Skip to main content
QUICK REVIEW

[论文解读] Privacy Policies Across the Ages: Content and Readability of Privacy Policies 1996--2021

Isabel Wagner|arXiv (Cornell University)|Jan 21, 2022
Privacy, Security, and Data Protection被引用 7
一句话总结

本项纵向研究利用自然语言处理与机器学习技术,分析了1996年至2021年间50,000份隐私政策,发现政策长度已翻倍,可读性下降——尤其在《通用数据保护条例》(GDPR)与《加州消费者隐私法》(CCPA)实施后更为明显——同时描述的数据实践日益具有侵入性。研究结果表明,隐私政策通过掩盖用户权利与数据实践,未能有效服务用户,建议采用机器可读格式并推动监管改革,以提升透明度与用户控制力。

ABSTRACT

It is well-known that most users do not read privacy policies, but almost all users tick the box to agree with them. In this paper, we analyze the 25-year history of privacy policies using methods from transparency research, machine learning, and natural language processing. Specifically, we collect a large-scale longitudinal corpus of privacy policies from 1996 to 2021 and analyze the length and readability of privacy policies as well as their content in terms of the data practices they describe, the rights they grant to users, and the rights they reserve for their organizations. We pay particular attention to changes in response to recent privacy regulations such as the GDPR and CCPA. Our results show that policies are getting longer and harder to read, especially after new regulations take effect, and we find a range of concerning data practices. Our results allow us to speculate why privacy policies are rarely read and propose changes that would make privacy policies serve their readers instead of their writers.

研究动机与目标

  • 调查过去25年隐私政策长度、可读性与内容的长期趋势。
  • 评估GDPR等重大隐私法规对政策演变的影响。
  • 识别隐私政策中术语、数据实践及用户权利表述的演变。
  • 评估近期法规是否真正提升了用户隐私保护,还是仅导致政策臃肿。
  • 提出可操作的改革建议——包括技术、监管与测量层面——使隐私政策服务于用户而非组织。

提出的方法

  • 利用互联网档案馆的Wayback Machine,从1996年至2021年收集了50,000份独立隐私政策文本的纵向语料库。
  • 应用基于BERT的模型,将政策段落分类为内容类别(如数据收集、用户权利、第三方共享等)。
  • 使用GraphSeg对政策文本进行无监督分割,生成可用于分析的逻辑单元。
  • 采用可读性公式(如Flesch阅读流畅度)评估随时间推移的文本复杂度。
  • 利用OPP-115语料库训练NLP分类器,并针对时间与语言漂移进行调整。
  • 对主要监管节点(GDPR于2018年实施,CCPA于2020年实施)前后的政策内容进行对比分析。

实验结果

研究问题

  • RQ11996年至2021年期间,隐私政策的长度与可读性如何演变?
  • RQ2GDPR与CCPA对隐私政策的结构与内容产生了何种影响?
  • RQ3术语及关键隐私相关术语的使用随时间如何变化?
  • RQ4过去25年中,隐私政策涵盖的数据实践与用户权利如何演变?
  • RQ5隐私政策在多大程度上体现了真正的用户控制,还是仅满足监管的合规性检查?

主要发现

  • 过去十年间,隐私政策的平均长度大约翻倍,自2000年以来则增长至四倍,GDPR与CCPA实施后增幅显著。
  • Flesch阅读流畅度得分从2001年的37降至2021年的31,表明政策如今的阅读难度已与学术法律文献相当。
  • 政策越来越多地描述对敏感数据(包括位置数据与隐式收集数据)的收集与共享,而用户选择权却微乎其微。
  • 缺乏关于政策变更的有效通知,且对安全与隐私措施的描述细节严重不足。
  • 第三方数据共享的描述日益模糊,未明确列出具体实体,导致透明度降低。
  • 尽管面临监管压力,隐私政策仍变得更加晦涩且用户不友好,表明其更倾向于服务于组织利益,而非用户理解。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。