Content Analysis of Privacy Policies Before and After GDPR

被引:2
|
作者
Bateni, Nastaran [1 ]
Kaur, Jasmin [1 ]
Dara, Rozita [1 ]
Song, Fei [1 ]
机构
[1] Univ Guelph, Sch Comp Sci, Guelph, ON, Canada
关键词
GDPR; content analysis; compliance; privacy policies;
D O I
10.1109/PST55820.2022.9851983
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Privacy policies are statements about how websites, applications, and any other service providers collect, use, share and manage users' data. Nowadays, the contents of privacy policies have been affected by different regulations such as the General Data Protection Regulation (GDPR), which enforces the protection of personal data and also requires privacy policies to be more transparent for readers. There is a limited understanding of how GDPR has impacted the content of privacy policies. This study presents a framework for evaluation of compliance of privacy policies with GDPR recommendations and best practices. This evaluation framework includes text feature analysis, coverage analysis, and content analysis. Our findings suggest that although GDPR enforcement has improved the content of privacy policies, many of these privacy policies do not fully satisfy GDPR requirements.
引用
收藏
页数:9
相关论文
共 50 条
  • [1] On GDPR Compliance of Companies' Privacy Policies
    Mueller, Nicolas M.
    Kowatsch, Daniel
    Debus, Pascal
    Mirdita, Donika
    Boettinger, Konstantin
    TEXT, SPEECH, AND DIALOGUE (TSD 2019), 2019, 11697 : 151 - 159
  • [2] Automatic Assessment of Privacy Policies under the GDPR
    Sanchez, David
    Viejo, Alexandre
    Batet, Montserrat
    APPLIED SCIENCES-BASEL, 2021, 11 (04): : 1 - 11
  • [3] The Effect of the GDPR on Privacy Policies: Recent Progress and Future Promise
    Zaeem, Razieh Nokhbeh
    Barber, K. Suzanne
    ACM TRANSACTIONS ON MANAGEMENT INFORMATION SYSTEMS, 2021, 12 (01)
  • [4] PolicyChecker: Analyzing the GDPR Completeness of Mobile Apps' Privacy Policies
    Xiang, Anhao
    Pei, Weiping
    Yue, Chuan
    PROCEEDINGS OF THE 2023 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, CCS 2023, 2023, : 3373 - 3387
  • [5] Privacy policies, cross-border health data and the GDPR
    Mulder, T.
    Tudorica, M.
    INFORMATION & COMMUNICATIONS TECHNOLOGY LAW, 2019, 28 (03) : 261 - 274
  • [6] A GDPR Compliant Approach to Assign Risk Levels to Privacy Policies
    Alshamsan, Abdullah R.
    Chaudhry, Shafique A.
    CMC-COMPUTERS MATERIALS & CONTINUA, 2023, 74 (03): : 4631 - 4647
  • [7] Cookie Banners and Privacy Policies: Measuring the Impact of the GDPR on the Web
    Kretschmer, Michael
    Pennekamp, Jan
    Wehrle, Klaus
    ACM TRANSACTIONS ON THE WEB, 2021, 15 (04)
  • [8] Did App Privacy Improve After the GDPR?
    Petrlic, Ronald
    IEEE SECURITY & PRIVACY, 2019, 17 (06) : 31 - 36
  • [9] A Content Analysis of the Privacy Policies of Cloud Computing Services
    Gao, Lei
    Brink, Alisa G.
    JOURNAL OF INFORMATION SYSTEMS, 2019, 33 (03) : 93 - 115
  • [10] How to Make Privacy Policies both GDPR-Compliant and Usable
    Renaud, Karen
    Shepherd, Lynsay A.
    2018 INTERNATIONAL CONFERENCE ON CYBER SITUATIONAL AWARENESS, DATA ANALYTICS AND ASSESSMENT (CYBER SA), 2018,