A Large-Scale Evaluation of U.S. Financial Institutions’ Standardized Privacy Notices

A Large-Scale Evaluation of U.S. Financial Institutions’ Standardized Privacy Notices
复制标题

对美国金融机构标准化隐私声明的大规模评估

DOI:
10.1145/2911988
复制
发表时间:
2016
期刊:
ACM Transactions on the Web (TWEB)
影响因子:
--
通讯作者:
Blase Ur
Blase Ur
中科院分区:
--
文献类型:
--
作者:
L. Cranor;P. Leon;Blase Ur

文献摘要

被引文献

相似文献

美国的金融机构被《格雷姆-里奇-比利利法案》要求每年提供隐私声明。2009年,8个联邦机构联合发布了一份关于这些信息披露的隐私表格范本。虽然不要求使用此模型隐私表单,但它已被广泛采用。我们自动评估了6191家美国金融机构在万维网上发布的隐私声明。我们发现,即使在相同类型的机构中,所陈述的实践也存在很大差异。虽然成千上万的金融机构共享个人信息,却没有为消费者提供退出的机会,但一些机构的做法更能保护隐私。回归分析表明,大型机构和总部位于东北地区的机构分享消费者个人信息的比例高于其他所有机构。此外,我们的分析还帮助我们发现了一些机构在法律要求时不允许消费者限制数据共享,以及一些机构发表了自相矛盾的声明。我们讨论了金融行业对隐私的影响,万维网上隐私表单模型的设计和使用问题,以及标准化隐私通知的未来方向。
Financial institutions in the United States are required by the Gramm-Leach-Bliley Act to provide annual privacy notices. In 2009, eight federal agencies jointly released a model privacy form for these disclosures. While the use of this model privacy form is not required, it has been widely adopted. We automatically evaluated 6,191 U.S. financial institutions’ privacy notices posted on the World Wide Web. We found large variance in stated practices, even among institutions of the same type. While thousands of financial institutions share personal information without providing the opportunity for consumers to opt out, some institutions’ practices are more privacy protective. Regression analyses show that large institutions and those headquartered in the northeastern region share consumers’ personal information at higher rates than all other institutions. Furthermore, our analysis helped us uncover institutions that do not let consumers limit data sharing when legally required to do so, as well as institutions making self-contradictory statements. We discuss implications for privacy in the financial industry, issues with the design and use of the model privacy form on the World Wide Web, and future directions for standardized privacy notice.