IAPP-GDPR Web Banners-300x250-FINAL
What Misconceptions Do Consumers Have About Privacy?

Control of personal information in the digital space, and particularly on mobile devices, presents a unique design challenge. Most people aren’t aware that their personal data is being collected and shared. Many users don’t take the time to validate their expectations and most never read privacy policies, only becoming aware of such concerns when something happens that doesn’t meet their expectations—such as seeing their friend’s picture in a Facebook ad or seeing banner ads that match their most recent purchase.

When people do become aware and their expectations are violated, trust in the brand is eroded. We can leverage existing technology to create new experiences around personal data collection that are both transparent and provide control. But before we can begin to think about design solutions, we need to understand consumers’ current experience and expectations of how their personal information is handled and safeguarded. And our research has shown that the experience is currently riddled with misconceptions.

Create with Context

Through our research with consumers in the U.S., Mexico and Canada, we found that consumer privacy expectations often do not map to reality. In the online interaction between consumers and companies, consumers do expect that companies access their personal data in order to complete transactions—and in that case, their expectations match reality. However, user expectations and reality diverge when it comes to companies’ storage and use of consumers’ personal data. A nearly total mismatch occurs when it comes to sharing people’s personal data: Companies do far more of it than most consumers realize.

This lack of awareness leaves consumers vulnerable. If they don’t realize that their data is being accessed and shared, they are unlikely to try to look for controls to set their preferences. While people understand that they can control what personal information other consumers see, they have little awareness of their ability to control how companies use, store and share their data.

Create with Context

What consumers do expect is that information stays in silos. Aware of all or some of the possible online data collectors—such as local service, social network, photo or shopping sites—users think that their data remains only with those sites. They don’t expect that their personal information will be transferred between them. Most consumers are also not aware of ad networks that may gather data across all sites they visit.

Create with Context

Consumers believe that companies only have access to limited personal information. In some ways, users feel that this is a form of protection, since the “real” me is made up of many components. Consumers only give each online site data about themselves that is relevant to that transaction or service and assume that sites don’t know the “whole” me.

Create with Context

People also expect they will have anonymity on sites until they provide authentication. For example, consumers believe that they are anonymous when shopping on the Internet until they choose to give their personal information. They believe that their provider or website only knows their location when they “Check In.” And while people expect to provide a password when accessing mail via a browser, they do not expect to need to enter a password when using their mail app.

Users operate under these false privacy expectations every day. False user expectations are often challenged in their own time—for many users, surprising information eventually surfaces naturally in forms we previously mentioned, like a friend’s picture in a Facebook ad or banner ads that match their most recent purchase. This new information changes how the user feels about the company, about themselves and about their role in keeping their information private.

In my next post, I will explore what happens when users DO realize their privacy expectations have been violated. How do consumers react to this new information, and what does that mean for businesses trying to gain their trust?

Written By

Ilana Westerman


If you want to comment on this post, you need to login.
  • Cindy Compert Jun 11, 2013

    Ilana, very interesting article. Did you have more details on your research methodology? Any specific statistics you can share?

  • Ilana Westerman Jun 19, 2013

    Cindy, our Trust:It™ Research Program has been running from 2007-2013 and we have conducted a number of different types of research including: 1. Qualitative methodologies -- Ethnography, usability studies, eyetracking, desirability studies, and longitudinal studies. 721 1:1 sessions 1 hour - 3 hours in duration; longitudinal studies 1 week - 3 months in duration. 2. Quantitative methodologies: Surveys and quantitative usability. 10344 respondents overall.


Board of Directors

See the esteemed group of leaders shaping the future of the IAPP.

Contact Us

Need someone to talk to? We’re here for you.

IAPP Staff

Looking for someone specific? Visit the staff directory.

Learn more about the IAPP»

Daily Dashboard

The day’s top stories from around the world

Privacy Perspectives

Where the real conversations in privacy happen

The Privacy Advisor

Original reporting and feature articles on the latest privacy developments

Privacy Tracker

Alerts and legal analysis of legislative trends

Privacy Tech

Exploring the technology of privacy

Canada Dashboard Digest

A roundup of the top Canadian privacy news

Europe Data Protection Digest

A roundup of the top European data protection news

Asia-Pacific Dashboard Digest

A roundup of the top privacy news from the Asia-Pacific region

IAPP Westin Research Center

Original works. Groundbreaking research. Emerging scholars.

Advertise in IAPP Publications

Find out how to get your message in front the people you want to reach. Download a media kit now.

Get more News »

Find a KnowledgeNet Chapter Near You

Network and talk privacy at IAPP KnowledgeNet meetings, taking place worldwide.

Women Leading Privacy

Events, volunteer opportunities and more designed to help you give and get career support and expand your network.

IAPP Job Board

Looking for a new challenge, or need to hire your next privacy pro? The IAPP Job Board is the answer.

Join the Privacy List

Have ideas? Need advice? Subscribe to the Privacy List. It’s crowdsourcing, with an exceptional crowd.

Find more ways to Connect »

Find a Privacy Training Class

Two-day privacy training classes are held around the world. See the complete schedule now.

Online Privacy Training

Build your knowledge. The privacy know-how you need is just a click away.

The Training Post—Can’t-Miss Training Updates

Subscribe now to get the latest alerts on training opportunities around the world.

New Web Conferences Added!

See our list of upcoming web conferences. Just log on, listen in and learn!

Train Your Staff

Get your team up to speed on privacy by bringing IAPP training to your organization.

Learn more »

CIPP Certification

The global standard for the go-to person for privacy laws, regulations and frameworks

CIPM Certification

The first and only privacy certification for professionals who manage day-to-day operations

CIPT Certification

The industry benchmark for IT professionals worldwide to validate their knowledge of privacy requirements

Certify Your Staff

Find out how you can bring the world’s only globally recognized privacy certification to a group in your organization.

Learn more about IAPP certification »

Get Close-up

Looking for tools and info on a hot topic? Our close-up pages organize it for you in one easy-to-find place.

Where's Your DPA?

Our interactive DPA locator helps you find data protection authorities and summary of law by country.

IAPP Westin Research Center

See the latest original research from the IAPP Westin fellows.

Looking for Certification Study Resources?

Find out what you need to prepare for your exams

More Resources »

GDPR Comprehensive: Registration Open

New! Intensive two-day GDPR training led by the sharpest minds in the field. It's a can't-miss event.

The Congress Is Cancelled

The IAPP Europe Data Protection Congress 2015 is cancelled. Click through to learn more.

Sponsor an Event

Increase visibility for your organization—check out sponsorship opportunities today.

Exhibit at an Event

Put your brand in front of the largest gatherings of privacy pros in the world. Learn more.

More Conferences »

Become a Member

Start taking advantage of the many IAPP member benefits today

Corporate Members

See our list of high-profile corporate members—and find out why you should become one, too

Renew Your Membership

Don’t miss out for a minute—continue accessing your benefits

Join the IAPP»