Automating identification of potentially problematic privacy policies

Research output: Contribution to conferenceProceeding

Abstract

Almost every website, mobile application or cloud service requires users to agree to a privacy policy, or similar terms of service, detailing how the developer or service provider will handle user data, and the purposes for which it will be used. Many past works have criticised these documents on account of their length, excessively complex wording, or the simple fact that users typically do not read or understand them, and that potentially invasive or wide-reaching terms are included in these policies. In this paper, we present our automated approach and tool to gather and analyse these policies, and highlight some interesting considerations for these documents, specifically those surrounding past legal rulings over the enforceability of some specific and widely-used contract terms --- the ability for terms to be changed without directly notifying users (and presumed continued use indicates acceptance), and the protections in place in the event of a sale or acquisition of a company. We highlight the concerns these pose to user privacy and choice, and the extent to which these terms are found in policies and documents from many popular websites. We use our tool to highlight the extent to which these terms are found, and the extent of this potential problem, and explore potential solutions to the challenge of regulating user privacy via such contracts in an era where mobile devices contain significant quantities of highly sensitive personal data, which is highly desirable to service operators, as a core valuation asset of their company.

Conference

ConferenceWireless World Research Forum Meeting 35 (WWRF35)
CountryDenmark
CityCopenhagen
Period14/10/1516/10/15

Fingerprint

Websites
Data privacy
Mobile devices
Industry
Sales

Keywords

  • privacy
  • privacy policies
  • personal data

Cite this

Paul, G., & Irvine, J. (2015). Automating identification of potentially problematic privacy policies. Wireless World Research Forum Meeting 35 (WWRF35), Copenhagen, Denmark.
Paul, Greig ; Irvine, James. / Automating identification of potentially problematic privacy policies. Wireless World Research Forum Meeting 35 (WWRF35), Copenhagen, Denmark.5 p.
@conference{6e034095f05a49819742464d54855c54,
title = "Automating identification of potentially problematic privacy policies",
abstract = "Almost every website, mobile application or cloud service requires users to agree to a privacy policy, or similar terms of service, detailing how the developer or service provider will handle user data, and the purposes for which it will be used. Many past works have criticised these documents on account of their length, excessively complex wording, or the simple fact that users typically do not read or understand them, and that potentially invasive or wide-reaching terms are included in these policies. In this paper, we present our automated approach and tool to gather and analyse these policies, and highlight some interesting considerations for these documents, specifically those surrounding past legal rulings over the enforceability of some specific and widely-used contract terms --- the ability for terms to be changed without directly notifying users (and presumed continued use indicates acceptance), and the protections in place in the event of a sale or acquisition of a company. We highlight the concerns these pose to user privacy and choice, and the extent to which these terms are found in policies and documents from many popular websites. We use our tool to highlight the extent to which these terms are found, and the extent of this potential problem, and explore potential solutions to the challenge of regulating user privacy via such contracts in an era where mobile devices contain significant quantities of highly sensitive personal data, which is highly desirable to service operators, as a core valuation asset of their company.",
keywords = "privacy, privacy policies, personal data",
author = "Greig Paul and James Irvine",
year = "2015",
month = "10",
language = "English",
note = "Wireless World Research Forum Meeting 35 (WWRF35) ; Conference date: 14-10-2015 Through 16-10-2015",

}

Paul, G & Irvine, J 2015, 'Automating identification of potentially problematic privacy policies' Wireless World Research Forum Meeting 35 (WWRF35), Copenhagen, Denmark, 14/10/15 - 16/10/15, .

Automating identification of potentially problematic privacy policies. / Paul, Greig; Irvine, James.

2015. Wireless World Research Forum Meeting 35 (WWRF35), Copenhagen, Denmark.

Research output: Contribution to conferenceProceeding

TY - CONF

T1 - Automating identification of potentially problematic privacy policies

AU - Paul, Greig

AU - Irvine, James

PY - 2015/10

Y1 - 2015/10

N2 - Almost every website, mobile application or cloud service requires users to agree to a privacy policy, or similar terms of service, detailing how the developer or service provider will handle user data, and the purposes for which it will be used. Many past works have criticised these documents on account of their length, excessively complex wording, or the simple fact that users typically do not read or understand them, and that potentially invasive or wide-reaching terms are included in these policies. In this paper, we present our automated approach and tool to gather and analyse these policies, and highlight some interesting considerations for these documents, specifically those surrounding past legal rulings over the enforceability of some specific and widely-used contract terms --- the ability for terms to be changed without directly notifying users (and presumed continued use indicates acceptance), and the protections in place in the event of a sale or acquisition of a company. We highlight the concerns these pose to user privacy and choice, and the extent to which these terms are found in policies and documents from many popular websites. We use our tool to highlight the extent to which these terms are found, and the extent of this potential problem, and explore potential solutions to the challenge of regulating user privacy via such contracts in an era where mobile devices contain significant quantities of highly sensitive personal data, which is highly desirable to service operators, as a core valuation asset of their company.

AB - Almost every website, mobile application or cloud service requires users to agree to a privacy policy, or similar terms of service, detailing how the developer or service provider will handle user data, and the purposes for which it will be used. Many past works have criticised these documents on account of their length, excessively complex wording, or the simple fact that users typically do not read or understand them, and that potentially invasive or wide-reaching terms are included in these policies. In this paper, we present our automated approach and tool to gather and analyse these policies, and highlight some interesting considerations for these documents, specifically those surrounding past legal rulings over the enforceability of some specific and widely-used contract terms --- the ability for terms to be changed without directly notifying users (and presumed continued use indicates acceptance), and the protections in place in the event of a sale or acquisition of a company. We highlight the concerns these pose to user privacy and choice, and the extent to which these terms are found in policies and documents from many popular websites. We use our tool to highlight the extent to which these terms are found, and the extent of this potential problem, and explore potential solutions to the challenge of regulating user privacy via such contracts in an era where mobile devices contain significant quantities of highly sensitive personal data, which is highly desirable to service operators, as a core valuation asset of their company.

KW - privacy

KW - privacy policies

KW - personal data

UR - http://www.wwrf35.ch

M3 - Proceeding

ER -

Paul G, Irvine J. Automating identification of potentially problematic privacy policies. 2015. Wireless World Research Forum Meeting 35 (WWRF35), Copenhagen, Denmark.