Skip to main content

2021 | OriginalPaper | Buchkapitel

Law in Books and Law in Action: The Readability of Privacy Policies and the GDPR

verfasst von : Shmuel I. Becher, Uri Benoliel

Erschienen in: Consumer Law and Economics

Verlag: Springer International Publishing

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

The most systematic legislative attempt to make more order in the chaotic world of privacy is the EU General Data Protection Regulation (GDPR). The primary objective of the GDPR is to level the playing field and give individuals more control over their personal data. Among other things, the GDPR aspires to force companies to be more transparent around data collection and usage. Along these lines, the GDPR requires firms to clearly communicate privacy terms to end users by using “clear and plain language” in their privacy agreements. In this study we ask whether, half a year post-GDPR, firms offer users online privacy agreements that are written in a readable manner. To that end, we empirically examine the readability of privacy policies of 300 highly popular websites. The results indicate that in spite of the GDPR’s requirement, users often encounter privacy policies that are largely unreadable. After presenting the empirical results we further discuss the legal and policy implications of our findings.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Fußnoten
1
Cf. Balkin (2018).
 
2
Tene (2008).
 
3
Hoofnagle et al. (2018), p. 2.
 
4
Schwartz and Peifer (2017).
 
5
Hoofnagle et al. (2018), pp. 2–3, and 6.
 
6
Abril et al. (2018), p. 30.
 
7
Markram (2018).
 
8
Rustad and Koenig (2018), p. 68.
 
9
Hoofnagle et al. (2018), p. 3.
 
10
Rustad and Koenig (2018).
 
13
Rustad and Koenig (2018).
 
14
Hoofnagle et al. (2018), pp. 2, 4, 6, 32–33.
 
15
Rustad and Koenig (2018).
 
16
Bignami and Resta (2015), Schwartz (2013) and Hoofnagle et al. (2018), p. 6.
 
17
Houser and Voss (2018).
 
19
Hoofnagle et al. (2018), p. 5.
 
20
Rustad and Koenig (2018), p. 88.
 
21
Felsenfeld (1982–1983), p. 408; Serafin (1998), p. 694; Kimble (1992), p. 3.
 
22
Schiess (2003–2004), p. 53.; Friman (1994–1995), p. 108.
 
24
16 C.F.R. § 436.6(b).
 
25
16 C.F.R. § 436.1(o).
 
26
17 C.F.R. § 230.421.
 
27
29 U.S.C. § 1022(a).
 
28
12 C.F.R. § 205.4; 15 U.S.C. § 2302(a).
 
29
45 C.F.R. 164.520(b)(1).
 
30
15 U.S.C. § 1632(a); 12 C.F.R. § 213.3(a) (Consumer Leasing Act); 12 C.F.R. § 1024.32(a)(1) (Real Estate Settlement Procedures Act of 1974); 12 C.F.R. § 1030.3(a) (Truth in Savings Act).
 
31
Timm and Oswald (1985), p. 33.; Ross (1981), p. 331.
 
32
Lloyd (1986), p. 687.
 
33
See, for instance, Mont. Code Ann. § 30-14-1103 (West 2015).
 
34
See, for instance, Con. Gen. Stat. Ann. § 42-152(c)(1), (2) & (5) (West 2015).
 
35
Asprey (2005), p. 62.
 
40
Asprey (2005), p. 9.
 
41
National Consumer Credit Protection Act 2009, s 184(1).
 
42
Legal Profession Uniform Law Application Act 2014 (NSW), s 181(2)(a).
 
43
Article 5.
 
44
Fair Trading Act 1986, s 2 (1), the definition of “transparent”.
 
45
Fair Trading Act 1986, s 46L… .
 
46
Zarsky (2019).
 
47
Zarsky (2019).
 
48
Hoofnagle et al. (2018), p. 5.
 
49
Schwartz and Peifer (2017), p. 144.
 
50
Data Protection Working Party (2018), p. 14.
 
52
Hoofnagle et al. (2018), p. 17.
 
53
GDPR, Article 6, 1(b).
 
54
GDPR, Article 5, 1(b).
 
57
The FRE and F-K tests were executed, as in many other empirical readability studies, using Microsoft Word software. See https://​support.​office.​com/​en-us/​article/​test-your-document-s-readability-85b4969e-e80a-4777-8dd3-f7fc3c8b3fd2.
 
