Skip to main content
  • Conferences
  • Students
Sign in
Gold Sponsor
Silver Sponsor
Silver Sponsor
Bronze Sponsor
Media Sponsor
Media Sponsor
Industry Partner

USENIX ATC '15 button

Get more
Help Promote graphics!


  •  Twitter
  •  Facebook
  •  LinkedIn
  •  Google+
  •  YouTube
Tweets by @usenix
  • Event Code of Conduct
  • Conference Network Policy
  • Statement on Environmental Responsibility Policy
Tweet

connect with us

Authors: 

Ashwini Rao, Florian Schaub, Norman Sadeh, and Alessandro Acquisti, Carnegie Mellon University; Ruogu Kang, Facebook

Abstract: 

Online privacy policies are the primary mechanism for in- forming users about data practices of online services. In practice, users ignore privacy policies as policies are long and complex to read. Since users do not read privacy policies, their expectations regarding data practices of online services may not match a service's actual data practices. Mismatches may result in users exposing themselves to unanticipated privacy risks such as unknowingly sharing personal information with online services. One approach for mitigating privacy risks is to provide simplified privacy notices, in addition to privacy policies, that highlight unexpected data practices. However, identifying mismatches between user expectations and services' practices is challenging. We propose and validate a practical approach for studying Web users' privacy expectations and identifying mismatches with practices stated in privacy policies. We conducted a user study with 240 participants and 16 websites, and identified mismatches in collection, sharing and deletion data practices. We discuss the implications of our results for the design of usable privacy notices, service providers, as well as public policy.

Ashwini Rao, Carnegie Mellon University

Florian Schaub, Carnegie Mellon University

Norman Sadeh, Carnegie Mellon University

Alessandro Acquisti, Carnegie Mellon University

Ruogu Kang, Facebook

Open Access Media

USENIX is committed to Open Access to the research presented at our events. Papers and proceedings are freely available to everyone once the event begins. Any video, audio, and/or slides that are posted after the event are also free and open to everyone. Support USENIX and our commitment to Open Access.

BibTeX
@inproceedings {197291,
author = {Ashwini Rao and Florian Schaub and Norman Sadeh and Alessandro Acquisti and Ruogu Kang},
title = {Expecting the Unexpected: Understanding Mismatched Privacy Expectations Online},
booktitle = {Twelfth Symposium on Usable Privacy and Security (SOUPS 2016)},
year = {2016},
isbn = {978-1-931971-31-7},
address = {Denver, CO},
pages = {77--96},
url = {https://www.usenix.org/conference/soups2016/technical-sessions/presentation/rao},
publisher = {USENIX Association},
month = jun
}
Download
Rao PDF
SOUPS 2016 Errata Slip
View the slides

Presentation Audio

MP3 Download

Download Audio

  • Log in or register to post comments
  • Privacy Policy
  • Contact Us

© USENIX
EIN 13-3055038