The Privacy Policy Landscape After the GDPR

Author:

Linden Thomas1,Khandelwal Rishabh1,Harkous Hamza2,Fawaz Kassem1

Affiliation:

1. University of Wisconsin

2. École Polytechnique Fédérale de Lausanne ,

Abstract

Abstract The EU General Data Protection Regulation (GDPR) is one of the most demanding and comprehensive privacy regulations of all time. A year after it went into effect, we study its impact on the landscape of privacy policies online. We conduct the first longitudinal, in-depth, and at-scale assessment of privacy policies before and after the GDPR. We gauge the complete consumption cycle of these policies, from the first user impressions until the compliance assessment. We create a diverse corpus of two sets of 6,278 unique English-language privacy policies from inside and outside the EU, covering their pre-GDPR and the post-GDPR versions. The results of our tests and analyses suggest that the GDPR has been a catalyst for a major overhaul of the privacy policies inside and outside the EU. This overhaul of the policies, manifesting in extensive textual changes, especially for the EU-based websites, comes at mixed benefits to the users. While the privacy policies have become considerably longer, our user study with 470 participants on Amazon MTurk indicates a significant improvement in the visual representation of privacy policies from the users’ perspective for the EU websites. We further develop a new workflow for the automated assessment of requirements in privacy policies. Using this workflow, we show that privacy policies cover more data practices and are more consistent with seven compliance requirements post the GDPR. We also assess how transparent the organizations are with their privacy practices by performing specificity analysis. In this analysis, we find evidence for positive changes triggered by the GDPR, with the specificity level improving on average. Still, we find the landscape of privacy policies to be in a transitional phase; many policies still do not meet several key GDPR requirements or their improved coverage comes with reduced specificity.

Publisher

Walter de Gruyter GmbH

Subject

General Medicine

Reference36 articles.

1. [1] W. F. Adkinson, J. A. Eisenach, and T. M. Lenard, “Privacy online: A report on the information practices and policies of commercial web sites,” Progress and Freedom Foundation, 2002.

2. [2] E. AI. [Online]. Available: https://spacy.io/

3. [3] A. I. Anton, J. B. Earp, Q. He, W. Stufflebeam, D. Bolchini, and C. Jensen, “Financial privacy policies and the need for standardization,” IEEE Security & privacy, vol. 2, no. 2, pp. 36–45, 2004.

4. [4] A. I. Antón, J. B. Earp, and A. Reese, “Analyzing website privacy requirements using a privacy goal taxonomy,” in Requirements Engineering, 2002. Proceedings. IEEE Joint International Conference on. IEEE, 2002, pp. 23–31.

5. [5] A. I. Anton, J. B. Earp, M. W. Vail, N. Jain, C. M. Gheen, and J. M. Frink, “Hipaa’s effect on web site privacy policies,” IEEE Security & Privacy, vol. 5, no. 1, pp. 45–52, 2007.

Cited by 94 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. Blockchain Applications for Internet of Things — A Survey;Internet of Things;2024-10

2. Key drivers of cybersecurity audit effectiveness: A neo‐institutional perspective;International Journal of Auditing;2024-07-22

3. SoK: Technical Implementation and Human Impact of Internet Privacy Regulations;2024 IEEE Symposium on Security and Privacy (SP);2024-05-19

4. Understanding the Privacy Practices of Political Campaigns: A Perspective from the 2020 US Election Websites;2024 IEEE Symposium on Security and Privacy (SP);2024-05-19

5. Automating Website Registration for Studying GDPR Compliance;Proceedings of the ACM Web Conference 2024;2024-05-13

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3