Privacy Interests In Public Records: An Empirical Investigation

Privacy Interests In Public Records: An Empirical Investigation
复制标题

公共记录中的隐私利益:实证调查

DOI:
10.2139/ssrn.2875720
复制
发表时间:
2017
期刊:
Information Privacy Law eJournal
影响因子:
--
通讯作者:
H. Nissenbaum
H. Nissenbaum
中科院分区:
--
文献类型:
--
作者:
Kirsten E. Martin;H. Nissenbaum

文献摘要

被引文献

相似文献

信息二分法的概念在规范隐私方面发挥了决定性作用:被视为隐私或敏感的信息通常受到高度保护,而被视为公开或非敏感的信息则受到较低程度的保护。根据这种二分法,语境完整性理论将隐私与复杂的信息类型联系起来,每种类型都与各自的社会语境有关。此外,它认为,信息类型只是几个变量之一,塑造人们的隐私期望和隐私的规范基础的基础。其他背景变量包括关键行为者-信息主体、信息提供者和接收者-以及信息传输的原则,如是否经主体同意、买卖、法律要求等。先前的工作揭示了这些其他变量对隐私评估的系统性影响,从而揭穿了所谓的私人信息的决定性影响。在本文中,我们揭示了相反的效果,挑战了关于公共信息的传统假设。该文件报告了一系列研究,探讨了对被认为是公开的信息的态度和期望。通过联邦、州和地方机构的历史实践建立的公共记录,作为一个恰当的例子,几乎没有隐私保护,或者可能根本没有。在逐步数字化和创建在线门户网站的推动下,这些记录已经公开访问,我们的工作强调了需要更集中和细致入微的隐私评估,面对积极的开放数据倡议,这要求联邦,州和地方机构以人类和机器可读的形式提供对政府记录的访问。在一系列研究中,我们的工作以情境完整性理论为指导,为开放数据倡议提出了可能的防护措施,深入了解了系统地塑造个人对信息的适当使用和访问条件的期望和规范性判断的因素。使用因子小插曲调查,我们要求受访者对一系列情景的适当性进行评级,其中上下文元素系统地变化;这些元素包括数据接收者(例如银行,雇主,朋友),数据主体以及信息的来源或发送者(例如个人、政府、数据经纪人)。由于本研究的目的是突出人们对所谓的公共信息的隐私期望的复杂性,信息类型来自公共政府记录中经常持有的数据字段(例如,选民登记,婚姻状况,犯罪地位和真实的财产所有权)。我们的研究结果是值得注意的理论和实践的理由。首先,它们强化了上下文完整性的关键主张,即信息类型之外的其他因素与隐私同时相关。其次,它们揭示了经常影响与隐私相关的公共政策的真理之间的不一致。例如,易访问性并不驱动适当性的判断。因此,即使受访者认为信息容易获取(婚姻状况),但他们仍认为在某些情况下获取这些信息是不合适的(“不合适”)。·即使有可能在公共记录中找到某些信息,受访者在判断特定数据流是否适当时也关心该信息的直接来源。特别是,无论已知公共记录中有相关信息,受访者都认为,数据经纪人是信息直接来源的所有情况都是不合适的。·与直接询问数据主体的无效条件相比,年轻受访者(35岁以下)对使用数据经纪人和在线政府记录更持批评态度,这揭穿了“数字原住民”对隐私不感兴趣的传统智慧。公共政策的一个直接应用是获取记录,其中包括有关可识别或可联系的个人的信息。这项研究表明,个人对适当获取和使用公共记录中的信息有着相当强烈的规范性期望,这与“一切皆有可能”的格言不符。此外,这些期望远非特殊和武断。我们的工作要求提供比简单的开/关模式更明智的访问方法。复杂的信息本体、关键行为者的凭证(即与数据主体有关的发送者和接收者)以及访问条件-甚至是轻量级的访问条件-例如身份或角色认证、不同的特权级别或对有限目的的承诺,都可以用来调整公众访问,使其更好地符合合法的隐私期望。在围绕公共记录和开放数据举措制定政策时,应系统地考虑到这种期望。
The construct of an information dichotomy has played a defining role in regulating privacy: information deemed private or sensitive typically earns high levels of protection, while lower levels of protection are accorded to information deemed public or non-sensitive. Challenging this dichotomy, the theory of contextual integrity associates privacy with complex typologies of information, each connected with respective social contexts. Moreover, it contends that information type is merely one among several variables that shape people’s privacy expectations and underpin privacy’s normative foundations. Other contextual variables include key actors - information subjects, senders, and recipients - as well as the principles under which information is transmitted, such as whether with subjects’ consent, as bought and sold, as required by law, and so forth. Prior work revealed the systematic impact of these other variables on privacy assessments, thereby debunking the defining effects of so-called private information. In this paper, we shine a light on the opposite effect, challenging conventional assumptions about public information. The paper reports on a series of studies, which probe attitudes and expectations regarding information that has been deemed public. Public records established through the historical practice of federal, state, and local agencies, as a case in point, are afforded little privacy protection, or possibly none at all. Motivated by progressive digitization and creation of online portals through which these records have been made publicly accessible our work underscores the need for more concentrated and nuanced privacy assessments, even more urgent in the face of vigorous open data initiatives, which call on federal, state, and local agencies to provide access to government records in both human and machine readable forms. Within a stream of research suggesting possible guard rails for open data initiatives, our work, guided by the theory of contextual integrity, provides insight into the factors systematically shaping individuals’ expectations and normative judgments concerning appropriate uses of and terms of access to information. Using a factorial vignette survey, we asked respondents to rate the appropriateness of a series of scenarios in which contextual elements were systematically varied; these elements included the data recipient (e.g. bank, employer, friend,.), the data subject, and the source, or sender, of the information (e.g. individual, government, data broker). Because the object of this study was to highlight the complexity of people’s privacy expectations regarding so-called public information, information types were drawn from data fields frequently held in public government records (e.g. voter registration, marital status, criminal standing, and real property ownership). Our findings are noteworthy on both theoretical and practical grounds. In the first place, they reinforce key assertions of contextual integrity about the simultaneous relevance to privacy of other factors beyond information types. In the second place, they reveal discordance between truisms that have frequently shaped public policy relevant to privacy. For example, • Ease of accessibility does not drive judgments of appropriateness. Thus, even when respondents deemed information easy to access (marital status) they nevertheless judged it inappropriate (“Not OK”) to access this information under certain circumstances.• Even when it is possible to find certain information in public records, respondents cared about the immediate source of that information in judging whether given data flows were appropriate. In particular, no matter that information in question was known to be available in public records, respondents deemed inappropriate all circumstances in which data brokers were the immediate source of information. • Younger respondents (under 35 years old) were more critical of using data brokers and online government records as compared with the null condition of asking data subjects directly, debunking conventional wisdom that “digital natives” are uninterested in privacy. One immediate application to public policy is in the sphere of access to records that include information about identifiable or reachable individuals. This study has shown that individuals have quite strong normative expectations concerning appropriate access and use of information in public records that do not comport with the maxim, “anything goes.” Furthermore, these expectations are far from idiosyncratic and arbitrary. Our work calls for approaches to providing access that are more judicious than a simple on/off spigot. Complex information ontologies, credentials of key actors (i.e. sender and recipients in relation to data subject), and terms of access – even lightweight ones – such as, identity or role authentication, varying privilege levels, or a commitment to limited purposes may all be used to adjust public access to align better with legitimate privacy expectations. Such expectations should be systematically considered when crafting policies around public records and open data initiatives.