SlideShare uma empresa Scribd logo
1 de 18
Baixar para ler offline
Privacy Languages: Are we there yet
to enable user controls?
Jun Zhao, Reuben Binns, Max Van
Kleek and Nigel Shadbolt
Personal Data and Privacy Lab
Department of Computer Science
University of Oxford
Dominic Difranzo
ECS, Faculty of Physical
Sciences and Engineering
University of Southampton
Outline
● Motivation
● Methodology
● Preliminary results
● Future work
Motivation
Personal data is one of the most valuable commodities
● The revenue of digital advertising in the EU in 2014 is estimated to be
€30.7bn1
However,
● Users have limited knowledge about how their data are used
● Users have no control of how they expect their data to be used
1. Interactive Advertising Bureau AdEx Benchmark research, http://www.iabuk.net/about/press/archive/eu-online-advertising-reaches-landmark-307bn
Tracking is ubiquitous
● There is 99.5% chance
that a user will become
tracked by all top 10
trackers within 30 clicks
on top search results.
(Gomer et al 2013)
● Users have little
awareness and control
https://www.mozilla.org/en-US/lightbeam/
http://research.microsoft.com/apps/pubs/default.aspx?
id=201586
Beyond the web
Web browsing is just part of a wider sphere of potential privacy harms, including:
- Employment
- Health
- Finance
- Consumer spending
How can people express their wishes about the use of their personal data in these
domains?
An example scenario: sharing of medical data
Users
- Want controls
E.g, no commercial use
- Limited time + capacity
to read and process
notifications
Information controller
- Show commitment
E.g research purpose only
- Act according to socially
and/or legally binding
agreements
Existing privacy enhancement approaches
● Organisation-centric approaches
○ Structured privacy policy from information controllers, like P3P
(https://www.w3.org/P3P/)
○ Standardisation effort: Do Not Track, and P3P
● User-centric approaches
○ More usable privacy notifications, like privacy nutrition labels
○ Browser plug-in developments, e.g. Mozilla Privacy Icons,
ToS;DR
○ Privacy preference languages
Credit of privacy nutrition label to: https://cups.cs.cmu.edu/privacyLabel/files/CHI-privacyFinal2010
Users remain the weak points
Users
Control remains a weak
point
- A lot of past efforts
- But little uptake
- Why?
Information controller
- Show commitment
- Act on social and legal
binding
Our privacy language review
Privacy languages
● A declarative language for specifying both users’ privacy preferences and information
controllers’ privacy policies in a machine-readable way+
Existing reviews
● Kumaraguru et al 2007 and Kolter 2009: focused on the purpose of languages only
● Belanger and Crossler 2011: a review of privacy in Management Information Systems
● Kasem-Madani and Meier 2015: more focus on security
Our goal
● A user-centric review: focusing on the support for users, instead of organisations
● Gaining insights on design a user-centric language that is easy-to-use
+
Becker et al. Practical Generic Privacy Language. Information Systems Security. Springer Berlin Heidelberg, 2010. 125-139.
Methodology of the review
● 18 privacy languages from existing review literature
● Limited to academic efforts
● Eliminated those languages that describe access control only
● 10 languages in the review
● Assessment through 3 dimensions
○ Their design purpose
○ Their user-facing tooling support
○ Their consideration of interoperability
Preliminary results
Purpose of the languages
Purpose of the languages
● More emphasis on information controllers (i.e. through policy
languages), than users (i.e. through preference languages)
● Some preference languages are too simple, and with limited
expressivity
● Other preference languages are way too complicated to be used by
end users
● Nothing we can use off-the-shelf
Tooling support
● Motivation
○ Easy-to-use user facing tool is critical for adoptions of any proposed languages
○ Been shown as a critical barrier to the adoptions of standards like P3P
● Observations
○ Very few languages come with a user-facing tool (3 out of 10)
○ Very limited usability studies (except one tool) to ensure that these tools are
truly usable for the end users
●
Interoperability
● Motivation
○ Privacy is a ubiquitous issue, given the fast
development of mobile devices and IoTs
○ Privacy languages from different devices, users and
platforms must be interchangeable
● Observations
○ Pros: Languages are defined in standard formats,
like XML or RDF
○ Cons: standardisation efforts (like P3P) have failed,
with the lack of social agreements and legal
enforcements
Reflections
● Strengths
○ Extensive understanding on privacy scenarios and challenges
● Weaknesses
○ Existing languages are either too complicated for normal web users or too
simplistic to cope with the diverse requirements
○ Limited tooling development for end users
Future work
● A first-step towards user-centric privacy ---
enabling users to gain control
● Easy-to-use privacy preference language
● Easy-to-use user-facing tools
● Tracking breakage of terms on a
decentralised Web (of Things)
Thank you!

