Empirical Measurement of Perceived Privacy Risk

被引:34
作者
Bhatia, Jaspreet [1 ]
Breaux, Travis D. [1 ]
机构
[1] Carnegie Mellon Univ, Sch Comp Sci, Inst Software Res, 5000 Forbes Ave, Pittsburgh, PA 15213 USA
关键词
Privacy; privacy risk perception; factorial vignettes; multilevel modeling; PERSONAL USE; INFORMATION;
D O I
10.1145/3267808
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Personal data is increasingly collected and used by companies to tailor services to users, and to make financial, employment, and health-related decisions about individuals. When personal data is inappropriately collected or misused, however, individuals may experience violations of their privacy. Historically, government regulators have relied on the concept of risk in energy, aviation and medicine, among other domains, to determine the extent to which products and services may harm the public. To address privacy concerns in government-controlled information technology, government agencies are advocating to adapt similar risk management frameworks to privacy. Despite the recent shift toward a risk-managed approach for privacy, to our knowledge, there are no empirical methods to determine which personal data are most at-risk and which contextual factors increase or decrease that risk. To this end, we introduce an empirical framework in this article that consists of factorial vignette surveys that can be used to measure the effect of different factors and their levels on privacy risk. We report a series of experiments to measure perceived privacy risk using the proposed framework, which are based on expressed preferences, and which we define as an individual's willingness to share their personal data with others given the likelihood of a potential privacy harm. These experiments control for one or more of the six factors affecting an individual's willingness to share their information: data type, computer type, data purpose, privacy harm, harm likelihood, and individual demographic factors, such as age range, gender, education level, ethnicity, and household income. To measure likelihood, we introduce and evaluate a new likelihood scale based on construal level theory in psychology. The scale frames individual attitudes about risk likelihood based on social and physical distance to the privacy harm. The findings include predictions about the extent to which the above factors correspond to risk acceptance, including that perceived risk is lower for induced disclosure harms when compared to surveillance and insecurity harms as defined in Solove's Taxonomy of Privacy. We also found that participants are more willing to share their information when they perceive the benefits of sharing. In addition, we found that likelihood was not a multiplicative factor in computing privacy risk perception, which challenges conventional theories of privacy risk in the privacy and security community.
引用
收藏
页数:47
相关论文
共 69 条
[1]   Privacy and rationality in individual decision making [J].
Acquisti, A ;
Grossklags, J .
IEEE SECURITY & PRIVACY, 2005, 3 (01) :26-33
[2]   Nudges for Privacy and Security: Understanding and Assisting Users' Choices Online [J].
Acquisti, Alessandro ;
Adjerid, Idris ;
Balebako, Rebecca ;
Brandimarte, Laura ;
Cranor, Lorrie Faith ;
Komanduri, Saranga ;
Giovanni Leon, Pedro ;
Sadeh, Norman ;
Schaub, Florian ;
Sleeper, Manya ;
Wang, Yang ;
Wilson, Shomir .
ACM COMPUTING SURVEYS, 2017, 50 (03)
[3]  
[Anonymous], 8062 NAT I STAND TEC
[4]  
[Anonymous], P IEEE 24 INT REQ EN
[5]  
[Anonymous], 2016, GLOB STAT INF SEC SU
[6]  
[Anonymous], 1948, RANK CORRELATION MET
[7]  
[Anonymous], R LANG ENV STAT COMP
[8]  
[Anonymous], 2005, Extended Abstracts on Human Factors in Computing Systems (CHI EA), DOI DOI 10.1145/1056808.1057073
[9]  
[Anonymous], 2016, AM FEEL TENSIONS PRI
[10]  
[Anonymous], COMMUNICATIONS STRAT