58
Calderón and Smith (2007), p. 21.
 
59
Alexander (2000), p. 938.
 
60
Rogers et al. (2007), p. 185; Long and Christensen (2011), p. 147.
 
61
See for instance, Lloyd (1986), p. 689 (‘Plain English’ is defined as a text with a score of 60 or better).
 
62
See for instance, Narwani et al. (2016), p. 603.
 
63
McClure (1987), p. 12.
 
69
Marotta-Wurgler and Davis (2019).
 
72
Milne et al. (2006), p. 243.
 
73
Milne et al. (2006), p. 245.
 
76
Graber et al. (2002), p. 644.
 
77
Graber et al. (2002), p. 645.
 
80
Milne et al. (2006).
 
81
Becher and Unger-Aviram (2010).
 
82
McDonald and Cranor (2008–2009).
 
84
Austin et al. (2018).
 
85
Contissa et al. (2018).
 
87
Reidenberg et al. (2015), p. 54; Marine-Roig (2014), p. 386.
 
92
Payne et al. (2000), p. 1792; Health and Safety Executive, Evaluation of Product Documentation Provided by Suppliers of Hand Held Power Tools, p. 14 available at http://​www.​hse.​gov.​uk/​research/​rrpdf/​rr714.​pdf.
 
93
Benoliel and Becher (2019).
 
94
Masson and Waldron (1994); Kelley et al. (2010); Seizov et al. (2019), p 161.
 
95
Wydick (2005), Garner (2013) and Kimble (2002).
 
96
McIntyre (1996) and Nirmaldasan (2012).
 
97
Benoliel and Becher (2019).
 
98
Marotta-Wurgler and Taylor (2013).
 
99
ECJ, Árpád Kásler, Hajnalka Káslerné Rábai v OTP Jelzálogbank Zrt, Judgement [2014] Case C-26/13, 30 April 2014 [(Kásler)], para.75.
 