Mais conteúdo relacionado

Semelhante a Www sociam-2016-policy-reviews

ALIAS WP1 Results
ALIAS WP1 ResultsALIAS WP1 Results
ALIAS WP1 Results
geigeralias
 
Blockade.io : One Click Browser Defense
Blockade.io : One Click Browser DefenseBlockade.io : One Click Browser Defense
Blockade.io : One Click Browser Defense
RiskIQ, Inc.
 
FOSS in Education in Guyana
FOSS in Education in GuyanaFOSS in Education in Guyana
FOSS in Education in Guyana
Lenandlar Singh
 

Semelhante a Www sociam-2016-policy-reviews (20)

Data management planning: the what, the why, the who, the how
Data management planning: the what, the why, the who, the howData management planning: the what, the why, the who, the how
Data management planning: the what, the why, the who, the how
 
End user development approach mis
End user development approach mis End user development approach mis
End user development approach mis
 
sample PPT.pptx
sample PPT.pptxsample PPT.pptx
sample PPT.pptx
 
Media management and thesaurus use in the production environment, Tom de Smet...
Media management and thesaurus use in the production environment, Tom de Smet...Media management and thesaurus use in the production environment, Tom de Smet...
Media management and thesaurus use in the production environment, Tom de Smet...
 
Shallow Dive in Univarsal usability and its need
Shallow Dive in Univarsal usability and its needShallow Dive in Univarsal usability and its need
Shallow Dive in Univarsal usability and its need
 
Gift presentation
Gift presentationGift presentation
Gift presentation
 
Data management plans and planning - a gentle introduction
Data management plans and planning - a gentle introductionData management plans and planning - a gentle introduction
Data management plans and planning - a gentle introduction
 
Herding Cats: Project Management for Digital Scholarship
Herding Cats: Project Management for Digital ScholarshipHerding Cats: Project Management for Digital Scholarship
Herding Cats: Project Management for Digital Scholarship
 
ALIAS WP1 Results
ALIAS WP1 ResultsALIAS WP1 Results
ALIAS WP1 Results
 
Blockade.io : One Click Browser Defense
Blockade.io : One Click Browser DefenseBlockade.io : One Click Browser Defense
Blockade.io : One Click Browser Defense
 
Community SUmmit: Legal & Licensing / Public procurement of open source softw...
Community SUmmit: Legal & Licensing / Public procurement of open source softw...Community SUmmit: Legal & Licensing / Public procurement of open source softw...
Community SUmmit: Legal & Licensing / Public procurement of open source softw...
 
FOSS in Education in Guyana
FOSS in Education in GuyanaFOSS in Education in Guyana
FOSS in Education in Guyana
 
Access VI HI
Access VI HIAccess VI HI
Access VI HI
 
H2020 Open Research Data pilot
H2020 Open Research Data pilotH2020 Open Research Data pilot
H2020 Open Research Data pilot
 
Final project
Final projectFinal project
Final project
 
Open Source
Open SourceOpen Source
Open Source
 
apidays LIVE Paris 2021 - Boavitza, Year 2 by Laurent Eskenazi
apidays LIVE Paris 2021 - Boavitza, Year 2 by Laurent Eskenaziapidays LIVE Paris 2021 - Boavitza, Year 2 by Laurent Eskenazi
apidays LIVE Paris 2021 - Boavitza, Year 2 by Laurent Eskenazi
 
Bl cybersecurity z_dooly
Bl cybersecurity z_doolyBl cybersecurity z_dooly
Bl cybersecurity z_dooly
 
SFSU ISYS 363 - Fall 2013 Section #1 - Buccaneers
SFSU ISYS 363 - Fall 2013 Section #1 - BuccaneersSFSU ISYS 363 - Fall 2013 Section #1 - Buccaneers
SFSU ISYS 363 - Fall 2013 Section #1 - Buccaneers
 
