PolicyChecker: Analyzing the GDPR Completeness of Mobile Apps' Privacy Policies

被引:4
|
作者
Xiang, Anhao [1 ]
Pei, Weiping [2 ]
Yue, Chuan [1 ]
机构
[1] Colorado Sch Mines, Dept Comp Sci, Golden, CO 80401 USA
[2] Univ Tulsa, Sch Cyber Studies, Tulsa, OK 74104 USA
关键词
Mobile App; Privacy Policy; GDPR; Completeness;
D O I
10.1145/3576915.3623067
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The European General Data Protection Regulation (GDPR) mandates a data controller (e.g., an app developer) to provide all information specified in Articles (Arts.) 13 and 14 to data subjects (e.g., app users) regarding how their data are being processed and what are their rights. While some studies have started to detect the fulfillment of GDPR requirements in a privacy policy, their exploration only focused on a subset of mandatory GDPR requirements. In this paper, our goal is to explore the state of GDPR-completeness violations in mobile apps' privacy policies. To achieve our goal, we design the PolicyChecker framework by taking a rule and semantic role based approach. PolicyChecker automatically detects complete-ness violations in privacy policies based not only on all mandatory GDPR requirements but also on all if-applicable GDPR requirements that will become mandatory under specific conditions. Using PolicyChecker, we conduct the first large-scale GDPR-completeness violation study on 205,973 privacy policies of Android apps in the UK Google Play store. PolicyChecker identified 163,068 (79.2%) privacy policies containing data collection statements; therefore, such policies are regulated by GDPR requirements. However, the majority (99.3%) of them failed to achieve the GDPR-completeness with at least one unsatisfied requirement; 98.1% of them had at least one unsatisfied mandatory requirement, while 73.0% of them had at least one unsatisfied if-applicable requirement logic chain. We conjecture that controllers' lack of understanding of some GDPR requirements and their poor practices in composing a privacy policy can be the potential major causes behind the GDPR-completeness violations. We further discuss recommendations for app developers to improve the completeness of their apps' privacy policies to provide a more transparent personal data processing environment to users.
引用
收藏
页码:3373 / 3387
页数:15
相关论文
共 50 条
  • [1] An Analysis of Mobile Gaming Apps' Privacy Policies
    Wang, Tian
    Hayes, Carol Mullins
    Chen, Chen
    Bashir, Masooda
    [J]. 2022 IEEE GAMES, ENTERTAINMENT, MEDIA CONFERENCE (GEM), 2022,
  • [2] Privacy Policies of Mobile Apps - A Usability Study
    Anikeev, Maxim
    Shulman, Haya
    Simo, Hervais
    [J]. IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (IEEE INFOCOM WKSHPS 2021), 2021,
  • [3] The death of privacy policies: How app stores shape GDPR compliance of apps
    Kraemer, Julia
    [J]. INTERNET POLICY REVIEW, 2024, 13 (02):
  • [4] An AI-assisted Approach for Checking the Completeness of Privacy Policies Against GDPR
    Torre, Damiano
    Abualhaija, Sallam
    Sabetzadeh, Mehrdad
    Briand, Lionel
    Baetens, Katrien
    Goes, Peter
    Forastier, Sylvie
    [J]. 2020 28TH IEEE INTERNATIONAL REQUIREMENTS ENGINEERING CONFERENCE (RE'20), 2020, : 136 - 146
  • [5] Reviewing the data security and privacy policies of mobile apps for depression
    O'Loughlin, Kristen
    Neary, Martha
    Adkins, Elizabeth C.
    Schueller, Stephen M.
    [J]. INTERNET INTERVENTIONS-THE APPLICATION OF INFORMATION TECHNOLOGY IN MENTAL AND BEHAVIOURAL HEALTH, 2019, 15 : 110 - 115
  • [6] On GDPR Compliance of Companies' Privacy Policies
    Mueller, Nicolas M.
    Kowatsch, Daniel
    Debus, Pascal
    Mirdita, Donika
    Boettinger, Konstantin
    [J]. TEXT, SPEECH, AND DIALOGUE (TSD 2019), 2019, 11697 : 151 - 159
  • [7] Saving Life and Keeping Privacy: A Study on Mobile Apps for Suicide Prevention and Privacy Policies
    Reen, Jaisheen
    Friday, Aniefiok
    Orji, Rita
    [J]. PERSUASIVE TECHNOLOGY (PERSUASIVE 2022), 2022, 13213 : 190 - 207
  • [8] Before and after GDPR: tracking in mobile apps
    Kollnig, Konrad
    Binns, Reuben
    Van Kleek, Max
    Lyngs, Ulrik
    Zhao, Jun
    Tinsman, Claudine
    Shadbolt, Nigel
    [J]. INTERNET POLICY REVIEW, 2021, 10 (04): : 1 - 30
  • [9] Question Answering Models for Privacy Policies of Mobile Apps: Are We There Yet?
    Alkhattabi, Khalid
    Bird, Davita
    Miller, Kai
    Yue, Chuan
    [J]. SCIENCE OF CYBER SECURITY, SCISEC 2022, 2022, 13580 : 333 - 352
  • [10] Assessment of the Fairness of Privacy Policies of Mobile Health Apps: Scale Development and Evaluation in Cancer Apps
    Benjumea, Jaime
    Ropero, Jorge
    Rivera-Romero, Octavio
    Dorronzoro-Zubiete, Enrique
    Carrasco, Alejandro
    [J]. JMIR MHEALTH AND UHEALTH, 2020, 8 (07):