Disaster privacy/privacy disaster

Disaster privacy/privacy disaster
复制标题

DOI:
10.1002/asi.24353
复制
发表时间:
2020-03
期刊:
J. Assoc. Inf. Sci. Technol.
影响因子:
--
通讯作者:
M. Sanfilippo;Yan Shvartzshnaider;Irwin Reyes;H. Nissenbaum;Serge Egelman
M. Sanfilippo;Yan Shvartzshnaider;Irwin Reyes;H. Nissenbaum;Serge Egelman
中科院分区:
其他
文献类型:
--
作者:
M. Sanfilippo;Yan Shvartzshnaider;Irwin Reyes;H. Nissenbaum;Serge Egelman

文献摘要

被引文献

相似文献

灾害期间的隐私期望与非紧急情况下有很大不同。最近的丑闻,如联邦应急管理局对承包商的不当披露,表明必须谨慎地在紧急情况和隐私之间进行权衡。越来越多地使用社交技术来促进沟通和支持第一反应者,为侵犯隐私提供了更多的机会,尽管对政府机构和政府信任的合作伙伴的灾害信息流的监管有所增加。本文专门探讨流行的灾难应用程序遵循的实际做法。我们的实证研究比较了隐私政策和政府机构政策的内容分析,由上下文完整性(CI)框架构建,静态和动态应用程序分析记录了他们发送的个人数据。我们确定了监管和指导、隐私政策以及应用程序/平台产生的信息流之间的实质性差距,这些差距是由模糊性和利用豁免造成的。研究结果还显示了治理与实践之间的差距,包括:(1)许多应用程序忽略了政策中自定义的传输原则;(2)虽然一些政策声明它们在某些条件下“可能”访问位置数据,但这些条件并不满足,因为我们研究中包含的12个应用程序在下载后立即捕获位置;以及(3)并非所有第三方数据接收者都在策略中被标识,包括违反可信第三方的期望的实例。我们直观地绘制了灾害期间以及灾害响应领域内第三方和政府应用程序周围的灾害信息流,并强调了特定参与者之间的信息交换以及个人信息的实际流动与监管和政策规范之间的差异。
Privacy expectations during disasters differ significantly from non-emergency situations. Recent scandals, such as inappropriate disclosures from FEMA to contractors, illustrate that tradeoffs between emergencies and privacy must be made carefully. Increased use of social technologies to facilitate communication and support first responders provide more opportunities for privacy infringements, despite increased regulation of disaster information flows to government agencies and with trusted partners of the government. This paper specifically explores the actual practices followed by popular disaster apps. Our empirical study compares content analysis of privacy policies and government agency policies, structured by the contextual integrity (CI) framework, with static and dynamic app analysis documenting the personal data they send. We identify substantive gaps between regulation and guidance, privacy policies, and information flows generated by apps/platforms, resulting from ambiguities and exploitation of exemptions. Results also indicate gaps between governance and practice, including: (1) many apps ignore transmission principles self-defined in policy; (2) while some policies state they “might” access location data under certain conditions, those conditions are not met as 12 apps included in our study capture location immediately upon download; and (3) not all third parties data recipients are identified in policy, including instances that violate expectations of trusted third parties. We visually map disaster information flows during disasters and around third party and government apps within the disaster response domain, and emphasize information exchanges between specific actors and the differences between actual flows of personal information and regulatory and policy specifications.