Universal Usability
Universal UsabilityUniversal Usability
Universal Usability
 

Mais de Jun Zhao

2010 09 opm_tutorial_02-jun-opmv
2010 09 opm_tutorial_02-jun-opmv2010 09 opm_tutorial_02-jun-opmv
2010 09 opm_tutorial_02-jun-opmv
Jun Zhao
 
2010 06 rdf_next
2010 06 rdf_next2010 06 rdf_next
2010 06 rdf_next
Jun Zhao
 
2010 03 Lodoxf Openflydata
2010 03 Lodoxf Openflydata2010 03 Lodoxf Openflydata
2010 03 Lodoxf Openflydata
Jun Zhao
 
2009 Dils Flyweb
2009 Dils Flyweb2009 Dils Flyweb
2009 Dils Flyweb
Jun Zhao
 
Talk_linked_data_for_hcls_at_iswc2009
Talk_linked_data_for_hcls_at_iswc2009Talk_linked_data_for_hcls_at_iswc2009
Talk_linked_data_for_hcls_at_iswc2009
Jun Zhao
 
2008 Jun Zhao Eswc
2008 Jun Zhao Eswc2008 Jun Zhao Eswc
2008 Jun Zhao Eswc
Jun Zhao
 

Mais de Jun Zhao (17)

2012 05-swpm-provo
2012 05-swpm-provo2012 05-swpm-provo
2012 05-swpm-provo
 
2012 04-ldow-prov
2012 04-ldow-prov2012 04-ldow-prov
2012 04-ldow-prov
 
2011 03-provenance-workshop-edingurgh
2011 03-provenance-workshop-edingurgh2011 03-provenance-workshop-edingurgh
2011 03-provenance-workshop-edingurgh
 
2011 03-provenance-workshop-edingurgh
2011 03-provenance-workshop-edingurgh2011 03-provenance-workshop-edingurgh
2011 03-provenance-workshop-edingurgh
 
2010 09 opm_tutorial_02-jun-opmv
2010 09 opm_tutorial_02-jun-opmv2010 09 opm_tutorial_02-jun-opmv
2010 09 opm_tutorial_02-jun-opmv
 
2010 09 opm_tutorial_01-jun-usecase-datagovuk
2010 09 opm_tutorial_01-jun-usecase-datagovuk2010 09 opm_tutorial_01-jun-usecase-datagovuk
2010 09 opm_tutorial_01-jun-usecase-datagovuk
 
2010 06 rdf_next
2010 06 rdf_next2010 06 rdf_next
2010 06 rdf_next
 
2010 06 ipaw_prv
2010 06 ipaw_prv2010 06 ipaw_prv
2010 06 ipaw_prv
 
2010 05 edinburgh
2010 05 edinburgh2010 05 edinburgh
2010 05 edinburgh
 
2010 03 Lodoxf Openflydata
2010 03 Lodoxf Openflydata2010 03 Lodoxf Openflydata
2010 03 Lodoxf Openflydata
 
2009 09 Lod London
2009 09 Lod London2009 09 Lod London
2009 09 Lod London
 
2009 0807 Lod Gmod
2009 0807 Lod Gmod2009 0807 Lod Gmod
2009 0807 Lod Gmod
 
2009 Dils Flyweb
2009 Dils Flyweb2009 Dils Flyweb
2009 Dils Flyweb
 
Talk_linked_data_for_hcls_at_iswc2009
Talk_linked_data_for_hcls_at_iswc2009Talk_linked_data_for_hcls_at_iswc2009
Talk_linked_data_for_hcls_at_iswc2009
 
myExperiment and AIDA
myExperiment and AIDAmyExperiment and AIDA
myExperiment and AIDA
 
2008 Jun Zhao Eswc
2008 Jun Zhao Eswc2008 Jun Zhao Eswc
2008 Jun Zhao Eswc
 
2008 04 22 Jun Zhao Ldow
2008 04 22 Jun Zhao Ldow2008 04 22 Jun Zhao Ldow
2008 04 22 Jun Zhao Ldow
 

Último

Thalassery Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call G...
Thalassery Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call G...Thalassery Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call G...
Thalassery Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call G...
Call Girls In Delhi Whatsup 9873940964 Enjoy Unlimited Pleasure
 
➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men 🔝mehsana🔝 Escorts...
➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men  🔝mehsana🔝   Escorts...➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men  🔝mehsana🔝   Escorts...
➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men 🔝mehsana🔝 Escorts...
nirzagarg
 
💚😋 Salem Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
💚😋 Salem Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋💚😋 Salem Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
💚😋 Salem Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
nirzagarg
 
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Chandigarh Call girls 9053900678 Call girls in Chandigarh
 
💚😋 Bilaspur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
💚😋 Bilaspur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋💚😋 Bilaspur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
💚😋 Bilaspur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
nirzagarg
 

Último (20)

Thalassery Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call G...
Thalassery Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call G...Thalassery Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call G...
Thalassery Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call G...
 
