Investigating Deceptive Design in GDPR's Legitimate Interest

要旨

Legitimate interest is one of the six grounds for processing data under the European Union's General Data Protection Regulation (GDPR). The flexibility and ambiguity of the term "legitimate interests" can be problematic; coupled with the lack of enforcement from legal authorities and different interpretations from the various data protection authorities, legitimate interests can be taken advantage of as a loophole to collect more user data. Drawing insights from multiple disciplines, we ran two studies to empirically investigate the deceptive designs being used when legitimate interests are applied in privacy notices, and how user perceptions line up with these practices. We identified six deceptive designs, and found that the ways legitimate interest is applied in practice does not match user expectations.

著者
Lin Kyi
Max Planck Institute for Security and Privacy, Bochum, Germany
Sushil Ammanaghatta Shivakumar
Max Planck Institute for Security and Privacy, Bochum, Germany
Cristiana Teixeira Santos
Utrecht University, Utrecht , Netherlands
Franziska Roesner
University of Washington, Seattle, Washington, United States
Frederike Zufall
Max Planck Institute for Research on Collective Goods, Bonn, Germany
Asia J.. Biega
Max Planck Institute for Security and Privacy, Bochum, Germany
論文URL

https://doi.org/10.1145/3544548.3580637

動画

会議: CHI 2023

The ACM CHI Conference on Human Factors in Computing Systems (https://chi2023.acm.org/)

セッション: Privacy Perceptions and Misconceptions

Hall D
6 件の発表
2023-04-27 18:00:00
2023-04-27 19:30:00