Privacy Rating: A User-Centered Approach for Visualizing Data Handling Practices of Online Services

Susanne Barth University of Twente ; Dan Ionita University of Twente ; Menno de Jong ; Pieter Hartel University of Twente ; Marianne Junger University of Twente

Abstract

<roman><b>Background:</b></roman> Many countries mandate transparency and consent when personal data are handled by online services. However, most users do not read privacy policies or cannot understand them. An important challenge for technical communicators is empowering users to manage their online privacy responsibly. <roman><b>Literature review:</b></roman> Research suggests that privacy visualizations may alleviate this problem, but existing approaches are incomplete and under-researched. <roman><b>Research questions:</b></roman> 1. How can we design a privacy rating that optimally empowers users with different levels of knowledge about and awareness of online privacy? 2. How do users react to such a privacy rating, in terms of usability, perceived usefulness, and trust in online services? <roman><b>Methodology:</b></roman> We developed Privacy Rating, a tool for mapping and visualizing the privacy of online services. The tool was subjected to user research (N = 30) focusing on usability, perceived usefulness, and effects on trust. To establish the effects on trust, participants were exposed to a website with either a positive or a negative privacy rating. <roman><b>Results:</b></roman> The Privacy Rating appeared to be usable and useful for lay users, and it had a significant effect on users’ trust in the online service. Users indicated that they would like the visualization to become an established standard, preferably approved by an independent organization. <roman><b>Conclusions:</b></roman> The Privacy Rating is a user-friendly privacy visualization covering all relevant aspects of privacy. We aim to bring the tool to the market and make it a standard, ideally supported by an independent trustworthy organization.

Journal
IEEE Transactions on Professional Communication
Published
2021-12-01
DOI
10.1109/tpc.2021.3110617
CompPile
Open Access
OA PDF Hybrid
Topics
Export

Citation Context

Cited by in this index (1)

  1. IEEE Transactions on Professional Communication

References (70) · 3 in this index

  1. 10.1145/2808117.2808119
  2. (2011 Jan.). Privacy by design. The 7 foundational principles. Tech. rep. (revised versio…
  3. 10.1007/3-540-45427-6_23
  4. 10.1108/ITP-08-2017-0241
  5. 10.21552/edpl/2019/3/9
Show all 70 →
  1. Communicating compliance: Developing a GDPR privacy label
    Proc 24th Am Conf Inf Syst
  2. 10.1145/3180445.3180447
  3. 10.1016/j.tele.2017.04.013
  4. 10.5210/fm.v11i9.1394
  5. Regulation (eu) 2016/679 of the european parliament and of the council of 27 april 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing directive 95/46/ec
  6. 10.1007/978-3-030-45691-7_75
  7. (2011). Privacy icons. Mozilla Wiki.
  8. Privacy short notice design
  9. (2011). PrimeLife&#x2014;Privacy and identity management in Europe for life: Final HCI Re…
  10. Privacy Label. Blog series part I-IV. Sensor lab
  11. 10.1145/3025453.3025556
  12. Upgrade Your Privacy Statement Privacy Label Helps You Communicate How You Use Data
  13. DAPIS: An ontology-based data protection icon set
    Knowledge of the Law in the Big Data Age
  14. Putting privacy pictograms into practice. A European perspective
    Informatik 2009&#x2013;Im Focus das Leben
  15. 10.1162/DAED_a_00113
  16. 10.1109/CyberSA.2018.8551442
  17. 10.1515/til-2019-0008
  18. Regulation (EU) 2017/1369 of the European Parliament and of the Council of 4 July 2017 Setting a Framework For Energy Labelling and Repealing Directive 2010/30/EU Legislation OJ L 198 28 7 2017
  19. Energy Label Templates
  20. 10.1111/j.1745-6606.2004.tb00865.x
  21. 10.1038/scientificamerican0501-34
  22. 10.1007/978-3-642-20769-3_27
  23. 10.5210/fm.v17i7.4010
  24. 10.1007/978-3-642-20317-6_15
  25. (2014-2015). The use of privacy icons and standard contract terms for generating consumer…
  26. A brief evaluation of icons in the first reading of the European Parliament on COM (2012) 0011
    Privacy and Identity Management for the Future Internet in the Age of Globalisation
  27. 10.1109/CeDEM.2017.23
  28. 10.1007/978-3-319-46963-8_4
  29. 10.1086/688405
  30. 10.1111/j.1745-6606.2006.00071.x
  31. KnowPrivacy
  32. Iconset for data-privacy declarations. v0.1.
  33. Understanding online privacy: A systematic review of privacy visualizations and privacy b…
  34. 10.1016/j.jbusres.2019.11.084
  35. Privacy awareness: A means to solve the privacy paradox?
    The Future of Identity
  36. Addressing the privacy paradox by expanded privacy awareness. The example of context-awar…
    Privacy and Identity Management for Life
  37. Journal of Business and Technical Communication
  38. Functional analysis for document design
    Tech Commun
  39. 10.1145/985692.985752
  40. 10.1136/amiajnl-2013-002605
  41. Information Technology&#x2014;Security Techniques&#x2014;Privacy Framework
  42. 10.1207/s15506878jobem4903_1
  43. 10.1145/3054926
  44. 10.1016/j.dss.2016.10.002
  45. 10.1515/9781503620766
    A Theory of Cognitive Dissonance  
  46. IEEE Transactions on Professional Communication
  47. Journal of Business and Technical Communication
  48. 10.1145/1572532.1572538
  49. 10.1145/1753326.1753561
  50. 10.1016/j.copsyc.2019.08.010
  51. 10.1186/s12916-015-0444-y
  52. 10.1086/708034
  53. 10.1371/journal.pone.0173284
  54. 10.1080/10447310801937999
  55. 10.1007/978-3-319-91238-7_45
  56. Lost in privacy? Online privacy from a cybersecurity expert perspective
  57. An analysis of app privacy statements
    Issues in Inform Syst
  58. Deceived By Design How Tech Companies Use Dark Patterns to Discourage Us from Exercising Our Rights to Privacy
  59. 10.1109/MCE.2019.2953739
  60. 10.1016/j.tele.2019.03.003
  61. Toward an understanding of online privacy perceptions: Using the Q-sort method to identif…
  62. A solution, but not a panacea for defending privacy: The challenges, criticism and limita…
    Annual Privacy Forum
  63. 10.1080/13600869.2013.801589
  64. Attitudes towards privacy by design in e-government: Views from the trenches
    J Soc Administ Sci
  65. 10.1016/j.ijinfomgt.2020.102124