PolicyChecker: Analyzing the GDPR Completeness of Mobile Apps' Privacy Policies
PolicyChecker: Analyzing the GDPR Completeness of Mobile Apps' Privacy Policies
复制标题
PolicyChecker:分析移动应用程序隐私政策的 GDPR 完整性
DOI:
10.1145/3576915.3623067
复制
发表时间:
2023
期刊:
影响因子:
--
通讯作者:
Yue, Chuan
中科院分区:
文献类型:
--
作者:
Xiang, Anhao;Pei, Weiping;Yue, Chuan
The European General Data Protection Regulation (GDPR) mandates a data controller (e.g., an app developer) to provide all information specified in Articles (Arts.) 13 and 14 to data subjects (e.g., app users) regarding how their data are being processed and what are their rights. While some studies have started to detect the fulfillment of GDPR requirements in a privacy policy, their exploration only focused on a subset of mandatory GDPR requirements. In this paper, our goal is to explore the state of GDPR-completeness violations in mobile apps' privacy policies. To achieve our goal, we design the PolicyChecker framework by taking a rule and semantic role based approach. PolicyChecker automatically detects completeness violations in privacy policies based not only on all mandatory GDPR requirements but also on all if-applicable GDPR requirements that will become mandatory under specific conditions. Using PolicyChecker, we conduct the first large-scale GDPR-completeness violation study on 205,973 privacy policies of Android apps in the UK Google Play store. PolicyChecker identified 163,068 (79.2%) privacy policies containing data collection statements; therefore, such policies are regulated by GDPR requirements. However, the majority (99.3%) of them failed to achieve the GDPR-completeness with at least one unsatisfied requirement; 98.1% of them had at least one unsatisfied mandatory requirement, while 73.0% of them had at least one unsatisfied if-applicable requirement logic chain. We conjecture that controllers' lack of understanding of some GDPR requirements and their poor practices in composing a privacy policy can be the potential major causes behind the GDPR-completeness violations. We further discuss recommendations for app developers to improve the completeness of their apps' privacy policies to provide a more transparent personal data processing environment to users.
登录
查看更多内容
DOI:
10.1145/3460120.3484536
发表时间:
2021-11
期刊:
Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
D. Bui;Y. Yao;K. Shin;Jong-Min Choi;Junbum Shin
通讯作者:
D. Bui;Y. Yao;K. Shin;Jong-Min Choi;Junbum Shin
DOI:
--
发表时间:
2020
期刊:
影响因子:
--
作者:
R. Polcák
通讯作者:
R. Polcák
DOI:
10.1093/oso/9780198826491.003.0045
发表时间:
2020
期刊:
2017 IEEE 25th International Requirements Engineering Conference (RE)
影响因子:
--
作者:
Gabriela Zanfir
通讯作者:
Gabriela Zanfir
DOI:
--
发表时间:
2019
期刊:
AAAI Conference on Human Computation & Crowdsourcing
影响因子:
--
作者:
Yan Shvartzshnaider;Noah J. Apthorpe;N. Feamster;H. Nissenbaum
通讯作者:
H. Nissenbaum
DOI:
--
发表时间:
2020
期刊:
Frontiers in artificial intelligence and applications
影响因子:
--
作者:
Poplavska, Ellen;Norton, Thomas B.;Wilson, Shomir;Sadeh, Norman
通讯作者:
Sadeh, Norman