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
 
2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs
2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs
2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs
 
20240509 QFM015 Engineering Leadership Reading List April 2024.pdf
20240509 QFM015 Engineering Leadership Reading List April 2024.pdf20240509 QFM015 Engineering Leadership Reading List April 2024.pdf
20240509 QFM015 Engineering Leadership Reading List April 2024.pdf
 
VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...
VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...
VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...
 
➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men 🔝mehsana🔝 Escorts...
➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men  🔝mehsana🔝   Escorts...➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men  🔝mehsana🔝   Escorts...
➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men 🔝mehsana🔝 Escorts...
 
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
 
20240510 QFM016 Irresponsible AI Reading List April 2024.pdf
20240510 QFM016 Irresponsible AI Reading List April 2024.pdf20240510 QFM016 Irresponsible AI Reading List April 2024.pdf
20240510 QFM016 Irresponsible AI Reading List April 2024.pdf
 
Nanded City ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready ...
Nanded City ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready ...Nanded City ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready ...
Nanded City ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready ...
 
20240507 QFM013 Machine Intelligence Reading List April 2024.pdf
20240507 QFM013 Machine Intelligence Reading List April 2024.pdf20240507 QFM013 Machine Intelligence Reading List April 2024.pdf
20240507 QFM013 Machine Intelligence Reading List April 2024.pdf
 
VIP Model Call Girls NIBM ( Pune ) Call ON 8005736733 Starting From 5K to 25K...
VIP Model Call Girls NIBM ( Pune ) Call ON 8005736733 Starting From 5K to 25K...VIP Model Call Girls NIBM ( Pune ) Call ON 8005736733 Starting From 5K to 25K...
VIP Model Call Girls NIBM ( Pune ) Call ON 8005736733 Starting From 5K to 25K...
 
20240508 QFM014 Elixir Reading List April 2024.pdf
20240508 QFM014 Elixir Reading List April 2024.pdf20240508 QFM014 Elixir Reading List April 2024.pdf
20240508 QFM014 Elixir Reading List April 2024.pdf
 
💚😋 Salem Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
💚😋 Salem Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋💚😋 Salem Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
💚😋 Salem Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
 
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls DubaiDubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
 
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
 
💚😋 Bilaspur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
💚😋 Bilaspur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋💚😋 Bilaspur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
💚😋 Bilaspur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
 
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort ServiceBusty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
 
Sarola * Female Escorts Service in Pune | 8005736733 Independent Escorts & Da...
Sarola * Female Escorts Service in Pune | 8005736733 Independent Escorts & Da...Sarola * Female Escorts Service in Pune | 8005736733 Independent Escorts & Da...
Sarola * Female Escorts Service in Pune | 8005736733 Independent Escorts & Da...
 
Hire↠Young Call Girls in Tilak nagar (Delhi) ☎️ 9205541914 ☎️ Independent Esc...
Hire↠Young Call Girls in Tilak nagar (Delhi) ☎️ 9205541914 ☎️ Independent Esc...Hire↠Young Call Girls in Tilak nagar (Delhi) ☎️ 9205541914 ☎️ Independent Esc...
Hire↠Young Call Girls in Tilak nagar (Delhi) ☎️ 9205541914 ☎️ Independent Esc...
 
Pune Airport ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready...
Pune Airport ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready...Pune Airport ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready...
Pune Airport ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready...
 

