By Sam Pfeifle
Publications Director

How bad is the situation for privacy notices? The National Science Foundation just used part of its largest grant program, a Frontier award of well over $1 million, to fund a team of researchers looking to fix them.

And, to be clear, “We try to look at society’s biggest challenges and the things that really matter,” said Lisa-Joy Zgorski, a spokesperson for the National Science Foundation, “things that affect lives and jobs, and we tackle these issues with the requests for proposals.”

The project in question, “Towards Effective Web Privacy Notice and Choice: A Multi-Disciplinary Perspective,” is led by researchers at Carnegie Mellon University and includes teams at both Fordham and Stanford. They hope to use advances in machine-learning, crowd-sourcing and graphic design to take the often-boilerplate privacy polices found on virtually every website nowadays and make them much more digestible and useful for the average web surfer.

“Nobody really understands these privacy policies,” said Nina Amla, one of the program managers at the National Science Foundation’s Computer and Information Science and Engineering Directorate. “They’re pages long, and the few people who do read them don’t come away with much information about how to make decisions about visiting that website or not.”

Of course, Amla is not the first to make those observations. Attendees at the IAPP’s Navigate event were treated to a presentation by Carnegie Mellon’s Jason Hong that showed you’d need to devote some 25 days a year to reading privacy notices if you actually read the notice on every site you, as an average surfer, visit.

“Every time I teach privacy, I ask for a show of hands to see who has read a privacy policy,” said Norman Sadeh, the project’s lead investigator at Carnegie Mellon. He starts by asking who’s read a privacy notice in the last month. No hands go up. The last year? No hands go up. Ever? “Maybe we’ll get a few hands,” he laughed, “but it’s a very tiny minority in the room.”

“I think we all realize that very few people read these polices,” he said, “and even if you do read them, you can’t answer the most basic questions about them.”

While researchers like Lorrie Cranor, who’s on Sadeh’s team, have looked at asking websites to use something more akin to a nutritional label, “we’re seeing that website operators are not necessarily keen to do much more than what they’ve already been doing,” Sadeh said.

With some background in machine learning and natural language studies, Sadeh a while back started to wonder if those kinds of technologies might be applied to privacy notices that tend to share a lot of similar language and patterns, so as to automatically answer those questions about privacy notices that are most important to the consumers visiting the sites.

Essentially, he asked, “can we take these policies in their ugliness and extract something meaningful out of them?”

The end result, he said, might be a browser plugin that displays a very simple color, or a letter grade, when someone visits a website that’s been evaluated by the program. It’s unlikely, said Sadeh, that what he’s envisioning could be done in real-time, but the sweeps of the kind done by privacy commissioners, for example, could be made much more efficient.

To that end, he’s assembled a team from the three universities with backgrounds in areas like legal research, public policy and human-computer interaction, in addition to privacy.

Once some research is done on what the privacy questions are that consumers really care about the answers to, and how to best to gather an online crowd interested in being a source of information, the workflow might look something like this:

First, the text of the privacy notice is ingested by the software. It pulls out the portions of the policy it believes answers the five-to-seven questions most important to consumers and offers up what it believes are the answers. The crowd online confirms or corrects those answers, and then a score for the site is generated. That score is recorded and added to the database. Finally, when someone next visits that site with the plugin installed, the score is displayed and the consumer can make a decision on whether to simply proceed or dive deeper into what the answers are to those important questions.

“Maybe we can find answers that matter to users,” said Sadeh, “though the answers may or may not be doable depending on what the policies do say. Some of them do a great job of never answering a question that you care about, and sometimes that’s very revealing. If they don’t make a statement about a valid question, then that’s an issue, and I can probably get a crowd to help me with pointing that out.”

At the end of the project’s three-and-a-half years, the hope, said Sadeh, is that “I can do this on a massive scale and we can start automating the sweeps … We might be able to see how policies evolve, or check how new regulations are being addressed, maybe even inform regulators and get them to impose various sanctions.

“We all realize that in many different domains,” he continued, “there’s been a rush to the bottom in terms of privacy practices, and the idea of self-regulation and that people would start competing on privacy polices, well, that was wishful thinking and that remains wishful thinking. But, if one day you can distill all this information so that it’s much easier for a user to digest, then maybe you find yourself with that actually happening.

“That’s the ultimate goal, I would think.”

Read More By Sam Pfeifle:
Skepticism Surrounds NSA Review; Massive “Black” Budget Revealed
A Turbulent Time for Gathering Privacy Commissioners
PCLOB to U.S. Intelligence: Update Data-Gathering Guidelines Now
PRIVACY IN POPULAR CULTURE: Privacy Is “More Complicated Than We Realized”


If you want to comment on this post, you need to login.


Board of Directors

See the esteemed group of leaders shaping the future of the IAPP.

