Investigating Deceptive Design in GDPR's Legitimate Interest
Lin Kyi, Sushil Ammanaghatta Shivakumar, Cristiana Teixeira Santos, Franziska Roesner, Frederike Zufall, Asia J. Biega
摘要
Legitimate interest is one of the six grounds for processing data under the European Union's General Data Protection Regulation (GDPR). The flexibility and ambiguity of the term "legitimate interests" can be problematic; coupled with the lack of enforcement from legal authorities and different interpretations from the various data protection authorities, legitimate interests can be taken advantage of as a loophole to collect more user data.
Drawing insights from multiple disciplines, we ran two studies to empirically investigate the deceptive designs being used when legitimate interests are applied in privacy notices, and how user perceptions line up with these practices. We identified six deceptive designs, and found that the ways legitimate interest is applied in practice does not match user expectations.
• Security and privacy → Human and societal aspects of security and privacy; • Human-centered computing → User studies; • Applied computing → Law;
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper12
- "It doesn't tell me anything about how my data is used": User Perceptions of Data Collection PurposesLin Kyi, Abraham Mhaidli, Cristiana Teixeira Santos, Franziska Roesner 等CHI 2024 · 被引用 22 次
- SoK: Technical Implementation and Human Impact of Internet Privacy RegulationsEleanor Birrell, Jay Rodolitz, Angel Ding, Jenna Lee 等S&P 2024 · 被引用 11 次
- A Study of GDPR Compliance under the Transparency and Consent FrameworkMichael Smith, Antonio Torres-Agüero, Riley Grossman, Pritam Sen 等WWW 2024 · 被引用 9 次
- Understanding Chinese Internet Users' Perceptions of, and Online Platforms' Compliance with, the Personal Information Protection Law (PIPL)Morgana Mo Zhou, Zhiyan Qu, Jinhan Wan, Bo Wen 等CSCW 2024 · 被引用 9 次
- Data Subjects' Reactions to Exercising Their Right of AccessArthur Borem, Elleen Pan, Olufunmilola Obielodan, Aurelie Roubinowitz 等USENIX Security 2024 · 被引用 7 次
它引用的顶会 Paper7
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski 等NDSS 2019 · 被引用 826 次
- Dark Patterns after the GDPR: Scraping Consent Pop-ups and Demonstrating their InfluenceMidas Nouwens, Ilaria Liccardi, Michael Veale, David R. Karger 等CHI 2020 · 被引用 491 次
- Do Cookie Banners Respect my Choice? : Measuring Legal Compliance of Banners from IAB Europe's Transparency and Consent FrameworkCélestin Matte, Nataliia Bielova, Cristiana Teixeira SantosS&P 2020 · 被引用 212 次
- Dark Patterns and the Legal Requirements of Consent Banners: An Interaction Criticism PerspectiveColin M. Gray, Cristiana Teixeira Santos, Nataliia Bielova, Michael Toth 等CHI 2021 · 被引用 175 次
- Privacy Policies over Time: Curation and Analysis of a Million-Document DatasetRyan Amos, Gunes Acar, Elena Lucherini, Mihir Kshirsagar 等WWW 2021 · 被引用 135 次
相关 Paper
- Freely Given Consent?: Studying Consent Notice of Third-Party Tracking and Its Violations of GDPR in Android AppsTrung Tin Nguyen, Michael Backes, Ben StockCCS 2022 · 被引用 32 次
- Navigating the Gray: Design Practitioners' Perceptions Toward the Implementation of Privacy Dark PatternsLeah Zhang-Kennedy, Maxwell Keleher, Michaela ValiquetteCSCW 2024 · 被引用 24 次
- "What I'm interested in is something that violates the law": Regulatory practitioner views on automated detection of deceptive design patternsArianna Rossi, Simon ParkinCHI 2026 · 被引用 1 次
- Out of Sight, Out of Mind? Exploring Data Protection Practices for Personal Data in Usable Security & Privacy StudiesFlorin Martius, Luisa Jansen, Lukas Struck, Arthi Arumugam 等CHI 2025 · 被引用 7 次
- Immersive Invaders: Privacy Threats from Deceptive Design in Virtual Reality Games and ApplicationsHilda Hadan, Michaela Valiquette, Lennart E. Nacke, Leah Zhang-KennedyCSCW 2025 · 被引用 2 次