100
Austin et al. (2018) and Contissa et al. (2018).
 
101
Becher et al. (2019).
 
102
Becher et al. (2019).
 
103
For a recent more general analysis see Reidenberg et al. (2019).
 
104
Masson and Waldron (1994) and Kelley et al. (2010).
 
105
Hoffman (2018).
 
Literatur
Zurück zum Zitat Abril P, Blázquez F, Evora J (2018) The right of withdrawal in consumer contracts: a comparative analysis of American and European law. Indret 3:1–56 Abril P, Blázquez F, Evora J (2018) The right of withdrawal in consumer contracts: a comparative analysis of American and European law. Indret 3:1–56
Zurück zum Zitat Alexander R (2000) Readability of published dental educational material. J Am Dent Assoc 131(7):937–942CrossRef Alexander R (2000) Readability of published dental educational material. J Am Dent Assoc 131(7):937–942CrossRef
Zurück zum Zitat Asprey M (2005) Plain language for lawyers, 3rd edn. Federation Press, Sydney Asprey M (2005) Plain language for lawyers, 3rd edn. Federation Press, Sydney
Zurück zum Zitat Austin LM, Lie D, Sun P et al (2018) Towards dynamic transparency: the AppTrans (transparency for android applications) project. SSRN Electr J:1–51 Austin LM, Lie D, Sun P et al (2018) Towards dynamic transparency: the AppTrans (transparency for android applications) project. SSRN Electr J:1–51
Zurück zum Zitat Balkin J (2018) Fixing Social Media’s Grand Bargain. Hoover Working Group on National Security, Technology, and Law, Aegis Series Paper No. 1814:1–20 Balkin J (2018) Fixing Social Media’s Grand Bargain. Hoover Working Group on National Security, Technology, and Law, Aegis Series Paper No. 1814:1–20
Zurück zum Zitat Becher S, Unger-Aviram E (2010) The law of standard form contracts: misguided intuitions and suggestions for reconstruction. DePaul Bus Commer Law J 8:199–223 Becher S, Unger-Aviram E (2010) The law of standard form contracts: misguided intuitions and suggestions for reconstruction. DePaul Bus Commer Law J 8:199–223
Zurück zum Zitat Becher S, Gao H, Harrison A et al (2019) Hungry for change: the law and policy of food health labeling. Wake Forest Law Rev 54:1305–1360 Becher S, Gao H, Harrison A et al (2019) Hungry for change: the law and policy of food health labeling. Wake Forest Law Rev 54:1305–1360
Zurück zum Zitat Benoliel U, Becher S (2019) The duty to read the unreadable. Boston College Law Rev 60:2255–2296 Benoliel U, Becher S (2019) The duty to read the unreadable. Boston College Law Rev 60:2255–2296
Zurück zum Zitat Bignami F, Resta G (2015) Transatlantic privacy regulation: conflict and cooperation. Law Contemp Probl 78:231–266 Bignami F, Resta G (2015) Transatlantic privacy regulation: conflict and cooperation. Law Contemp Probl 78:231–266
Zurück zum Zitat Calderón J, Smith S (2007) FONBAYS: a simple method for enhancing readability of patient information. Ann Behav Sci Med Educ 13(1):20–24. Calderón J, Smith S (2007) FONBAYS: a simple method for enhancing readability of patient information. Ann Behav Sci Med Educ 13(1):20–24.
Zurück zum Zitat Contissa G, Docter K, Lagioia F et al (2018) Claudette meets GDPR: automating the evaluation of privacy policies using artificial intelligence. SSRN Electr J:1–64 Contissa G, Docter K, Lagioia F et al (2018) Claudette meets GDPR: automating the evaluation of privacy policies using artificial intelligence. SSRN Electr J:1–64
Zurück zum Zitat Data Protection Working Party (2018) Guidelines on consent under Regulation2016/679. WP259 rev.01:1–33 Data Protection Working Party (2018) Guidelines on consent under Regulation2016/679. WP259 rev.01:1–33
Zurück zum Zitat Felsenfeld C (1982–1983) The plain English movement in the United States. Can Bus Law J 6:408–421 Felsenfeld C (1982–1983) The plain English movement in the United States. Can Bus Law J 6:408–421
Zurück zum Zitat Friman M (1994–1995) Plain English statutes: long overdue or underdone? Loyal Univ Consum Law Rev 7:103–112 Friman M (1994–1995) Plain English statutes: long overdue or underdone? Loyal Univ Consum Law Rev 7:103–112
Zurück zum Zitat Garner B (2013) Legal Writing in Plain Language English 27 Garner B (2013) Legal Writing in Plain Language English 27
Zurück zum Zitat Graber M, D’Alessandro D, Johnson-West J (2002) Reading level of privacy policies on Internet health Web sites. J Family Pract 52:642–645 Graber M, D’Alessandro D, Johnson-West J (2002) Reading level of privacy policies on Internet health Web sites. J Family Pract 52:642–645
