DPI16_Banner_300x250 WITH COPY


By Sam Pfeifle
Publications Director

How bad is the situation for privacy notices? The National Science Foundation just used part of its largest grant program, a Frontier award of well over $1 million, to fund a team of researchers looking to fix them.

And, to be clear, “We try to look at society’s biggest challenges and the things that really matter,” said Lisa-Joy Zgorski, a spokesperson for the National Science Foundation, “things that affect lives and jobs, and we tackle these issues with the requests for proposals.”

The project in question, “Towards Effective Web Privacy Notice and Choice: A Multi-Disciplinary Perspective,” is led by researchers at Carnegie Mellon University and includes teams at both Fordham and Stanford. They hope to use advances in machine-learning, crowd-sourcing and graphic design to take the often-boilerplate privacy polices found on virtually every website nowadays and make them much more digestible and useful for the average web surfer.

“Nobody really understands these privacy policies,” said Nina Amla, one of the program managers at the National Science Foundation’s Computer and Information Science and Engineering Directorate. “They’re pages long, and the few people who do read them don’t come away with much information about how to make decisions about visiting that website or not.”

Of course, Amla is not the first to make those observations. Attendees at the IAPP’s Navigate event were treated to a presentation by Carnegie Mellon’s Jason Hong that showed you’d need to devote some 25 days a year to reading privacy notices if you actually read the notice on every site you, as an average surfer, visit.

“Every time I teach privacy, I ask for a show of hands to see who has read a privacy policy,” said Norman Sadeh, the project’s lead investigator at Carnegie Mellon. He starts by asking who’s read a privacy notice in the last month. No hands go up. The last year? No hands go up. Ever? “Maybe we’ll get a few hands,” he laughed, “but it’s a very tiny minority in the room.”

“I think we all realize that very few people read these polices,” he said, “and even if you do read them, you can’t answer the most basic questions about them.”

While researchers like Lorrie Cranor, who’s on Sadeh’s team, have looked at asking websites to use something more akin to a nutritional label, “we’re seeing that website operators are not necessarily keen to do much more than what they’ve already been doing,” Sadeh said.

With some background in machine learning and natural language studies, Sadeh a while back started to wonder if those kinds of technologies might be applied to privacy notices that tend to share a lot of similar language and patterns, so as to automatically answer those questions about privacy notices that are most important to the consumers visiting the sites.

Essentially, he asked, “can we take these policies in their ugliness and extract something meaningful out of them?”

The end result, he said, might be a browser plugin that displays a very simple color, or a letter grade, when someone visits a website that’s been evaluated by the program. It’s unlikely, said Sadeh, that what he’s envisioning could be done in real-time, but the sweeps of the kind done by privacy commissioners, for example, could be made much more efficient.

To that end, he’s assembled a team from the three universities with backgrounds in areas like legal research, public policy and human-computer interaction, in addition to privacy.

Once some research is done on what the privacy questions are that consumers really care about the answers to, and how to best to gather an online crowd interested in being a source of information, the workflow might look something like this:

First, the text of the privacy notice is ingested by the software. It pulls out the portions of the policy it believes answers the five-to-seven questions most important to consumers and offers up what it believes are the answers. The crowd online confirms or corrects those answers, and then a score for the site is generated. That score is recorded and added to the database. Finally, when someone next visits that site with the plugin installed, the score is displayed and the consumer can make a decision on whether to simply proceed or dive deeper into what the answers are to those important questions.

“Maybe we can find answers that matter to users,” said Sadeh, “though the answers may or may not be doable depending on what the policies do say. Some of them do a great job of never answering a question that you care about, and sometimes that’s very revealing. If they don’t make a statement about a valid question, then that’s an issue, and I can probably get a crowd to help me with pointing that out.”

At the end of the project’s three-and-a-half years, the hope, said Sadeh, is that “I can do this on a massive scale and we can start automating the sweeps … We might be able to see how policies evolve, or check how new regulations are being addressed, maybe even inform regulators and get them to impose various sanctions.

“We all realize that in many different domains,” he continued, “there’s been a rush to the bottom in terms of privacy practices, and the idea of self-regulation and that people would start competing on privacy polices, well, that was wishful thinking and that remains wishful thinking. But, if one day you can distill all this information so that it’s much easier for a user to digest, then maybe you find yourself with that actually happening.

