skip to main content
10.1145/1753326.1753561acmconferencesArticle/Chapter ViewAbstractPublication PageschiConference Proceedingsconference-collections
research-article

Standardizing privacy notices: an online study of the nutrition label approach

Published:10 April 2010Publication History

ABSTRACT

Earlier work has shown that consumers cannot effectively find information in privacy policies and that they do not enjoy using them. In our previous research we developed a standardized table format for privacy policies. We compared this standardized format, and two short variants (one tabular, one text) with the current status quo: full text natural-language policies and layered policies. We conducted an online user study of 764 participants to test if these three more-intentionally designed, standardized privacy policy formats, assisted by consumer education, can benefit consumers. Our results show that standardized privacy policy presentations can have significant positive effects on accuracy and speed of information finding and on reader enjoyment of privacy policies.

References

  1. S. Balasubramanian and C. Cole. Consumers' search and use of nutrition information: The challenge and promise of the nutrition labeling and education act. In Journal of Marketing, 2002.Google ScholarGoogle Scholar
  2. L.F. Cranor. Web Privacy with P3P. O'Reilly and Associates, Sebastopol, CA, 2002. Google ScholarGoogle ScholarDigital LibraryDigital Library
  3. A. Drichoutis, P. Lazaridis, and R. Nayga. Consumers' use of nutritional labels. In Academy Marketing Science Review, 2006.Google ScholarGoogle Scholar
  4. C. Jensen and C. Potts. Privacy policies as decision-making tools: An evaluation of online privacy notices. In Proceedings of the SIGCHI conference on Human Factors in Computing Systems, pages 471--478, Vienna, Austria, 2004. Google ScholarGoogle ScholarDigital LibraryDigital Library
  5. P. Kelley, L. Cesca, J. Bresee, and L. Cranor. Standardizing privacy notices: An online study of the nutrition label approach. Technical Report CMU-CyLab-09-014, Carnegie Mellon University, November 2009.Google ScholarGoogle Scholar
  6. P.G. Kelley, J. Bresee, L.F. Cranor, and R.W. Reeder. A "Nutrition Label" for Privacy. In Proceedings of the 2009 Symposium On Usable Privacy and Security (SOUPS), 2009. Google ScholarGoogle ScholarDigital LibraryDigital Library
  7. Kleimann Communication Group Inc. Evolution of a prototype financial privacy notice., February 2006. http://www.ftc.gov/privacy/privacy initiatives/ftcfinalreport060228.pdf.Google ScholarGoogle Scholar
  8. A. Levy and M. Hastak. Consumer comprehension of financial privacy notices: A report on the results of the quantitative testing, 2008. http://www.ftc.gov/privacy/privacy initiatives/Levy-Hastak-Report.pdf.Google ScholarGoogle Scholar
  9. A. McDonald and L. Cranor. The cost of reading privacy policies. In Proceedings of the Technology Policy Research Conference, September 26-28 2008.Google ScholarGoogle Scholar
  10. A.M. McDonald, R.W. Reeder, P.G. Kelley, and L.F. Cranor. A comparative study of online privacy policies and formats. In Proceedings of 2009 Workshop on Privacy Enhancing Technologies. ACM, 2009. Google ScholarGoogle ScholarDigital LibraryDigital Library
  11. R. Reeder, L. Cranor, P. Kelley, and A. McDonald. A user study of the expandable grid applied to p3p privacy policy visualization. In Workshop on Privacy in the Electronic Society, 2008. Google ScholarGoogle ScholarDigital LibraryDigital Library
  12. The Center for Information Policy Leadership. Multi-Layered Notices Explained, 2004. http://www.hunton.com/files/tbls47Details/FileUpload265/1303/CIPLAPECNotices White Paper.pdf.Google ScholarGoogle Scholar
  13. The Center for Information Policy Leadership. Ten steps to develop a multilayered privacy notice, 2005. http://www.hunton.com/files/tbls47Details/FileUpload265/1405/Ten_Steps_whitepaper.pdf.Google ScholarGoogle Scholar
  14. United States Code. 6803. Disclosure of institution privacy policy, 2008. http://www.ftc.gov/privacy/glbact/_glbsub1.htm#6803.Google ScholarGoogle Scholar
  15. World Wide Web Consortium. The platform for privacy preferences 1.1 (p3p1.1) specification, 2006. http://www.w3.org/TR/P3P11/.Google ScholarGoogle Scholar

Index Terms

  1. Standardizing privacy notices: an online study of the nutrition label approach

        Recommendations

        Comments

        Login options

        Check if you have access through your login credentials or your institution to get full access on this article.

        Sign in
        • Published in

          cover image ACM Conferences
          CHI '10: Proceedings of the SIGCHI Conference on Human Factors in Computing Systems
          April 2010
          2690 pages
          ISBN:9781605589299
          DOI:10.1145/1753326

          Copyright © 2010 ACM

          Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

          Publisher

          Association for Computing Machinery

          New York, NY, United States

          Publication History

          • Published: 10 April 2010

          Permissions

          Request permissions about this article.

          Request Permissions

          Check for updates

          Qualifiers

          • research-article

          Acceptance Rates

          Overall Acceptance Rate6,199of26,314submissions,24%

        PDF Format

        View or Download as a PDF file.

        PDF

        eReader

        View online with eReader.

        eReader