Skip to main content
QUICK REVIEW

[论文解读] The Challenges and Impact of Privacy Policy Comprehension

Jana Korunovska, Bernadette Kamleitner|arXiv (Cornell University)|May 18, 2020
Privacy, Security, and Data Protection被引用 9
一句话总结

本研究调查了为何用户即使在隐私政策设计简化后仍无法理解其内容,揭示了即使政策透明且简洁,仍普遍存在误解。在一项针对214名Facebook用户的实验中,有50%的用户误解了一项简单的隐私政策;而接触过二次数据使用威胁的用户,反而将政策回忆为更具隐私友好性的,导致其数据共享行为增加——这削弱了‘清晰性即能确保知情同意’的假设。

ABSTRACT

The new information and communication technology providers collect increasing amounts of personal data, a lot of which is user generated. Unless use policies are privacy-friendly, this leaves users vulnerable to privacy risks such as exposure through public data visibility or intrusive commercialisation of their data through secondary data use. Due to complex privacy policies, many users of online services unwillingly agree to privacy-intruding practices. To give users more control over their privacy, scholars and regulators have pushed for short, simple, and prominent privacy policies. The premise has been that users will see and comprehend such policies, and then rationally adjust their disclosure behaviour. In this paper, on a use case of social network service site, we show that this premise does not hold. We invited 214 regular Facebook users to join a new fictitious social network. We experimentally manipulated the privacy-friendliness of an unavoidable and simple privacy policy. Half of our participants miscomprehended even this transparent privacy policy. When privacy threats of secondary data use were present, users remembered the policies as more privacy-friendly than they actually were and unwittingly uploaded more data. To mitigate such behavioural pitfalls we present design recommendations to improve the quality of informed consent.

研究动机与目标

  • 检验简化、透明的隐私政策是否能带来用户准确的理解与知情同意。
  • 探究用户在接触二次数据使用威胁时,对隐私风险的感知情况。
  • 识别因误解隐私政策而引发的数据披露行为陷阱。
  • 提出改进在线服务中知情同意质量的设计建议。

提出的方法

  • 对214名定期使用Facebook的用户开展实验研究,招募其加入一个虚构的社交网络。
  • 通过操纵不可避免的简化隐私政策的隐私友好程度,创建两种条件:隐私友好型与隐私侵入型。
  • 通过实验后回忆与不同威胁情境下的披露行为,测量用户的理解程度。
  • 通过受控暴露于二次数据使用威胁,评估其对感知隐私友好性与数据共享行为的影响。
  • 收集关于政策回忆、感知隐私友好性以及实际数据上传行为的数据。
  • 分析结果,识别误解模式与隐私政策清晰度下行为不一致的特征。

实验结果

研究问题

  • RQ1用户在在线服务中对简化、透明的隐私政策的理解准确程度如何?
  • RQ2二次数据使用威胁在多大程度上影响用户对隐私政策友好性的感知?
  • RQ3即使政策本身清晰,感知到的隐私友好性是否会影响实际的数据披露行为?
  • RQ4当隐私政策被简化但被误解时,用户同意行为中会浮现哪些行为不一致?

主要发现

  • 一半参与者(50%)误解了一项透明且简洁的隐私政策,表明清晰度本身并不能确保理解。
  • 接触过二次数据使用威胁的用户,将隐私政策回忆为比实际更具隐私友好性的,显示出显著的误解偏差。
  • 感知政策更隐私友好的参与者,即使政策本身并不友好,也上传了显著更多的个人数据。
  • 本研究表明,由于用户持续误解与行为不一致,简化隐私政策无法支持知情同意。
  • 即使有显著且简短的政策,用户也不会理性调整其数据披露行为,从而削弱了隐私优先设计方法的基本前提。
  • 研究结果揭示了政策设计初衷与用户实际理解之间存在关键差距,亟需改进同意机制。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。