Privacy Legislation as Business Risks: How GDPR and CCPA are Represented in Technology Companies' Investment Risk Disclosures
Richmond Y. Wong, Andrew Chong, R. Cooper Aspegren
摘要
Power exercised by large technology companies has led to concerns over privacy and data protection, evidenced by the passage of legislation including the EU's General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). While much privacy research has focused on how users perceive privacy and interact with companies, we focus on how privacy legislation is discussed among a different set of relationships-those between companies and investors. This paper investigates how companies translate the GDPR and CCPA into business risks in documents created for investors. We conduct a qualitative document analysis of annual regulatory filings (Form 10-K) from nine major technology companies. We outline five ways that technology companies consider GDPR and CCPA as business risks, describing both direct and indirect ways that the legislation may affect their businesses. We highlight how these findings are relevant for the broader CSCW and privacy research communities in research, design, and practice. Creating meaningful privacy changes within existing institutional structures requires some understanding of the dynamics of these companies' decision-making processes and the role of capital.
CCS Concepts: • Social and professional topics → Computing / technology policy; • Security and privacy → Social aspects of security and privacy; Economics of security and privacy.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- Exploring Privacy Practices of Female mHealth Apps in a Post-Roe WorldLisa Mekioussa Malki, Ina Kaleva, Dilisha Patel, Mark Warner 等CHI 2024 · 被引用 44 次
- SoK: Technical Implementation and Human Impact of Internet Privacy RegulationsEleanor Birrell, Jay Rodolitz, Angel Ding, Jenna Lee 等S&P 2024 · 被引用 11 次
- Understanding Chinese Internet Users' Perceptions of, and Online Platforms' Compliance with, the Personal Information Protection Law (PIPL)Morgana Mo Zhou, Zhiyan Qu, Jinhan Wan, Bo Wen 等CSCW 2024 · 被引用 9 次
- Funding AI for Good: A Call for Meaningful EngagementHongjin Lin, Anna Kawakami, Catherine D'Ignazio, Kenneth Holstein 等CHI 2026 · 被引用 3 次
- "We Wanted to Do Better Than the Law": Exploring UI/UX Designers' Privacy Advocacy in PracticeKeyu Yao, Jinghui Cheng, Jin L.C. GuoCSCW 2026
它引用的顶会 Paper11
- Co-Designing Checklists to Understand Organizational Challenges and Opportunities around Fairness in AIMichael A. Madaio, Luke Stark, Jennifer Wortman Vaughan, Hanna M. WallachCHI 2020 · 被引用 428 次
- Assessing the Fairness of AI Systems: AI Practitioners' Processes, Challenges, and Needs for SupportMichael Madaio, Lisa Egede, Hariharan Subramonyam, Jennifer Wortman Vaughan 等CSCW 2022 · 被引用 149 次
- Between Subjectivity and Imposition: Power Dynamics in Data Annotation for Computer VisionMilagros Miceli, Martin Schuessler, Tianling YangCSCW 2020 · 被引用 148 次
- The Politics of Privacy Theories: Moving from Norms to VulnerabilitiesNora McDonald, Andrea ForteCHI 2020 · 被引用 119 次
- Seeing Like a Toolkit: How Toolkits Envision the Work of AI EthicsRichmond Y. Wong, Michael A. Madaio, Nick MerrillCSCW 2023 · 被引用 108 次
相关 Paper
- Encoding Privacy: Sociotechnical Dynamics of Data Protection Compliance WorkRohan GroverCHI 2024 · 被引用 8 次
- Powerful Privacy Norms in Social Network DiscourseNora McDonald, Andrea ForteCSCW 2021 · 被引用 28 次
- Protecting Privacy in Software Logs: What Should Be Anonymized?Roozbeh Aghili, Heng Li, Foutse KhomhFSE 2025 · 被引用 7 次
- Understanding Users' Security and Privacy Concerns and Attitudes Towards Conversational AI PlatformsMutahar Ali, Arjun Arunasalam, Habiba FarrukhS&P 2025
- C3PA: An Open Dataset of Expert-Annotated and Regulation-Aware Privacy Policies to Enable Scalable Regulatory Compliance AuditsMaaz Bin Musa, Steven M. Winston, Garrison Allen, Jacob Schiller 等EMNLP 2024 · 被引用 3 次