Zurück zum Zitat Hoffman D (2018) Relational contract of adhesion. Chicago Law Rev 85:1395–1461 Hoffman D (2018) Relational contract of adhesion. Chicago Law Rev 85:1395–1461
Zurück zum Zitat Hoofnagle C, van der Sloot B, Borgesius F (2018) The European general data protection regulation: what it is and what it means? UC Berkeley Public Law Research Paper, pp 1–40 Hoofnagle C, van der Sloot B, Borgesius F (2018) The European general data protection regulation: what it is and what it means? UC Berkeley Public Law Research Paper, pp 1–40
Zurück zum Zitat Houser K, Voss G (2018) GDPR: the end of Google and Facebook or a new paradigm in data privacy? Richmond J Law Technol 25:1–109 Houser K, Voss G (2018) GDPR: the end of Google and Facebook or a new paradigm in data privacy? Richmond J Law Technol 25:1–109
Zurück zum Zitat Kelley P, Cesca L, Bresee J et al (2010) Standardizing privacy notices: an online study of the nutrition label approach. In: CyLab SIGCHI Conference on Human Factors in Computing Systems, New York, pp 1573–1582 Kelley P, Cesca L, Bresee J et al (2010) Standardizing privacy notices: an online study of the nutrition label approach. In: CyLab SIGCHI Conference on Human Factors in Computing Systems, New York, pp 1573–1582
Zurück zum Zitat Kimble J (1992) Plain English: A Charter for Clear Writing, Thomas M. Cooley Law Rev 9:11–14 Kimble J (1992) Plain English: A Charter for Clear Writing, Thomas M. Cooley Law Rev 9:11–14
Zurück zum Zitat Kimble J (2002) The elements of plain language. Mich Bar J Oct. 2002-44 Kimble J (2002) The elements of plain language. Mich Bar J Oct. 2002-44
Zurück zum Zitat Lloyd H (1986) Plain language statutes: plain good sense or plain nonsense? Law Library J 78(683):696 Lloyd H (1986) Plain language statutes: plain good sense or plain nonsense? Law Library J 78(683):696
Zurück zum Zitat Long L, Christensen W (2011) Does the readability of your brief affect your chance of winning an appeal? J Appellate Pract Process 12(1):145–162 Long L, Christensen W (2011) Does the readability of your brief affect your chance of winning an appeal? J Appellate Pract Process 12(1):145–162
Zurück zum Zitat Marine-Roig E (2014) A webometric analysis of travel blogs and review hosting: the case of Catalonia. J Travel Tour Market 31:381–396CrossRef Marine-Roig E (2014) A webometric analysis of travel blogs and review hosting: the case of Catalonia. J Travel Tour Market 31:381–396CrossRef
Zurück zum Zitat Marotta-Wurgler F, Davis K (2019) Contracting for data. N Y Univ Law Rev 94:662–705 Marotta-Wurgler F, Davis K (2019) Contracting for data. N Y Univ Law Rev 94:662–705
Zurück zum Zitat Marotta-Wurgler F, Taylor R (2013) Set in Stone? Change and innovation in standard-form contracts. N Y Univ Law Rev 88(1):240–245 Marotta-Wurgler F, Taylor R (2013) Set in Stone? Change and innovation in standard-form contracts. N Y Univ Law Rev 88(1):240–245
Zurück zum Zitat Masson M, Waldron M (1994) Comprehension of legal contracts by non experts: effectiveness of plain language redrafting. Appl Cogn Psychol 8:67–85 Masson M, Waldron M (1994) Comprehension of legal contracts by non experts: effectiveness of plain language redrafting. Appl Cogn Psychol 8:67–85
Zurück zum Zitat McClure G (1987) Readability formulas: useful or useless? IEEE Trans Prof Commun 30(1):12–15CrossRef McClure G (1987) Readability formulas: useful or useless? IEEE Trans Prof Commun 30(1):12–15CrossRef
Zurück zum Zitat McDonald A, Cranor L (2009) The cost of reading privacy policies. J Law Policy Inf Soc 4:543–568 McDonald A, Cranor L (2009) The cost of reading privacy policies. J Law Policy Inf Soc 4:543–568
Zurück zum Zitat Mcintyre B (1996) English News Writing 19 Mcintyre B (1996) English News Writing 19
Zurück zum Zitat Milne G, Culnan M, Greene H (2006) A longitudinal assessment of online privacy notice readability. J Public Policy Mark 25(2):238–249CrossRef Milne G, Culnan M, Greene H (2006) A longitudinal assessment of online privacy notice readability. J Public Policy Mark 25(2):238–249CrossRef
Zurück zum Zitat Narwani V, Nalamada K, Lee M et al (2016) Readability and quality assessment of internet-based patient education materials related to laryngeal cancer. Head Neck 38(4):601–605CrossRef Narwani V, Nalamada K, Lee M et al (2016) Readability and quality assessment of internet-based patient education materials related to laryngeal cancer. Head Neck 38(4):601–605CrossRef
