2019
DOI: 10.1609/hcomp.v7i1.5266
|View full text |Cite
|
Sign up to set email alerts
|

Going against the (Appropriate) Flow: A Contextual Integrity Approach to Privacy Policy Analysis

Abstract: We present a method for analyzing privacy policies using the framework of contextual integrity (CI). This method allows for the systematized detection of issues with privacy policy statements that hinder readers’ ability to understand and evaluate company data collection practices. These issues include missing contextual details, vague language, and overwhelming possible interpretations of described information transfers. We demonstrate this method in two different settings. First, we compare versions of Faceb… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
12
0

Year Published

2020
2020
2024
2024

Publication Types

Select...
3
3
2
1

Relationship

0
9

Authors

Journals

citations
Cited by 19 publications
(12 citation statements)
references
References 28 publications
(32 reference statements)
0
12
0
Order By: Relevance
“…We then empirically documented the prevalence and visibility of data collection within Disney Parks, various identifiable categories of sensors that interact with apps and with MagicBands. Following the Shvartzshnaider et al (2019) methodology, we annotated statements that describe information-handling practices in terms of relevant CI parameters in prescribed flows analysis of the Walt Disney Company privacy policy and My Disney Experience -Frequently Asked Questions (FAQs) page.…”
Section: Methodsmentioning
confidence: 99%
“…We then empirically documented the prevalence and visibility of data collection within Disney Parks, various identifiable categories of sensors that interact with apps and with MagicBands. Following the Shvartzshnaider et al (2019) methodology, we annotated statements that describe information-handling practices in terms of relevant CI parameters in prescribed flows analysis of the Walt Disney Company privacy policy and My Disney Experience -Frequently Asked Questions (FAQs) page.…”
Section: Methodsmentioning
confidence: 99%
“…Moreover, prior works have also focused on enabling automated understanding of privacy policies [27], [4], [33]. Additionally, prior work has used the theory of Contextual Integrity [47] to study the alignment with U.S. Children's Online Privacy Protection Act (COPPA) [9], and to evaluate its viability in privacy policies [64]. However, none of these works focus on analyzing privacy regulations, which is the focus of our work.…”
Section: Related Workmentioning
confidence: 99%
“…This analysis can help in identifying potentially confusing or misleading statements, e.g., when one of the five parameters such as transmission principle or receiver is missing or ambiguous (Shvartzshnaider et al, 2019a). Furthermore, one can use the identified parameters to formalize the expressed informational norms and privacy rules in formal logic (Shvartzshnaider et al, 2019b;Datta et al, 2011).…”
Section: And Privacymentioning
confidence: 99%
“…In this paper, we show that existing NLP models and techniques can assist a human annotator in identifying relevant privacy parameters in the policy text. The proposed novel NLP task can support the following applications: automate comparative analysis of privacy policies using the theory of contextual integrity (Shvartzshnaider et al, 2019a;Sanfilippo et al, 2019); extraction and enforcement of prescribed CI-based policy from legal and co-operate document (Shvartzshnaider et al, 2019a;Sanfilippo et al, 2019), an enhanced auditing of existing privacy policies for correctness and consistency (Andow et al, 2019).…”
Section: Introductionmentioning
confidence: 99%