USENIX Security2019Top-tier venue
PolicyLint: Investigating Internal Privacy Policy Contradictions on Google Play
Benjamin Andow, Samin Yaseer Mahmud, Wenyu Wang, Justin Whitaker, William Enck, Bradley Reaves, Kapil Singh, Tao Xie
Abstract
Privacy policies are the primary mechanism by which companies inform users about data collection and sharing practices. To help users better understand these long and complex legal documents, recent research has proposed tools that summarize collection and sharing. However, these tools have a significant oversight: they do not account for contradictions that may occur within an individual policy. In this paper, we present PolicyLint, a privacy policy analysis tool that identifies such contradictions by simultaneously considering negation and varying semantic levels of data objects and entities. To do so, PolicyLint automatically generates ontologies from a large corpus of privacy policies and uses sentence-level natural language processing to capture both positive and negative statements of data collection and sharing. We use PolicyLint to analyze the policies of 11,430 apps and find that 14.2% of these policies contain contradictions that may be indicative of misleading statements. We manually verify 510 contradictions, identifying concerning trends that include the use of misleading presentation, attempted redefinition of common understandings of terms, conflicts in regulatory definitions (e.g., US and EU), and "laundering" of tracking information facilitated by sharing or collecting data that can be used to derive sensitive information. In doing so, PolicyLint significantly advances automated analysis of privacy policies.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers30
- Understanding Malicious Cross-library Data Harvesting on AndroidJice Wang, Yue Xiao, Xueqiang Wang, Yuhong Nan et al.USENIX Security 2021 · 41 citations
- Scrutinizing Privacy Policy Compliance of Virtual Personal Assistant AppsFuman Xie, Yanjun Zhang, Chuan Yan, Suwan Li et al.ASE 2022 · 31 citations
- Understanding IoT Security from a Market-Scale PerspectiveXin Jin, Sunil Manandhar, Kaushal Kafle, Zhiqiang Lin et al.CCS 2022 · 30 citations
- A NEW HOPE: Contextual Privacy Policies for Mobile Applications and An Approach Toward Automated GenerationShidong Pan, Zhen Tao, Thong Hoang, Dawen Zhang et al.USENIX Security 2024 · 24 citations
- Understanding GDPR Non-Compliance in Privacy Policies of Alexa Skills in European MarketplacesSong Liao, Mohammed Aldeen, Jingwen Yan, Long Cheng et al.WWW 2024 · 9 citations
Builds on2
- Polisis: Automated Analysis and Presentation of Privacy Policies Using Deep LearningHamza Harkous, Kassem Fawaz, Rémi Lebret, Florian Schaub et al.USENIX Security 2018 · 400 citations
- Automated Analysis of Privacy Requirements for Mobile AppsSebastian Zimmeck, Ziqi Wang, Lieyong Zou, Roger Iyengar et al.NDSS 2017 · 255 citations
Related papers
- PoliCond: Condition-Aware Ontology-Driven LLMs for Privacy Policy Contradiction AnalysisYalin Feng, Yifei Lu, Minxue PanASE 2025
- PoliGraph: Automated Privacy Policy Analysis using Knowledge GraphsHao Cui, Rahmadi Trimananda, Athina Markopoulou, Scott JordanUSENIX Security 2023
- Consistency Analysis of Data-Usage Purposes in Mobile AppsDuc Bui, Yuan Yao, Kang G. Shin, Jong-Min Choi et al.CCS 2021 · 41 citations
- Actions Speak Louder than Words: Entity-Sensitive Privacy Policy and Data Flow Analysis with PoliCheckBenjamin Andow, Samin Yaseer Mahmud, Justin Whitaker, William Enck et al.USENIX Security 2020
- PTPDroid: Detecting Violated User Privacy Disclosures to Third-Parties of Android AppsZeya Tan, Wei SongICSE 2023 · 20 citations
