The University of Southampton
University of Southampton Institutional Repository

Scared or naïve? An exploratory study on users perceptions of online privacy disclosures

Scared or naïve? An exploratory study on users perceptions of online privacy disclosures
Scared or naïve? An exploratory study on users perceptions of online privacy disclosures
Online service providers offer “free” services in exchange for the personal data of its users. In the last few years there has been an increase of online industry regulations requiring service providers, such as websites and app developers, to disclosure the ways in which they collect, process and use the personal data of service users. These “privacy disclosures,” such as the privacy policy, the cookie notice and, on smart phones, the app permission request, are designed with the purpose of informing users and empowering them to control their privacy. The interaction problems with these different types of disclosure are relatively well understood – habituation, inattention and cognitive biases undermine the extent to which user consent is truly informed. Users understanding of the actual content of these disclosures, and their feelings toward it, are less well understood, though. In this paper we report the results of a mixed-method exploratory study of the privacy disclosures and compare their relative merits as a starting point for the development of more meaningful consent interactions. First, we conducted a focus group study, with 21 students from the University of Southampton, to understand behavior and privacy concerns of Millenials (those born between 1982 and 2004) in response to the these three most common types of privacy disclosure. Second, we conducted an online survey, with 100 students from the University of Southampton, to study perception and feelings towards the content of the privacy disclosures. We identify three key findings. Firstly, we find heterogeneity of user perceptions and attitudes to privacy disclosures in both studies. The results of the focus groups suggests three types of users: the scared and worried about their online privacy, who think there is an option out; the naïve, who do not understand how their personal data is collected and processed by the online service providers; and the meh, who understand the trade off but are not worried about their privacy. Secondly, we find limited ability of users to infer data processing outputs and risks based on technical explanations of particular practices, suggestions of a naïve model of “cost justification” rather cost-benefit analysis by users. Finally, we show evidence of the possibility that consent interactions are valuable in themselves as a mean to improve user perceptions of a service
1645-7641
1-16
Marreiros, Helia
98fa5fe4-bdb6-4737-8a82-69dc3d1b031c
Gomer, Richard
170145a5-ed38-4f46-ab46-dd8dc956df03
Vlassopoulos, Michael
2d557227-958c-4855-92a8-b74b398f95c7
Tonin, Mirco
2929ca00-ca4e-4eb3-bf2b-a5d233b80253
schraefel, m.c.
ac304659-1692-47f6-b892-15113b8c929f
Marreiros, Helia
98fa5fe4-bdb6-4737-8a82-69dc3d1b031c
Gomer, Richard
170145a5-ed38-4f46-ab46-dd8dc956df03
Vlassopoulos, Michael
2d557227-958c-4855-92a8-b74b398f95c7
Tonin, Mirco
2929ca00-ca4e-4eb3-bf2b-a5d233b80253
schraefel, m.c.
ac304659-1692-47f6-b892-15113b8c929f

Marreiros, Helia, Gomer, Richard, Vlassopoulos, Michael, Tonin, Mirco and schraefel, m.c. (2015) Scared or naïve? An exploratory study on users perceptions of online privacy disclosures. IADIS International Journal on WWW/Internet, 13 (2), 1-16.

Record type: Article

Abstract

Online service providers offer “free” services in exchange for the personal data of its users. In the last few years there has been an increase of online industry regulations requiring service providers, such as websites and app developers, to disclosure the ways in which they collect, process and use the personal data of service users. These “privacy disclosures,” such as the privacy policy, the cookie notice and, on smart phones, the app permission request, are designed with the purpose of informing users and empowering them to control their privacy. The interaction problems with these different types of disclosure are relatively well understood – habituation, inattention and cognitive biases undermine the extent to which user consent is truly informed. Users understanding of the actual content of these disclosures, and their feelings toward it, are less well understood, though. In this paper we report the results of a mixed-method exploratory study of the privacy disclosures and compare their relative merits as a starting point for the development of more meaningful consent interactions. First, we conducted a focus group study, with 21 students from the University of Southampton, to understand behavior and privacy concerns of Millenials (those born between 1982 and 2004) in response to the these three most common types of privacy disclosure. Second, we conducted an online survey, with 100 students from the University of Southampton, to study perception and feelings towards the content of the privacy disclosures. We identify three key findings. Firstly, we find heterogeneity of user perceptions and attitudes to privacy disclosures in both studies. The results of the focus groups suggests three types of users: the scared and worried about their online privacy, who think there is an option out; the naïve, who do not understand how their personal data is collected and processed by the online service providers; and the meh, who understand the trade off but are not worried about their privacy. Secondly, we find limited ability of users to infer data processing outputs and risks based on technical explanations of particular practices, suggestions of a naïve model of “cost justification” rather cost-benefit analysis by users. Finally, we show evidence of the possibility that consent interactions are valuable in themselves as a mean to improve user perceptions of a service

Text
2015131201.pdf - Version of Record
Download (410kB)

More information

Published date: 1 May 2015
Organisations: Web & Internet Science, Agents, Interactions & Complexity, Economics

Identifiers

Local EPrints ID: 399150
URI: http://eprints.soton.ac.uk/id/eprint/399150
ISSN: 1645-7641
PURE UUID: a586b0fa-725b-4f11-a93b-23bc48b664d3
ORCID for Michael Vlassopoulos: ORCID iD orcid.org/0000-0003-3683-1466
ORCID for m.c. schraefel: ORCID iD orcid.org/0000-0002-9061-7957

Catalogue record

Date deposited: 08 Aug 2016 11:05
Last modified: 16 Mar 2024 03:55

Export record

Contributors

Author: Helia Marreiros
Author: Richard Gomer
Author: Mirco Tonin
Author: m.c. schraefel ORCID iD

Download statistics

Downloads from ePrints over the past year. Other digital versions may also be available to download e.g. from the publisher's website.

View more statistics

Atom RSS 1.0 RSS 2.0

Contact ePrints Soton: eprints@soton.ac.uk

ePrints Soton supports OAI 2.0 with a base URL of http://eprints.soton.ac.uk/cgi/oai2

This repository has been built using EPrints software, developed at the University of Southampton, but available to everyone to use.

We use cookies to ensure that we give you the best experience on our website. If you continue without changing your settings, we will assume that you are happy to receive cookies on the University of Southampton website.

×