES TOWARDS AI-DRIVEN DATA HARVESTING AMONG E-COMMERCE USERS IN JALGAON · 2026 · DOI
  • Security Awareness of End-Users of Mobile this contributes to the level of awareness concerning confidentiality. A higher score indicates a better awareness The question meets the research observation by asses how the patient perceives the confidentiality of his healthcare data as an important aspect.

    Patients’ mHealth Apps Usage and Data Privacy, Security, and Confidentiality Concerns: Exploratory Study · 2026 · DOI
  • While the study examines autocratic settings, the generalizability of findings to democratic societies where surveillance cues and political sensitivity operate differently remains unclear.

    Digital Surveillance and Self-Censorship in Autocracies: Evidence from a Survey Experiment in Kazakhstan · 2026 · DOI
  • The heterogeneous effect by foreign media consumption should be interpreted with caution, as it remains unclear whether heightened sensitivity to surveillance among informed citizens reflects genuine differential effects or measurement artifacts.

    Digital Surveillance and Self-Censorship in Autocracies: Evidence from a Survey Experiment in Kazakhstan · 2026 · DOI
  • This study has two limitations that should be acknowledged. First, our paper primarily provides a theoretical discussion on the conceptualization and operationalization of variables within the Privacy Calculus Model (PCM). While we offer insights and recommendations, further empirical studies are necessary to determine which measurements should be used and to test the effectiveness of the alignment in measurements of variables. Second, our review only covers studies published between 2018 and 2023. With the emergence of generative AI, the context and behaviors surrounding information disclosure are likely to evolve significantly. Therefore, future research should focus on the implications of AI advancements on information disclosure, ensuring that the PCM remains relevant in the face of rapid technological change. More attention and discussion are needed to address these evolving contexts and behaviors in the privacy literature. 101 Peng Z et al. / RCR, Vol. 14, 84-118 REFERENCES Acquisti, A., Brandimarte, L., & Loewenstein, G. (2020). Secrets and likes: The drive for privacy and the difficulty of achieving it in the digital age. Journal of Consumer Psychology: The Official Journal of the Society for Consumer Psychology, 30(4), 736–758. https://doi.org/10.1002/jcpy.1191 Abramova, O., Wagner, A., Olt, C. M., & Buxmann, P. (2022). One for all, all for one: Social considerations in user acceptance of contact tracing apps using longitudinal evidence from Germany and Switzerland. International Journal of Information Management, 64, 102473. Alkhalifah, A., & Bukar, U. A. (2022). Examining the prediction of COVID-19 contact-tracing app adoption using an integrated model and hybrid approach analysis. Frontiers in Public Health, 10, 847184. Baek, Y. M., Kim, E.-M., & Bae, Y. (2014). My privacy is okay, but theirs is endangered: Why comparative optimism matters 48–56. https://doi.org/10.1016/j.chb.2013.10.010 in Human Behavior, concerns. Computers privacy online 31, in Barth, S., & De Jong, M. D. T. (2017). The privacy paradox – Investigating discrepancies between expressed privacy concerns and actual online behavior – A systematic literature review. Telematics and Informatics, 34(7), 1038–1058. https://doi.org/10.1016/j.tele.2017.04.013 Bartol, J., Vehovar, V., & Petrovčič, A. (2023). Systematic review of survey scales measuring information privacy concerns 102063.

    Rethinking the Trade-Off: A Systematic Review of Current Research on the Privacy Calculus Model · 2026 · DOI
  • While SHT manufacturers promise to provide a range of services relating to home security, health and wellness, automated domestic tasks, entertainment, and beyond, user perceptions vary widely in terms of benefits and drawbacks.

    User Perception of Smart Home Surveillance: An Integrative Review · 2024 · DOI
  • Finally, since this is a relatively understudied subject, we point out some areas where future conceptual and empirical work could contribute to the development of relevant ethics guidance and regulatory governance in SSA.

    Private commercial companies sharing health-relevant consumer data with health researchers in sub-Saharan Africa: an ethical exploration · 2024 · DOI
  • The question to be examined and discussed in the article is therefore: If personal data exist and there is a claim for erasure, can the obligation to erase be fulfilled by anonymising the personal data? Such question has not yet been addressed in the case law and has only been examined to a limited extent in the literature by different authors with no exact court ruling.

    Erasure and Anonymisation of Personal Data in Context of General Data Protection Regulation · 2022 · DOI
  • While the Snowden revelations began in 2013 and the Cambridge Analytica scandal broke in 2018, privacy extensions remain underexplored in the literature on privacy advocacy.

    Developing Privacy Extensions: Is it Advocacy through the Web Browser? · 2022 · DOI
  • Third, we outline the follow-on research we did to extend AppTrans to analyse the information sharing of mobile applications with third parties, with mixed results.

    Automating accountability? Privacy policies, data transparency, and the third party problem · 2021 · DOI
  • Privacy scholars, advocates, and activists repeatedly emphasize the fact that current measures of privacy protection are insufficient to counter the systemic threats presented by datafication and platformization (van Dijck, de Waal, and Poell 2018: 24).

    Normative Paradoxes of Privacy: Literacy and Choice in Platform Societies · 2020 · DOI
  • In particular, we focus on two popular trends in worker tracking—productivity apps and worker wellness programs—to argue that current legal constraints are insufficient and may leave American workers at the mercy of 24/7 employer monitoring.

    Limitless Worker Surveillance · 2016 · DOI
  • 2012)? Or should these data subject turn to the private company? While digital security governance is currently a hot issue, there is still a gap in research about how, in reality, security officials apply risk knowledge and protect privacy.

    Digital Security Governance and Risk Anticipation: What About the Role of Security Officials in Privacy Protection? · 2014 · DOI
  • This Article also evaluates the arguments for and against a market in personal data, and concludes that while free alienability arguments are insufficient to justify unregulated trade in personal information, concerns about market failure and the public's interest in a protected privacy commons are equally insufficient to justify a ban on the trade.

    Property, Privacy, and Personal Data · 2004 · DOI

Most-cited papers in Privacy, Security, and Data Protection

Most recent work

Find a gap in your own Privacy, Security, and Data Protection sub-topic

This page shows what the Privacy, Security, and Data Protection literature already flags as unresolved. To narrow it to your specific question, run the guided finder — it searches the gap library on demand and checks candidates against 250M+ OpenAlex works.

Open the Research Gap Finder →

Related topics in Social Sciences

94 open questions have been extracted from the limitations and future-work passages of 2,908 Privacy, Security, and Data Protection papers in our library. Each one below links back to the study that raised it, so you can read the original claim in context.

Tools for your next paper

Compare the categoryHonest roundups of the AI research tools, ours listed alongside the alternatives.

Command palette

Jump anywhere, run any action.