“That’s the ultimate goal, I would think.”

Read More By Sam Pfeifle:
Skepticism Surrounds NSA Review; Massive “Black” Budget Revealed
A Turbulent Time for Gathering Privacy Commissioners
PCLOB to U.S. Intelligence: Update Data-Gathering Guidelines Now
PRIVACY IN POPULAR CULTURE: Privacy Is “More Complicated Than We Realized”


If you want to comment on this post, you need to login.


Board of Directors

See the esteemed group of leaders shaping the future of the IAPP.

Contact Us

Need someone to talk to? We’re here for you.

IAPP Staff

Looking for someone specific? Visit the staff directory.

Learn more about the IAPP»

Daily Dashboard

The day’s top stories from around the world

Privacy Perspectives

Where the real conversations in privacy happen

The Privacy Advisor

Original reporting and feature articles on the latest privacy developments

Privacy Tracker

Alerts and legal analysis of legislative trends

Privacy Tech

Exploring the technology of privacy

Canada Dashboard Digest

A roundup of the top Canadian privacy news

Europe Data Protection Digest

A roundup of the top European data protection news

Asia-Pacific Dashboard Digest

A roundup of the top privacy news from the Asia-Pacific region

Latin America Dashboard Digest

A roundup of the top privacy news from Latin America

IAPP Westin Research Center

Original works. Groundbreaking research. Emerging scholars.

Get more News »

Find a KnowledgeNet Chapter Near You

Network and talk privacy at IAPP KnowledgeNet meetings, taking place worldwide.

Women Leading Privacy

Events, volunteer opportunities and more designed to help you give and get career support and expand your network.

IAPP Job Board

Looking for a new challenge, or need to hire your next privacy pro? The IAPP Job Board is the answer.

Join the Privacy List

Have ideas? Need advice? Subscribe to the Privacy List. It’s crowdsourcing, with an exceptional crowd.

Find more ways to Connect »

Find a Privacy Training Class

Two-day privacy training classes are held around the world. See the complete schedule now.

Online Privacy Training

Build your knowledge. The privacy know-how you need is just a click away.

The Training Post—Can’t-Miss Training Updates

Subscribe now to get the latest alerts on training opportunities around the world.

New Web Conferences Added!

See our list of upcoming web conferences. Just log on, listen in and learn!

Train Your Staff

Get your team up to speed on privacy by bringing IAPP training to your organization.

Learn more »

CIPP Certification

The global standard for the go-to person for privacy laws, regulations and frameworks

CIPM Certification

The first and only privacy certification for professionals who manage day-to-day operations

CIPT Certification

The industry benchmark for IT professionals worldwide to validate their knowledge of privacy requirements

Certify Your Staff

Find out how you can bring the world’s only globally recognized privacy certification to a group in your organization.

Learn more about IAPP certification »

Get Close-up

Looking for tools and info on a hot topic? Our close-up pages organize it for you in one easy-to-find place.

Where's Your DPA?

Our interactive DPA locator helps you find data protection authorities and summary of law by country.

IAPP Westin Research Center

See the latest original research from the IAPP Westin fellows.

Looking for Certification Study Resources?

Find out what you need to prepare for your exams

More Resources »

GDPR Comprehensive: Spots Going Fast

With the top minds in the field leading this exceptional program, it's no wonder it's filling quickly. Register now to secure your spot.

Be Part of Something Big: Join the Summit

Registration is open for the Global Privacy Summit 2016. Discounted early bird rates available for a short time, register today!

Data Protection Intensive Returns to London

Registration is now open for the IAPP Europe Data Protection Intensive in London. Check out the program!

P.S.R. Call for Speakers Open!

P.S.R. is THE privacy + cloud security event of the year, and you can take a leading role. Propose a session for this year's program.

Sponsor an Event

Increase visibility for your organization—check out sponsorship opportunities today.

Exhibit at an Event

Put your brand in front of the largest gatherings of privacy pros in the world. Learn more.

More Conferences »

Become a Member

Start taking advantage of the many IAPP member benefits today

Corporate Members

See our list of high-profile corporate members—and find out why you should become one, too

Renew Your Membership

Don’t miss out for a minute—continue accessing your benefits

Join the IAPP»