Am I Private and If So, how Many?: Communicating Privacy Guarantees of Differential Privacy with Risk Communication Formats
Daniel Franzen, Saskia Nuñez von Voigt, Peter Sörries, Florian Tschorsch, Claudia Müller-Birn
Abstract
Every day, we have to decide multiple times, whether and how much personal data we allow to be collected. This decision is not trivial, since there are many legitimate and important purposes for data collection, for examples, the analysis of mobility data to improve urban traffic and transportation. However, often the collected data can reveal sensitive information about individuals. Recently visited locations can, for example, reveal information about political or religious views or even about an individual's health. Privacypreserving technologies, such as differential privacy (DP), can be employed to protect the privacy of individuals and, furthermore, provide mathematically sound guarantees on the maximum privacy risk. However, they can only support informed privacy decisions, if individuals understand the provided privacy guarantees. This article proposes a novel approach for communicating privacy guarantees to support individuals in their privacy decisions when sharing data. For this, we adopt risk communication formats from the medical domain in conjunction with a model for privacy guarantees of DP to create quantitative privacy risk notifications. We conducted a crowd-sourced study with 343 participants to evaluate how well our notifications conveyed the privacy risk information and how confident participants were about their own understanding of the privacy risk. Our findings suggest that these new notifications can communicate the objective information similarly well to currently used qualitative notifications, but left individuals less confident in their understanding. We also discovered that several of our notifications and the currently used qualitative notification disadvantage individuals with low numeracy: these individuals appear overconfident compared to their actual understanding of the associated privacy risks and are, therefore, less likely to seek the needed additional information before an informed decision. The promising results allow for multiple directions in future research, for example, adding visual aids or tailoring privacy risk communication to characteristics of the individuals.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers8
- Prior-itizing Privacy: A Bayesian Approach to Setting the Privacy Budget in Differential PrivacyZeki Kazan, Jerome P. ReiterNeurIPS 2024 · 23 citations
- Attack-Aware Noise Calibration for Differential PrivacyBogdan Kulynych, Juan Felipe Gómez, Georgios Kaissis, Flávio P. Calmon et al.NeurIPS 2024 · 23 citations
- Unifying Re-Identification, Attribute Inference, and Data Reconstruction Risks in Differential PrivacyBogdan Kulynych, Juan Felipe Gómez, Georgios Kaissis, Jamie Hayes et al.NeurIPS 2025 · 15 citations
- "Having Confidence in My Confidence Intervals": How Data Users Engage with Privacy-Protected Wikipedia DataHarold Triedman, Jayshree Sarathy, Priyanka Nanayakkara, Rachel Cummings et al.CHI 2026 · 2 citations
- Comprehension from Chaos: Towards Informed Consent for Private ComputationBailey Kacsmar, Vasisht Duddu, Kyle Tilbury, Blase Ur et al.CCS 2023 · 2 citations
Builds on6
- Polisis: Automated Analysis and Presentation of Privacy Policies Using Deep LearningHamza Harkous, Kassem Fawaz, Rémi Lebret, Florian Schaub et al.USENIX Security 2018 · 400 citations
- Quantifying the Invisible Labor in Crowd WorkCarlos Toxtli, Siddharth Suri, Saiph SavageCSCW 2021 · 91 citations
- Towards Effective Differential Privacy Communication for Users' Data Sharing Decision and ComprehensionAiping Xiong, Tianhao Wang, Ninghui Li, Somesh JhaS&P 2020 · 72 citations
- "I need a better description": An Investigation Into User Expectations For Differential PrivacyRachel Cummings, Gabriel Kaptchuk, Elissa M. RedmilesCCS 2021 · 45 citations
- Exploring Design and Governance Challenges in the Development of Privacy-Preserving ComputationNitin Agrawal, Reuben Binns, Max Van Kleek, Kim Laine et al.CHI 2021 · 37 citations
Related papers
- Communicating the Privacy-Utility Trade-off: Supporting Informed Data Donation with Privacy Decision Interfaces for Differential PrivacyDaniel Franzen, Claudia Müller-Birn, Odette WegwarthCSCW 2024 · 11 citations
- What Are the Chances? Explaining the Epsilon Parameter in Differential PrivacyPriyanka Nanayakkara, Mary Anne Smart, Rachel Cummings, Gabriel Kaptchuk et al.USENIX Security 2023
- Casual Users and Rational Choices within Differential PrivacyNarges Ashena, Oana Inel, Badrie L. Persaud, Abraham BernsteinS&P 2024 · 3 citations
- TransRisk: Mobility Privacy Risk Prediction based on Transferred KnowledgeXiaoyang Xie, Zhiqing Hong, Zhou Qin, Zhihan Fang et al.UbiComp 2022 · 1 citation
- Supporting Informed Self-Disclosure: Design Recommendations for Presenting AI-Estimates of Privacy Risks to UsersIsadora Krsek, Meryl Ye, Wei Xu, Alan Ritter et al.CHI 2026 · 1 citation