Zurück zum Zitat Payne S, Large S, Jarrett N et al (2000) Written information given to patients and families by palliative care units: a national survey. Lancet 355:1792–1792CrossRef Payne S, Large S, Jarrett N et al (2000) Written information given to patients and families by palliative care units: a national survey. Lancet 355:1792–1792CrossRef
Zurück zum Zitat Pound R (1910) Law in books and law in action. Am Law Rev 44(1):12–36 Pound R (1910) Law in books and law in action. Am Law Rev 44(1):12–36
Zurück zum Zitat Reidenberg J, Breaux T, Carnor L et al (2015) Disagreeable privacy policies: mismatches between meaning and users’ understanding. Berkeley Technol Law J 30(1):39–68 Reidenberg J, Breaux T, Carnor L et al (2015) Disagreeable privacy policies: mismatches between meaning and users’ understanding. Berkeley Technol Law J 30(1):39–68
Zurück zum Zitat Reidenberg JR et al (2019) Trustworthy privacy indicators: grades, labels, certifications and dashboards. Wash Law Rev 96:1409–1460 Reidenberg JR et al (2019) Trustworthy privacy indicators: grades, labels, certifications and dashboards. Wash Law Rev 96:1409–1460
Zurück zum Zitat Rogers R, Harrison KS, Shuman DW et al (2007) An analysis of miranda warnings and waivers: comprehension and coverage. Law Human Behav 31(2):177–192CrossRef Rogers R, Harrison KS, Shuman DW et al (2007) An analysis of miranda warnings and waivers: comprehension and coverage. Law Human Behav 31(2):177–192CrossRef
Zurück zum Zitat Ross S (1981) On legalities and linguistics: plain language legislation. Buffalo Law Rev 30:317–362 Ross S (1981) On legalities and linguistics: plain language legislation. Buffalo Law Rev 30:317–362
Zurück zum Zitat Rustad M, Koenig T (2018) Towards a global data privacy standard. Florida Law Rev 71:365–453 Rustad M, Koenig T (2018) Towards a global data privacy standard. Florida Law Rev 71:365–453
Zurück zum Zitat Schiess W (2003–2004) What plain language really is. Scribes J Legal Writ 9:43–75 Schiess W (2003–2004) What plain language really is. Scribes J Legal Writ 9:43–75
Zurück zum Zitat Schwartz P (2013) The EU-US Privacy collision: a turn to institutions and procedures. Harv Law Rev 126:1966–2009 Schwartz P (2013) The EU-US Privacy collision: a turn to institutions and procedures. Harv Law Rev 126:1966–2009
Zurück zum Zitat Schwartz P, Peifer K (2017) Transatlantic data privacy. Georgetown Law J 106:115–179 Schwartz P, Peifer K (2017) Transatlantic data privacy. Georgetown Law J 106:115–179
Zurück zum Zitat Seizov O, Wulf A, Luzak J (2019) The transparent trap: a multidisciplinary perspective on the design of transparent online disclosures in the EU. J Consum Policy 42:149–173CrossRef Seizov O, Wulf A, Luzak J (2019) The transparent trap: a multidisciplinary perspective on the design of transparent online disclosures in the EU. J Consum Policy 42:149–173CrossRef
Zurück zum Zitat Serafin A (1998) Kicking the legalese habit: the SEC’s plain English disclosure proposal. Loyola Univ Chicago Law J 29:681–717 Serafin A (1998) Kicking the legalese habit: the SEC’s plain English disclosure proposal. Loyola Univ Chicago Law J 29:681–717
Zurück zum Zitat Tene O (2008) What Google knows: privacy and internet search engines. Utah Law Rev 4:1433–1492 Tene O (2008) What Google knows: privacy and internet search engines. Utah Law Rev 4:1433–1492
Zurück zum Zitat Timm P, Oswald D (1985) Plain English laws: symbolic or real? J Bus Commun 22:31–38CrossRef Timm P, Oswald D (1985) Plain English laws: symbolic or real? J Bus Commun 22:31–38CrossRef
Zurück zum Zitat Wydick R (2005) Plain English for Lawyers 36 Wydick R (2005) Plain English for Lawyers 36
Zurück zum Zitat Zarsky T (2019) Privacy and manipulation in the digital age. Theor Inq Law 20:157–188CrossRef Zarsky T (2019) Privacy and manipulation in the digital age. Theor Inq Law 20:157–188CrossRef
Zurück zum Zitat EUGDPR. The EU General Data Protection Regulation (GDPR) is the most important change in data privacy regulation in 20 years. Key Changes with the General Data Protection Regulation. Available at https://eugdpr.org/. Accessed 26 November 2018 EUGDPR. The EU General Data Protection Regulation (GDPR) is the most important change in data privacy regulation in 20 years. Key Changes with the General Data Protection Regulation. Available at https://​eugdpr.​org/​. Accessed 26 November 2018
Metadaten
Titel
Law in Books and Law in Action: The Readability of Privacy Policies and the GDPR
verfasst von
Shmuel I. Becher
Uri Benoliel
Copyright-Jahr
2021
DOI
https://doi.org/10.1007/978-3-030-49028-7_9