Privacy Policies over Time: Curation and Analysis of a Million-Document Dataset
Ryan Amos, Gunes Acar, Elena Lucherini, Mihir Kshirsagar, Arvind Narayanan, Jonathan R. Mayer
Abstract
Automated analysis of privacy policies has proved a fruitful research direction, with developments such as automated policy summarization, question answering systems, and compliance detection. Prior research has been limited to analysis of privacy policies from a single point in time or from short spans of time, as researchers did not have access to a large-scale, longitudinal, curated dataset. To address this gap, we developed a crawler that discovers, downloads, and extracts archived privacy policies from the Internet Archive's Wayback Machine. Using the crawler and following a series of validation and quality control steps, we curated a dataset of 1,071,488 English language privacy policies, spanning over two decades and over 130,000 distinct websites. Our analyses of the data paint a troubling picture of the transparency and accessibility of privacy policies. By comparing the occurrence of tracking-related terminology in our dataset to prior web privacy measurements, we find that privacy policies have consistently failed to disclose the presence of common tracking technologies and third parties. We also find that over the last twenty years privacy policies have become even more difficult to read, doubling in length and increasing a full grade in the median reading level. Our data indicate that self-regulation for first-party websites has stagnated, while self-regulation for third parties has increased but is dominated by online advertising trade associations. Finally, we contribute to the literature on privacy regulation by demonstrating the historic impact of the GDPR on privacy policies.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e95f32e6-bc35-4291-a109-982925179127Cited by top-tier papers23
- Investigating Deceptive Design in GDPR's Legitimate InterestLin Kyi, Sushil Ammanaghatta Shivakumar, Cristiana Teixeira Santos, Franziska Roesner et al.CHI 2023 · 32 citations
- A NEW HOPE: Contextual Privacy Policies for Mobile Applications and An Approach Toward Automated GenerationShidong Pan, Zhen Tao, Thong Hoang, Dawen Zhang et al.USENIX Security 2024 · 24 citations
- Is It a Trap? A Large-scale Empirical Study And Comprehensive Assessment of Online Automated Privacy Policy Generators for Mobile AppsShidong Pan, Dawen Zhang, Mark Staples, Zhenchang Xing et al.USENIX Security 2024 · 18 citations
- SoK: Technical Implementation and Human Impact of Internet Privacy RegulationsEleanor Birrell, Jay Rodolitz, Angel Ding, Jenna Lee et al.S&P 2024 · 11 citations
- A Study of GDPR Compliance under the Transparency and Consent FrameworkMichael Smith, Antonio Torres-Agüero, Riley Grossman, Pritam Sen et al.WWW 2024 · 9 citations
Builds on8
- Online Tracking: A 1-million-site Measurement and AnalysisSteven Englehardt, Arvind NarayananCCS 2016 · 798 citations
- Polisis: Automated Analysis and Presentation of Privacy Policies Using Deep LearningHamza Harkous, Kassem Fawaz, Rémi Lebret, Florian Schaub et al.USENIX Security 2018 · 400 citations
- Internet Jones and the Raiders of the Lost Trackers: An Archaeological Study of Web Tracking from 1996 to 2016Ada Lerner, Anna Kornfeld Simpson, Tadayoshi Kohno, Franziska RoesnerUSENIX Security 2016 · 273 citations
- "It's a scavenger hunt": Usability of Websites' Opt-Out and Data Deletion ChoicesHana Habib, Sarah Pearman, Jiamin Wang, Yixin Zou et al.CHI 2020 · 113 citations
- Finding a Choice in a Haystack: Automatic Extraction of Opt-Out Statements from Privacy Policy TextVinayshekhar Bannihatti Kumar, Roger Iyengar, Namita Nisal, Yuanyuan Feng et al.WWW 2020 · 93 citations
Related papers
- C3PA: An Open Dataset of Expert-Annotated and Regulation-Aware Privacy Policies to Enable Scalable Regulatory Compliance AuditsMaaz Bin Musa, Steven M. Winston, Garrison Allen, Jacob Schiller et al.EMNLP 2024 · 3 citations
- Evaluating Privacy Policies under Modern Privacy Laws At Scale: An LLM-Based Automated ApproachQinge Xie, Karthik Ramakrishnan, Frank LiUSENIX Security 2025
- We Value Your Privacy ... Now Take Some Cookies: Measuring the GDPR's Impact on Web PrivacyMartin Degeling, Christine Utz, Christopher Lentzsch, Henry Hosseini et al.NDSS 2019
- Privacy at Scale: Introducing the PrivaSeer Corpus of Web Privacy PoliciesMukund Srinath, Shomir Wilson, C. Lee GilesACL 2021
- Have You been Properly Notified? Automatic Compliance Analysis of Privacy Policy Text with GDPR Article 13Shuang Liu, Baiyang Zhao, Renjie Guo, Guozhu Meng et al.WWW 2021 · 68 citations
