Privacy Policies over Time: Curation and Analysis of a Million-Document Dataset

被引:43
作者
Amos, Ryan [1 ]
Acar, Gunes [2 ]
Lucherini, Elena [1 ]
Kshirsagar, Mihir [1 ]
Narayanan, Arvind [1 ]
Mayer, Jonathan [1 ]
机构
[1] Princeton Univ, Princeton, NJ 08544 USA
[2] Katholieke Univ Leuven, Imec COSIC, Leuven, Belgium
来源
PROCEEDINGS OF THE WORLD WIDE WEB CONFERENCE 2021 (WWW 2021) | 2021年
关键词
privacy policy; web tracking; data protection; open dataset; SELF-REGULATION; ONLINE; IMPACT;
D O I
10.1145/3442381.3450048
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Automated analysis of privacy policies has proved a fruitful research direction, with developments such as automated policy summarization, question answering systems, and compliance detection. Prior research has been limited to analysis of privacy policies from a single point in time or from short spans of time, as researchers did not have access to a large-scale, longitudinal, curated dataset. To address this gap, we developed a crawler that discovers, downloads, and extracts archived privacy policies from the Internet Archive's Wayback Machine. Using the crawler and following a series of validation and quality control steps, we curated a dataset of 1,071,488 English language privacy policies, spanning over two decades and over 130,000 distinct websites. Our analyses of the data paint a troubling picture of the transparency and accessibility of privacy policies. By comparing the occurrence of tracking-related terminology in our dataset to prior web privacy measurements, we find that privacy policies have consistently failed to disclose the presence of common tracking technologies and third parties. We also find that over the last twenty years privacy policies have become even more difficult to read, doubling in length and increasing a full grade in the median reading level. Our data indicate that self-regulation for first-party websites has stagnated, while self-regulation for third parties has increased but is dominated by online advertising trade associations. Finally, we contribute to the literature on privacy regulation by demonstrating the historic impact of the GDPR on privacy policies.
引用
收藏
页码:2165 / 2176
页数:12
相关论文
共 75 条
[1]  
Al-Rfou Rami, 2020, POLYGLOT
[2]  
Alir3z4, 2020, HTML2TEXT
[3]  
[Anonymous], 2012, COMMUNICATIONS IIMA
[4]  
[Anonymous], 2016, J LEGAL STUD
[5]  
[Anonymous], 2000, CDTs Guide to Online Privacy, Fair Information Practices
[6]  
[Anonymous], 2020, P 2020 CHI C HUM FAC, DOI DOI 10.1109/IAS44978.2020.9449617
[7]   HIPAA's effect on web site privacy policies [J].
Anton, Annie I. ;
Earp, Julia B. ;
Vail, Matthew W. ;
Jain, Neha ;
Gheen, Carrie M. ;
Frink, Jack M. .
IEEE SECURITY & PRIVACY, 2007, 5 (01) :45-52
[8]  
Bowers J, 2017, PROCEEDINGS OF THIRTEENTH SYMPOSIUM ON USABLE PRIVACY AND SECURITY (SOUPS 2017), P97
[9]   The impact of Java']JavaScript on archivability [J].
Brunelle, Justin F. ;
Kelly, Mat ;
Weigle, Michele C. ;
Nelson, Michael L. .
INTERNATIONAL JOURNAL ON DIGITAL LIBRARIES, 2016, 17 (02) :95-117
[10]   Not all mementos are created equal: measuring the impact of missing resources [J].
Brunelle, Justin F. ;
Kelly, Mat ;
SalahEldeen, Hany ;
Weigle, Michele C. ;
Nelson, Michael L. .
INTERNATIONAL JOURNAL ON DIGITAL LIBRARIES, 2015, 16 (3-4) :283-301