Layered, Overlapping, and Inconsistent: A Large-Scale Analysis of the Multiple Privacy Policies and Controls of U.S. Banks
Lu Xian, Van Hong Tran, Lauren Lee, Meera Kumar, Yichen Zhang, Florian Schaub
摘要
Privacy policies are often complex. An exception is the two-page standardized notice that U.S. financial institutions must provide under the Gramm-Leach-Bliley Act (GLBA). However, banks now operate websites, mobile apps, and other services that involve complex data sharing practices that require additional privacy notices and do-not-sell opt-outs. We conducted a large-scale analysis of how U.S. banks implement privacy policies and controls in response to GLBA; other federal privacy policy requirements; and the California Consumer Privacy Act (CCPA), a key example for U.S. state privacy laws. We focused on the disclosure and control of a set of especially privacy-invasive practices: third-party data sharing for marketing-related purposes. We collected privacy policies for the 2,067 largest U.S. banks, 45.2% of which provided multiple policies. Across disclosures and controls for the same bank, we identified frequent, concerning inconsistencies---53.8% of banks with multiple privacy policies indicated in GLBA notices that they do not share with third parties but disclosed sharing in other policies. This multiplicity of policies, with the inconsistencies it causes, may create consumer confusion and undermine the transparency goals of the very laws that require them. Our findings call into question whether current policy requirements, such as the GLBA notice, are achieving their intended goals in today's online banking landscape. We discuss potential avenues for reforming and harmonizing privacy policies and control requirements across federal and state laws.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper19
- Dark Patterns after the GDPR: Scraping Consent Pop-ups and Demonstrating their InfluenceMidas Nouwens, Ilaria Liccardi, Michael Veale, David R. Karger 等CHI 2020 · 被引用 491 次
- Polisis: Automated Analysis and Presentation of Privacy Policies Using Deep LearningHamza Harkous, Kassem Fawaz, Rémi Lebret, Florian Schaub 等USENIX Security 2018 · 被引用 400 次
- Do Cookie Banners Respect my Choice? : Measuring Legal Compliance of Banners from IAB Europe's Transparency and Consent FrameworkCélestin Matte, Nataliia Bielova, Cristiana Teixeira SantosS&P 2020 · 被引用 212 次
- PolicyLint: Investigating Internal Privacy Policy Contradictions on Google PlayBenjamin Andow, Samin Yaseer Mahmud, Wenyu Wang, Justin Whitaker 等USENIX Security 2019 · 被引用 185 次
- Privacy Policies over Time: Curation and Analysis of a Million-Document DatasetRyan Amos, Gunes Acar, Elena Lucherini, Mihir Kshirsagar 等WWW 2021 · 被引用 135 次
相关 Paper
- Websites' Global Privacy Control Compliance at Scale and over TimeKatherine Hausladen, Oliver Wang, Sophie Eng, Jocelyn Wang 等USENIX Security 2025 · 被引用 5 次
- Toggles, Dollar Signs, and Triangles: How to (In)Effectively Convey Privacy Choices with Icons and Link TextsHana Habib, Yixin Zou, Yaxing Yao, Alessandro Acquisti 等CHI 2021 · 被引用 73 次
- Measuring Compliance with the California Consumer Privacy Act Over Space and TimeVan Hong Tran, Aarushi Mehrotra, Marshini Chetty, Nick Feamster 等CHI 2024 · 被引用 10 次
- Dark Patterns in the Opt-Out Process and Compliance with the California Consumer Privacy Act (CCPA)Van Hong Tran, Aarushi Mehrotra, Ranya Sharma, Marshini Chetty 等CHI 2025 · 被引用 5 次
- C3PA: An Open Dataset of Expert-Annotated and Regulation-Aware Privacy Policies to Enable Scalable Regulatory Compliance AuditsMaaz Bin Musa, Steven M. Winston, Garrison Allen, Jacob Schiller 等EMNLP 2024 · 被引用 3 次