Www sociam-2016-policy-reviews

  • 1. Privacy Languages: Are we there yet to enable user controls? Jun Zhao, Reuben Binns, Max Van Kleek and Nigel Shadbolt Personal Data and Privacy Lab Department of Computer Science University of Oxford Dominic Difranzo ECS, Faculty of Physical Sciences and Engineering University of Southampton
  • 2. Outline ● Motivation ● Methodology ● Preliminary results ● Future work
  • 3. Motivation Personal data is one of the most valuable commodities ● The revenue of digital advertising in the EU in 2014 is estimated to be €30.7bn1 However, ● Users have limited knowledge about how their data are used ● Users have no control of how they expect their data to be used 1. Interactive Advertising Bureau AdEx Benchmark research, http://www.iabuk.net/about/press/archive/eu-online-advertising-reaches-landmark-307bn
  • 4. Tracking is ubiquitous ● There is 99.5% chance that a user will become tracked by all top 10 trackers within 30 clicks on top search results. (Gomer et al 2013) ● Users have little awareness and control https://www.mozilla.org/en-US/lightbeam/ http://research.microsoft.com/apps/pubs/default.aspx? id=201586
  • 5. Beyond the web Web browsing is just part of a wider sphere of potential privacy harms, including: - Employment - Health - Finance - Consumer spending How can people express their wishes about the use of their personal data in these domains?
  • 6. An example scenario: sharing of medical data Users - Want controls E.g, no commercial use - Limited time + capacity to read and process notifications Information controller - Show commitment E.g research purpose only - Act according to socially and/or legally binding agreements
  • 7. Existing privacy enhancement approaches ● Organisation-centric approaches ○ Structured privacy policy from information controllers, like P3P (https://www.w3.org/P3P/) ○ Standardisation effort: Do Not Track, and P3P ● User-centric approaches ○ More usable privacy notifications, like privacy nutrition labels ○ Browser plug-in developments, e.g. Mozilla Privacy Icons, ToS;DR ○ Privacy preference languages Credit of privacy nutrition label to: https://cups.cs.cmu.edu/privacyLabel/files/CHI-privacyFinal2010
  • 8. Users remain the weak points Users Control remains a weak point - A lot of past efforts - But little uptake - Why? Information controller - Show commitment - Act on social and legal binding
  • 9. Our privacy language review Privacy languages ● A declarative language for specifying both users’ privacy preferences and information controllers’ privacy policies in a machine-readable way+ Existing reviews ● Kumaraguru et al 2007 and Kolter 2009: focused on the purpose of languages only ● Belanger and Crossler 2011: a review of privacy in Management Information Systems ● Kasem-Madani and Meier 2015: more focus on security Our goal ● A user-centric review: focusing on the support for users, instead of organisations ● Gaining insights on design a user-centric language that is easy-to-use + Becker et al. Practical Generic Privacy Language. Information Systems Security. Springer Berlin Heidelberg, 2010. 125-139.
  • 10. Methodology of the review ● 18 privacy languages from existing review literature ● Limited to academic efforts ● Eliminated those languages that describe access control only ● 10 languages in the review ● Assessment through 3 dimensions ○ Their design purpose ○ Their user-facing tooling support ○ Their consideration of interoperability
  • 12. Purpose of the languages
  • 13. Purpose of the languages ● More emphasis on information controllers (i.e. through policy languages), than users (i.e. through preference languages) ● Some preference languages are too simple, and with limited expressivity ● Other preference languages are way too complicated to be used by end users ● Nothing we can use off-the-shelf
  • 14. Tooling support ● Motivation ○ Easy-to-use user facing tool is critical for adoptions of any proposed languages ○ Been shown as a critical barrier to the adoptions of standards like P3P ● Observations ○ Very few languages come with a user-facing tool (3 out of 10) ○ Very limited usability studies (except one tool) to ensure that these tools are truly usable for the end users ●
  • 15. Interoperability ● Motivation ○ Privacy is a ubiquitous issue, given the fast development of mobile devices and IoTs ○ Privacy languages from different devices, users and platforms must be interchangeable ● Observations ○ Pros: Languages are defined in standard formats, like XML or RDF ○ Cons: standardisation efforts (like P3P) have failed, with the lack of social agreements and legal enforcements
  • 16. Reflections ● Strengths ○ Extensive understanding on privacy scenarios and challenges ● Weaknesses ○ Existing languages are either too complicated for normal web users or too simplistic to cope with the diverse requirements ○ Limited tooling development for end users
  • 17. Future work ● A first-step towards user-centric privacy --- enabling users to gain control ● Easy-to-use privacy preference language ● Easy-to-use user-facing tools ● Tracking breakage of terms on a decentralised Web (of Things)