A BERT-based Empirical Study of Privacy Policies' Compliance with GDPR

被引:4
作者
Zhang, Lu [1 ]
Moukafih, Nabil [1 ]
Alamri, Hamad [1 ]
Epiphaniou, Gregory [1 ]
Maple, Carsten [1 ]
机构
[1] Univ Warwick, Warwick Mfg Grp, Coventry, W Midlands, England
来源
2023 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY, CNS | 2023年
关键词
Privacy policies; GDPR; compliance checking; readability;
D O I
10.1109/CNS59707.2023.10288797
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Since its implementation in May 2018, the General Data Protection Regulation (GDPR) has prompted businesses to revisit and revise their data handling practices to ensure compliance. The privacy policy, which serves as the primary means of informing users about their privacy rights and the data practices of companies, has been significantly updated by numerous businesses post-GDPR implementation. However, many privacy policies remain packed with technical jargon, lengthy explanations, and vague descriptions of data practices and user rights. This makes it a challenging task for users and regulatory authorities to manually verify the GDPR compliance of these privacy policies. In this study, we aim to address the challenge of compliance analysis between GDPR (Article 13) and privacy policies for 5G networks. We manually collected privacy policies from almost 70 different 5G MNOs, and we utilized an automated BERT-based model for classification. We show that an encouraging 51% of companies demonstrate a strong adherence to GDPR. In addition, we present the first study that provides current empirical evidence on the readability of privacy policies for 5G network. we adopted readability analysis toolset that incorporates various established readability metrics. The findings empirically show that the readability of the majority of current privacy policies remains a significant challenge. Hence, 5G providers need to invest considerable effort into revising these documents to enhance both their utility and the overall user experience.
引用
收藏
页数:6
相关论文
共 50 条
[41]   A Data Sharing Scheme for GDPR-Compliance Based on Consortium Blockchain [J].
Piao, Yangheran ;
Ye, Kai ;
Cui, Xiaohui .
FUTURE INTERNET, 2021, 13 (08)
[42]   GDPR Compliance in the Design of the INFORM e-Learning Platform: a Case Study [J].
Vanezi, Evangelia ;
Kouzapas, Dimitrios ;
Kapitsaki, Georgia M. ;
Costi, Theodora ;
Yeratziotis, Alexandros ;
Mettouris, Christos ;
Philippou, Anna ;
Papadopoulos, George A. .
2019 13TH INTERNATIONAL CONFERENCE ON RESEARCH CHALLENGES IN INFORMATION SCIENCE (RCIS), 2019, :257-+
[43]   Pattern-Based Incorporation of Privacy Preferences into Privacy Policies [J].
Mohammadi, Nazila Gol ;
Pampus, Julia ;
Heisel, Maritta .
PROCEEDINGS OF THE 24TH EUROPEAN CONFERENCE ON PATTERN LANGUAGES OF PROGRAMS (EUROPLOP 2019), 2019,
[44]   CIDaTa: an ontology-based framework for international data transfers and GDPR compliance [J].
Hasan M.M. ;
Compagnucci M.C. ;
Kousiouris G. ;
Anagnostopoulos D. .
International Journal of Metadata, Semantics and Ontologies, 2023, 16 (03) :195-209
[45]   GDPR Compliance in Cybersecurity Software: A Case Study of DPIA in Information Sharing Platform [J].
Horak, Martin ;
Stupka, Vaclav ;
Husak, Martin .
14TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES 2019), 2019,
[46]   Deontic Modality in the GDPR Based Finnish Privacy Notices in the Light of the Transparency Principle [J].
Rydzewska-Siemiatkowska, Joanna .
INTERNATIONAL JOURNAL FOR THE SEMIOTICS OF LAW-REVUE INTERNATIONALE DE SEMIOTIQUE JURIDIQUE, 2023, 36 (02) :1007-1031
[47]   Deontic Modality in the GDPR Based Finnish Privacy Notices in the Light of the Transparency Principle [J].
Joanna Rydzewska-Siemiątkowska .
International Journal for the Semiotics of Law - Revue internationale de Sémiotique juridique, 2023, 36 :1007-1031
[48]   Access Control Model Extensions to Support Data Privacy Protection based on GDPR [J].
Davari, Maryam ;
Bertino, Elisa .
2019 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2019, :4017-4024
[49]   A Model-Based Privacy Compliance Checker [J].
Pearson, Siani ;
Allison, Damien .
INTERNATIONAL JOURNAL OF E-BUSINESS RESEARCH, 2009, 5 (02) :63-83
[50]   Privacy icons as a component of effective transparency and controls under the GDPR: effective data protection by design based on art. 25 GDPR [J].
von Grafenstein, Max ;
Kiefaber, Isabel ;
Heumueller, Julie ;
Rupp, Valentin ;
Grassl, Paul ;
Kolless, Otto ;
Puzst, Zsofia .
COMPUTER LAW & SECURITY REVIEW, 2024, 52