Disagreeable Privacy Policies: Mismatches between Meaning and Users’ Understanding

通知 隐私政策 互联网隐私 合法性 互联网 信息隐私 意义(存在) 个人可识别信息 社会学 公共关系 政治学 计算机科学 万维网 法学 心理学 政治 心理治疗师
作者
Joël R. Reidenberg,Travis D. Breaux,Lorrie Faith Carnor,Brian F. French
出处
期刊:Berkeley Technology Law Journal 卷期号:30 (1): 39- 被引量:181
标识
DOI:10.15779/z384k33
摘要

Privacy policies are verbose, difficult to understand, take too long to read, and may be the least-read items on most websites even as users express growing concerns about information collection practices. For all their faults, though, privacy policies remain the single most important source of information for users to attempt to learn how companies collect, use, and share data. Likewise, these policies form the basis for the selfregulatory notice and choice framework that is designed and promoted as a replacement for regulation. The underlying value and legitimacy of notice and choice depends, however, on the ability of users to understand privacy policies. This paper investigates the differences in interpretation among expert, knowledgeable, and typical users and explores whether these groups can understand the practices described in privacy policies at a level sufficient to support rational decision-making. This paper seeks © 2015 Joel R. Reidenberg, Travis Breaux, Lorrie Faith Cranor, Brian French, Amanda Grannis, James T. Graves, Fei Liu, Aleecia McDonald, Thomas B. Norton, Rohan Ramanath, N. Cameron Russell, Norman Sadeh and Florian Schaub. † For their comments on this study, the authors would like to acknowledge and thank Alessandro Acquisti, Noah A. Smith, and Shomir Wilson, and the participants at the 2014 TPRC 42nd Research Conference on Communication, Information and Internet Policy. Funding for this project was provided, in part, by the National Science Foundation under its Secure and Trustworthy Computing (SaTC) initiative grants 1330596, 1330214, and 1330141 for “TWC SBE: Option: Frontier: Collaborative: Towards Effective Web Privacy Notice and Choice: A Multi-Disciplinary Prospective” and by a Fordham Law School Faculty Research Grant. †† Respectively, Stanley D. and Nikki Waxberg Chair and Professor of Law, Fordham University; Assistant Professor of Computer Science, Carnegie Mellon University; Professor of Computer Science and Engineering & Public Policy, Carnegie Mellon University: Senior Research Programmer, Carnegie Mellon University; Research Fellow, Fordham Center on Law and Information Policy; Ph.D Candidate (Engineering and Public Policy) Carnegie Mellon University; Ph.D Candidate (Computer Science), Carnegie Mellon University; Director of Privacy, Stanford Center for Internet & Society; Privacy Fellow, Fordham Center on Law and Information Policy; Masters Candidate (Computer Science), Carnegie Mellon University; Executive Director, Fordham Center on Law and Information Policy; Professor of Computer Science, Carnegie Mellon University; Postdoctoral Fellow (Computer Science), Carnegie Mellon University. 40 BERKELEY TECHNOLOGY LAW JOURNAL [Vol. 30:1 to fill an important gap in the understanding of privacy policies through primary research on user interpretation and to inform the development of technologies combining natural language processing, machine learning, and crowdsourcing for policy interpretation and summarization. For this research, we recruited a group of law and public policy graduate students at Fordham University, Carnegie Mellon University, and the University of Pittsburgh (“knowledgeable users”) and presented these law and policy researchers with a set of privacy policies from companies in the e-commerce and news and entertainment industries. We asked them nine basic questions about the policies’ statements regarding data collection, data use, and retention. We then presented the same set of policies to a group of privacy experts and to a group of crowd workers representing typical Internet users. The findings show areas of common understanding across all groups for certain data collection and deletion practices, but also demonstrate very important discrepancies in the interpretation of privacy policy language, particularly with respect to data sharing. The discordant interpretations arose both within groups and between the experts and the two other groups. The presence of these significant discrepancies has critical implications. First, the common understandings of some attributes of described data practices mean that semiautomated extraction of meaning from website privacy policies may be able to assist typical users and improve the effectiveness of notice by conveying the true meaning of these policies. However, the disagreements among experts and disagreement between experts and the other groups reflect that ambiguous wording in typical privacy policies undermines the ability of privacy policies to effectively convey notice of data practices to the general public. The results of this research will, consequently, have significant policy implications for the construction of the notice and choice framework and for the U.S. reliance on this approach. The gap in interpretation indicates that privacy policies may be misleading the general public and that those policies could be considered legally unfair and deceptive. And, where websites are not effectively conveying privacy policies to consumers in a way that a “reasonable person” could, in fact, understand the policies, “notice and choice” fails as a framework. Such a failure has broad international implications since websites extend their reach beyond the United States.

科研通智能强力驱动
Strongly Powered by AbleSci AI
更新
大幅提高文件上传限制,最高150M (2024-4-1)

科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
盼盼完成签到,获得积分10
刚刚
1秒前
2秒前
3秒前
穆紫应助kk采纳,获得10
3秒前
搜集达人应助zzz采纳,获得30
3秒前
研友_VZG7GZ应助阿三采纳,获得10
4秒前
盼盼发布了新的文献求助10
5秒前
虚拟的姒发布了新的文献求助20
5秒前
爆米花应助吃人陈采纳,获得10
6秒前
zxvcbnm发布了新的文献求助10
6秒前
缥缈伟祺完成签到,获得积分20
7秒前
7秒前
杀手爱吃小熊饼干完成签到,获得积分20
7秒前
DianaRang发布了新的文献求助10
8秒前
8秒前
8秒前
初级小白发布了新的文献求助10
9秒前
10秒前
10秒前
10秒前
11秒前
月光取暖发布了新的文献求助10
12秒前
狂野元枫发布了新的文献求助10
12秒前
huo发布了新的文献求助10
12秒前
ningning完成签到 ,获得积分10
12秒前
zzz完成签到,获得积分20
12秒前
鹿不羁完成签到 ,获得积分10
12秒前
whz完成签到,获得积分10
13秒前
13秒前
李健应助橙子采纳,获得10
14秒前
1233发布了新的文献求助10
14秒前
mitty完成签到,获得积分10
16秒前
16秒前
专注亦玉发布了新的文献求助10
16秒前
冷艳的寻冬完成签到,获得积分10
17秒前
17秒前
18秒前
18秒前
李健的小迷弟应助huo采纳,获得10
18秒前
高分求助中
Sustainability in Tides Chemistry 2000
Bayesian Models of Cognition:Reverse Engineering the Mind 800
Essentials of thematic analysis 700
A Dissection Guide & Atlas to the Rabbit 600
Very-high-order BVD Schemes Using β-variable THINC Method 568
Mantiden: Faszinierende Lauerjäger Faszinierende Lauerjäger 500
PraxisRatgeber: Mantiden: Faszinierende Lauerjäger 500
热门求助领域 (近24小时)
化学 医学 生物 材料科学 工程类 有机化学 生物化学 物理 内科学 纳米技术 计算机科学 化学工程 复合材料 基因 遗传学 催化作用 物理化学 免疫学 量子力学 细胞生物学
热门帖子
关注 科研通微信公众号,转发送积分 3124803
求助须知:如何正确求助?哪些是违规求助? 2775148
关于积分的说明 7725553
捐赠科研通 2430633
什么是DOI,文献DOI怎么找? 1291291
科研通“疑难数据库(出版商)”最低求助积分说明 622121
版权声明 600328