A BERT-based Empirical Study of Privacy Policies' Compliance with GDPR

被引:4
作者
Zhang, Lu [1 ]
Moukafih, Nabil [1 ]
Alamri, Hamad [1 ]
Epiphaniou, Gregory [1 ]
Maple, Carsten [1 ]
机构
[1] Univ Warwick, Warwick Mfg Grp, Coventry, W Midlands, England
来源
2023 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY, CNS | 2023年
关键词
Privacy policies; GDPR; compliance checking; readability;
D O I
10.1109/CNS59707.2023.10288797
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Since its implementation in May 2018, the General Data Protection Regulation (GDPR) has prompted businesses to revisit and revise their data handling practices to ensure compliance. The privacy policy, which serves as the primary means of informing users about their privacy rights and the data practices of companies, has been significantly updated by numerous businesses post-GDPR implementation. However, many privacy policies remain packed with technical jargon, lengthy explanations, and vague descriptions of data practices and user rights. This makes it a challenging task for users and regulatory authorities to manually verify the GDPR compliance of these privacy policies. In this study, we aim to address the challenge of compliance analysis between GDPR (Article 13) and privacy policies for 5G networks. We manually collected privacy policies from almost 70 different 5G MNOs, and we utilized an automated BERT-based model for classification. We show that an encouraging 51% of companies demonstrate a strong adherence to GDPR. In addition, we present the first study that provides current empirical evidence on the readability of privacy policies for 5G network. we adopted readability analysis toolset that incorporates various established readability metrics. The findings empirically show that the readability of the majority of current privacy policies remains a significant challenge. Hence, 5G providers need to invest considerable effort into revising these documents to enhance both their utility and the overall user experience.
引用
收藏
页数:6
相关论文
共 50 条
  • [21] Methods and Tools for GDPR Compliance through Privacy and Data Protection Engineering
    Martin, Yod-Samuel
    Kung, Antonio
    2018 3RD IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS (EUROS&PW 2018), 2018, : 108 - 111
  • [22] DEFeND DSM: A Data Scope Management Service for Model-Based Privacy by Design GDPR Compliance
    Piras, Luca
    Al-Obeidallah, Mohammed Ghazi
    Pavlidis, Michalis
    Mouratidis, Haralambos
    Tsohou, Aggeliki
    Magkos, Emmanouil
    Praitano, Andrea
    Iodice, Annarita
    Gallego-Nicasio Crespo, Beatriz
    TRUST, PRIVACY AND SECURITY IN DIGITAL BUSINESS, TRUSTBUS 2020, 2020, 12395 : 186 - 201
  • [23] Understanding privacy policies A study in empirical analysis of language usage
    Laemmel, Ralf
    Pek, Ekaterina
    EMPIRICAL SOFTWARE ENGINEERING, 2013, 18 (02) : 310 - 374
  • [24] A systematic study on the impact of GDPR compliance on Organizations
    Machado, Pedro
    Vilela, Jessyka
    Peixoto, Mariana
    Silva, Carla
    PROCEEDINGS OF THE 19TH BRAZILIAN SYMPOSIUM ON INFORMATION SYSTEMS, 2023, : 435 - 442
  • [25] Communicating Compliance: Developing a GDPR Privacy Label Emergent Research Forum (ERF)
    Fox, Grace
    Tonge, Colin
    Lynn, Theo
    Mooney, John
    AMCIS 2018 PROCEEDINGS, 2018,
  • [26] Who Leaks My Privacy: Towards Automatic and Association Detection with GDPR Compliance
    Jia, Qiwei
    Zhou, Lu
    Li, Huaxin
    Yang, Ruoxu
    Du, Suguo
    Zhu, Haojin
    WIRELESS ALGORITHMS, SYSTEMS, AND APPLICATIONS, WASA 2019, 2019, 11604 : 137 - 148
  • [27] An AI-assisted Approach for Checking the Completeness of Privacy Policies Against GDPR
    Torre, Damiano
    Abualhaija, Sallam
    Sabetzadeh, Mehrdad
    Briand, Lionel
    Baetens, Katrien
    Goes, Peter
    Forastier, Sylvie
    2020 28TH IEEE INTERNATIONAL REQUIREMENTS ENGINEERING CONFERENCE (RE'20), 2020, : 136 - 146
  • [28] A Framework for Privacy and Security Requirements Analysis and Conflict Resolution for Supporting GDPR Compliance Through Privacy-by-Design
    Alkubaisy, Duaa
    Piras, Luca
    Al-Obeidallah, Mohammed Ghazi
    Cox, Karl
    Mouratidis, Haralambos
    EVALUATION OF NOVEL APPROACHES TO SOFTWARE ENGINEERING (ENASE 2021), 2022, 1556 : 67 - 87
  • [29] Design of a Compliance Index for Privacy Policies: A Study of Mobile Wallet and Remittance Services
    Akanfe, Oluwafemi
    Valecha, Rohit
    Rao, H. Raghav
    IEEE TRANSACTIONS ON ENGINEERING MANAGEMENT, 2023, 70 (03) : 864 - 876
  • [30] Privacy, security, legal and technology acceptance elicited and consolidated requirements for a GDPR compliance platform
    Tsohou, Aggeliki
    Magkos, Emmanouil
    Mouratidis, Haralambos
    Chrysoloras, George
    Piras, Luca
    Pavlidis, Michalis
    Debussche, Julien
    Rotoloni, Marco
    Crespo, Beatriz Gallego-Nicasio
    INFORMATION AND COMPUTER SECURITY, 2020, 28 (04) : 531 - 553