PolicyChecker: Analyzing the GDPR Completeness of Mobile Apps' Privacy Policies

PolicyChecker: Analyzing the GDPR Completeness of Mobile Apps' Privacy Policies
复制标题

PolicyChecker:分析移动应用程序隐私政策的 GDPR 完整性

DOI:
10.1145/3576915.3623067
复制
发表时间:
2023
期刊:
Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security (CCS
影响因子:
--
通讯作者:
Yue, Chuan
Yue, Chuan
中科院分区:
--
文献类型:
--
作者:
Xiang, Anhao;Pei, Weiping;Yue, Chuan

文献摘要

参考文献

相似文献

欧洲通用数据保护条例(GDPR)要求数据控制者(例如,应用程序开发人员)提供条款(第2条)中指定的所有信息。第13和14条向数据主体(例如,应用程序用户)告知其数据的处理方式以及他们的权利。虽然一些研究已经开始在隐私政策中发现GDPR要求的实现,但他们的探索只集中在强制性GDPR要求的子集上。在本文中,我们的目标是探索移动应用隐私政策中违反gdpr完整性的状态。为了实现我们的目标,我们采用基于规则和语义角色的方法来设计PolicyChecker框架。PolicyChecker不仅根据所有强制性GDPR要求,而且根据所有在特定条件下将成为强制性的适用GDPR要求,自动检测隐私政策中的完整性违规行为。我们使用PolicyChecker对英国b谷歌Play商店中205973个Android应用的隐私政策进行了首次大规模的gdpr完整性违规研究。PolicyChecker识别出163,068条(79.2%)包含数据收集声明的隐私政策;因此,此类策略受GDPR要求的监管。但绝大多数(99.3%)企业至少有一项不符合要求,未能达到gdp的完备性;其中98.1%至少有一项未获满足的强制性需求,而73.0%至少有一项未获满足的“如果适用”需求逻辑链。我们推测,控制者缺乏对某些GDPR要求的理解,以及他们在制定隐私政策方面的不良做法,可能是违反GDPR完整性背后的潜在主要原因。我们进一步讨论了应用程序开发者的建议,以提高其应用程序隐私政策的完整性,为用户提供更透明的个人数据处理环境。
The European General Data Protection Regulation (GDPR) mandates a data controller (e.g., an app developer) to provide all information specified in Articles (Arts.) 13 and 14 to data subjects (e.g., app users) regarding how their data are being processed and what are their rights. While some studies have started to detect the fulfillment of GDPR requirements in a privacy policy, their exploration only focused on a subset of mandatory GDPR requirements. In this paper, our goal is to explore the state of GDPR-completeness violations in mobile apps' privacy policies. To achieve our goal, we design the PolicyChecker framework by taking a rule and semantic role based approach. PolicyChecker automatically detects completeness violations in privacy policies based not only on all mandatory GDPR requirements but also on all if-applicable GDPR requirements that will become mandatory under specific conditions. Using PolicyChecker, we conduct the first large-scale GDPR-completeness violation study on 205,973 privacy policies of Android apps in the UK Google Play store. PolicyChecker identified 163,068 (79.2%) privacy policies containing data collection statements; therefore, such policies are regulated by GDPR requirements. However, the majority (99.3%) of them failed to achieve the GDPR-completeness with at least one unsatisfied requirement; 98.1% of them had at least one unsatisfied mandatory requirement, while 73.0% of them had at least one unsatisfied if-applicable requirement logic chain. We conjecture that controllers' lack of understanding of some GDPR requirements and their poor practices in composing a privacy policy can be the potential major causes behind the GDPR-completeness violations. We further discuss recommendations for app developers to improve the completeness of their apps' privacy policies to provide a more transparent personal data processing environment to users.
DOI: 10.1145/3460120.3484536
发表时间: 2021-11
期刊: Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
D. Bui;Y. Yao;K. Shin;Jong-Min Choi;Junbum Shin
通讯作者: D. Bui;Y. Yao;K. Shin;Jong-Min Choi;Junbum Shin
DOI: --
发表时间: 2020
期刊:
影响因子: --
作者:
R. Polcák
通讯作者: R. Polcák
第十四条 未从数据主体处获取个人数据时应提供的信息
DOI: 10.1093/oso/9780198826491.003.0045
发表时间: 2020
期刊: 2017 IEEE 25th International Requirements Engineering Conference (RE)
影响因子: --
作者:
Gabriela Zanfir
通讯作者: Gabriela Zanfir
逆(适当)流程:隐私政策分析的上下文完整性方法
DOI: --
发表时间: 2019
期刊: AAAI Conference on Human Computation & Crowdsourcing
影响因子: --
作者:
Yan Shvartzshnaider;Noah J. Apthorpe;N. Feamster;H. Nissenbaum
通讯作者: H. Nissenbaum
从规定到描述:将 GDPR 映射到隐私政策语料库注释方案
DOI: --
发表时间: 2020
期刊: Frontiers in artificial intelligence and applications
影响因子: --
作者:
Poplavska, Ellen;Norton, Thomas B.;Wilson, Shomir;Sadeh, Norman
通讯作者: Sadeh, Norman