Contact Us

Need someone to talk to? We’re here for you.

IAPP Staff

Looking for someone specific? Visit the staff directory.

Learn more about the IAPP»

Daily Dashboard

The day’s top stories from around the world

Privacy Perspectives

Where the real conversations in privacy happen

The Privacy Advisor

Original reporting and feature articles on the latest privacy developments

Privacy Tracker

Alerts and legal analysis of legislative trends

Privacy Tech

Exploring the technology of privacy

Canada Dashboard Digest

A roundup of the top Canadian privacy news

Europe Data Protection Digest

A roundup of the top European data protection news

Asia-Pacific Dashboard Digest

A roundup of the top privacy news from the Asia-Pacific region

Latin America Dashboard Digest

A roundup of the top privacy news from Latin America

IAPP Westin Research Center

Original works. Groundbreaking research. Emerging scholars.

Get more News »

IAPP Communities

Meet locally with privacy pros, dive deep into specialized topics or connect over common interests. Find your Community in KnowledgeNet Chapters, Sections and Affinity Groups.

IAPP Job Board

Looking for a new challenge, or need to hire your next privacy pro? The IAPP Job Board is the answer.

Join the Privacy List

Have ideas? Need advice? Subscribe to the Privacy List. It’s crowdsourcing, with an exceptional crowd.

Find a KnowledgeNet Chapter Near You

Talk privacy and network with local members at IAPP KnowledgeNet Chapter meetings, taking place worldwide.

Find more ways to Connect »

Find a Privacy Training Class

Two-day privacy training classes are held around the world. See the complete schedule now.

The Privacy Core™ Library Has Evolved

Privacy Core™ e-learning essentials just expanded to include seven new units for marketers. Keep your data safe and your staff in the know!

Online Privacy Training

Build your knowledge. The privacy know-how you need is just a click away.

Upcoming Web Conferences

See our list of upcoming web conferences. Just log on, listen in and learn!

Train Your Team

Get your team up to speed on privacy by bringing IAPP training to your organization.

Let’s Get You DPO Ready

There’s no better time to train than right now! We have all the resources you need to meet the challenges of the GDPR.

Learn more »

CIPP Certification

The global standard for the go-to person for privacy laws, regulations and frameworks

CIPM Certification

The first and only privacy certification for professionals who manage day-to-day operations

CIPT Certification

The industry benchmark for IT professionals worldwide to validate their knowledge of privacy requirements

FIP Designation

Recognizing the advanced knowledge and issue-spotting skills a privacy pro must attain in today’s complex world of data privacy.

Certify Your Staff

Find out how you can bring the world’s only globally recognized privacy certification to a group in your organization.


The IAPP’S CIPP/E and CIPM are the ANSI/ISO-accredited, industry-recognized combination for DPO readiness. Learn more today.

Learn more about IAPP certification »

Are You Ready for the GDPR?

Check out the IAPP's EU Data Protection Reform page for all the tools and resources you need.

IAPP-OneTrust PIA Platform

New U.S. Government Agency privacy impact assessments - free to IAPP members!

IAPP Communities

Meet locally with privacy pros, dive deep into specialized topics or connect over common interests. Find your Community in KnowledgeNet Chapters, Sections and Affinity Groups.

Privacy Vendor List

Find a privacy vendor to meet your needs with our filterable list of global service providers.

More Resources »

Europe Data Protection Intensive 2017

The Intensive is sold out! But cancellations do happen—so hurry and get on the wait list in case more seats become available.

Global Privacy Summit 2017

The world’s premier privacy conference returns with the sharpest minds, unparalleled programs and preeminent networking opportunities.

Canada Privacy Symposium 2017

The Symposium returns to Toronto this spring and registration has opened! Take advantage of Early Bird rates and join your fellow privacy pros for another stellar program.

The Privacy Bar Section Forum 2017

The Privacy Bar Section Forum is sold out! But you can still add your name to the wait list, and we'll keep in touch about your status. Good luck!

Asia Privacy Forum 2017

Call for Speakers open! Join the Forum in Singapore for exclusive networking and intensive education on data protection trends and challenges in the Asia Pacific region.

Privacy. Security. Risk. 2017

Call for Speakers open! This year, we're bringing P.S.R. to San Diego. Submit today and be a part of something big! Submission deadline: February 26.

Europe Data Protection Congress 2017

Call for Speakers open! The Congress is your source for European policy debate, multi-level strategic thinking and thought-provoking discussion. Submit a proposal by March 19.

Sponsor an Event

Increase visibility for your organization—check out sponsorship opportunities today.

More Conferences »

Become a Member

Start taking advantage of the many IAPP member benefits today

Corporate Members

See our list of high-profile corporate members—and find out why you should become one, too

Renew Your Membership

Don’t miss out for a minute—continue accessing your benefits

Join the IAPP»