A Theory of Vagueness and Privacy Risk Perception

被引:31
|
作者
Bhatia, Jaspreet [1 ]
Breaux, Travis D. [1 ]
Reidenberg, Joel R. [2 ]
Norton, Thomas B. [2 ]
机构
[1] Carnegie Mellon Univ, Inst Software Res, Pittsburgh, PA 15213 USA
[2] Fordham Univ, Sch Law, Ctr Law & Informat Policy, New York, NY 10023 USA
基金
美国国家科学基金会;
关键词
vagueness; hedging; natural language processing; privacy; risk perception; REQUIREMENTS;
D O I
10.1109/RE.2016.20
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Ambiguity arises in requirements when a statement is unintentionally or otherwise incomplete, missing information, or when a word or phrase has more than one possible meaning. For web-based and mobile information systems, ambiguity, and vagueness in particular, undermines the ability of organizations to align their privacy policies with their data practices, which can confuse or mislead users thus leading to an increase in privacy risk. In this paper, we introduce a theory of vagueness for privacy policy statements based on a taxonomy of vague terms derived from an empirical content analysis of 15 privacy policies. The taxonomy was evaluated in a paired comparison experiment and results were analyzed using the Bradley-Terry model to yield a rank order of vague terms in both isolation and composition. The theory predicts how vague modifiers to information actions and information types can be composed to increase or decrease overall vagueness. We further provide empirical evidence based on factorial vignette surveys to show how increases in vagueness will decrease users' acceptance of privacy risk and thus decrease users' willingness to share personal information.
引用
收藏
页码:26 / 35
页数:10
相关论文
共 50 条