Deficiencies in the Disclosures of Privacy Policies and in User Choice

49 Pages Posted: 28 Jul 2021 Last revised: 1 Feb 2022

See all articles by Scott Jordan

Scott Jordan

University of California, Irvine - Donald Bren School of Information and Computer Sciences

Siddharth Narasimhan

University of California, Irvine - Department of Computer Science

Jina Hong

University of California, Irvine - Donald Bren School of Information and Computer Sciences

Date Written: July 27, 2021

Abstract

Development of a comprehensive legal privacy framework in the United States should be based on identification of the common deficiencies of privacy policies. We attempt to delineate deficiencies by critically analyzing the privacy policies of mobile apps, application suites, social networks, Internet Service Providers, and Internet-of-Things devices. Whereas many studies have examined readability of privacy policies, few have specifically identified the information that should be provided in privacy policies but is not.

Privacy legislation invariably starts a definition of personally identifiable information. We find that privacy policies’ definitions of personally identifiable information are far too restrictive, excluding information that does not itself identify a person but which can be used to reasonably identify a person, and excluding information paired with a device identifier which can be reasonably linked to a person. Legislation should define personally identifiable information to include such information, and should differentiate between information paired with a name versus information paired with a device identifier.

Privacy legislation often excludes anonymous and de-identified information from notice and choice requirements. We find that privacy policies’ descriptions of anonymous and de-identified information are far too broad, including information paired with advertising identifiers. Computer science has repeatedly demonstrated that such information is reasonably linkable. Legislation should define these categories of information to align with technological abilities. Legislation should also not exempt de-identified information from notice requirements, to increase transparency.

Privacy legislation relies heavily on notice requirements. We find that, because privacy policies’ disclosures of the uses of personal information are disconnected from their disclosures about the types of personal information collected, we are often unable to determine which types of information are used for which purposes. Often, we cannot determine whether location or web browsing history is used solely for functional purposes or also for advertising. Legislation should require the disclosure of the purposes for each type of personal information collected.

We also find that, because privacy policies disclosures of sharing of personal information are disconnected from their disclosures about the types of personal information collected, we are often unable to determine which types of information are shared. Legislation should require the disclosure of the types of personal information shared.

Finally, privacy legislation relies heavily on user choice. We find that free services often require the collection and sharing of personal information. As a result, users often have no choices. We find that whereas some paid services afford users a wide variety of choices, paid services in less competitive sectors often afford users few choices over use and sharing of personal information for purposes unrelated to the service. As a result, users are often unable to dictate which types of information they wish to allow to be shared, and which types they wish to allow to be used for advertising. Legislation should differentiate between take-it-or-leave it, opt-out, and opt-in approaches based on the type of use and on whether the information is shared. Congress should consider whether user choices should be affected by the presence of market power.

Suggested Citation

Jordan, Scott and Narasimhan, Siddharth and Hong, Jina, Deficiencies in the Disclosures of Privacy Policies and in User Choice (July 27, 2021). Loyola Consumer Law Review, Forthcoming, TPRC49: The 49th Research Conference on Communication, Information and Internet Policy, Available at SSRN: https://ssrn.com/abstract=3894548 or http://dx.doi.org/10.2139/ssrn.3894548

Scott Jordan (Contact Author)

University of California, Irvine - Donald Bren School of Information and Computer Sciences ( email )

Bren Hall
Irvine, CA 92697-3440
United States
(949) 824-2177 (Phone)

Siddharth Narasimhan

University of California, Irvine - Department of Computer Science ( email )

Bren Hall
Irvine, CA 92697-3440
United States

Jina Hong

University of California, Irvine - Donald Bren School of Information and Computer Sciences

Bren Hall
Irvine, CA 92697-3440
United States

Do you have a job opening that you would like to promote on SSRN?

Paper statistics

Downloads
68
Abstract Views
353
Rank
531,531
PlumX Metrics