A BERT-based Empirical Study of Privacy Policies' Compliance with GDPR

被引:4
|
作者
Zhang, Lu [1 ]
Moukafih, Nabil [1 ]
Alamri, Hamad [1 ]
Epiphaniou, Gregory [1 ]
Maple, Carsten [1 ]
机构
[1] Univ Warwick, Warwick Mfg Grp, Coventry, W Midlands, England
来源
2023 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY, CNS | 2023年
关键词
Privacy policies; GDPR; compliance checking; readability;
D O I
10.1109/CNS59707.2023.10288797
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Since its implementation in May 2018, the General Data Protection Regulation (GDPR) has prompted businesses to revisit and revise their data handling practices to ensure compliance. The privacy policy, which serves as the primary means of informing users about their privacy rights and the data practices of companies, has been significantly updated by numerous businesses post-GDPR implementation. However, many privacy policies remain packed with technical jargon, lengthy explanations, and vague descriptions of data practices and user rights. This makes it a challenging task for users and regulatory authorities to manually verify the GDPR compliance of these privacy policies. In this study, we aim to address the challenge of compliance analysis between GDPR (Article 13) and privacy policies for 5G networks. We manually collected privacy policies from almost 70 different 5G MNOs, and we utilized an automated BERT-based model for classification. We show that an encouraging 51% of companies demonstrate a strong adherence to GDPR. In addition, we present the first study that provides current empirical evidence on the readability of privacy policies for 5G network. we adopted readability analysis toolset that incorporates various established readability metrics. The findings empirically show that the readability of the majority of current privacy policies remains a significant challenge. Hence, 5G providers need to invest considerable effort into revising these documents to enhance both their utility and the overall user experience.
引用
收藏
页数:6
相关论文
共 50 条
  • [1] Is Your Policy Compliant? A Deep Learning-based Empirical Study of Privacy Policies' Compliance with GDPR
    Al Rahat, Tamjid
    Long, Minjun
    Tian, Yuan
    PROCEEDINGS OF THE 21ST WORKSHOP ON PRIVACY IN THE ELECTRONIC SOCIETY, WPES 2022, 2022, : 89 - 102
  • [2] Machine Understandable Policies and GDPR Compliance Checking
    Bonatti, Piero A.
    Kirrane, Sabrina
    Petrova, Iliana M.
    Sauro, Luigi
    KUNSTLICHE INTELLIGENZ, 2020, 34 (03): : 303 - 315
  • [3] The death of privacy policies: How app stores shape GDPR compliance of apps
    Kraemer, Julia
    INTERNET POLICY REVIEW, 2024, 13 (02):
  • [4] Automatic Assessment of Privacy Policies under the GDPR
    Sanchez, David
    Viejo, Alexandre
    Batet, Montserrat
    APPLIED SCIENCES-BASEL, 2021, 11 (04): : 1 - 11
  • [5] Machine Understandable Policies and GDPR Compliance Checking
    Piero A. Bonatti
    Sabrina Kirrane
    Iliana M. Petrova
    Luigi Sauro
    KI - Künstliche Intelligenz, 2020, 34 : 303 - 315
  • [6] Content Analysis of Privacy Policies Before and After GDPR
    Bateni, Nastaran
    Kaur, Jasmin
    Dara, Rozita
    Song, Fei
    2022 19TH ANNUAL INTERNATIONAL CONFERENCE ON PRIVACY, SECURITY & TRUST (PST), 2022,
  • [7] CompLicy: Evaluating the GDPR Alignment of Privacy Policies - A Study on Web Platforms
    Vanezi, Evangelia
    Zampa, George
    Mettouris, Christos
    Yeratziotis, Alexandros
    Papadopoulos, George A.
    RESEARCH CHALLENGES IN INFORMATION SCIENCE (RCIS 2021), 2021, 415 : 152 - 168
  • [8] Towards Inclusive Privacy Consenting for GDPR Compliance in Visual Surveillance: A Survey Study
    Chattopadhayay, Ankur
    Rijal, Isha
    2023 IEEE 13TH ANNUAL COMPUTING AND COMMUNICATION WORKSHOP AND CONFERENCE, CCWC, 2023, : 1287 - 1293
  • [9] DEFeND Architecture: A Privacy by Design Platform for GDPR Compliance
    Piras, Luca
    Al-Obeidallah, Mohammed Ghazi
    Praitano, Andrea
    Tsohou, Aggeliki
    Mouratidis, Haralambos
    Gallego-Nicasio Crespo, Beatriz
    Bernard, Jean Baptiste
    Fiorani, Marco
    Magkos, Emmanouil
    Castillo Sanz, Andres
    Pavlidis, Michalis
    D'Addario, Roberto
    Zorzino, Giuseppe Giovanni
    TRUST, PRIVACY AND SECURITY IN DIGITAL BUSINESS, TRUSTBUS 2019, 2019, 11711 : 78 - 93
  • [10] Privacy Implication and Technical Requirements Toward GDPR Compliance
    Huang, Ching-Chun
    Yuan, Zih-shiuan
    PROCEEDINGS OF THE FUTURE TECHNOLOGIES CONFERENCE (FTC) 2019, VOL 2, 2020, 1070 : 353 - 367