Despite having growing awareness and concerns about privacy, technology users are often insufficiently informed of the data practices of various digital products to protect themselves. Privacy policies and privacy labels, as two conventional ways of communicating data practices, are each criticized for important limitations -- one being lengthy and filled with legal jargon, and the other oversimplified and inaccurate -- causing users significant difficulty in understanding the privacy practices of the products and assessing their impact. To mitigate those issues, we explore ways to enhance privacy labels with the relevant content in complementary sources, including privacy policy, app reviews, and community-curated privacy assessments. Our user study results indicate that perceived usefulness and trust on those information sources are personal and influenced by past experience. Our work highlights the importance of considering various information needs for privacy practice and consolidating different sources for more useful privacy solutions.
翻译:尽管技术用户对隐私的意识与担忧日益增长,他们往往对各类数字产品的数据实践了解不足,难以有效保护自身。隐私政策与隐私标签作为传达数据实践的两种传统方式,各自存在重要局限而备受批评——前者冗长且充斥法律术语,后者则过于简化且不够准确——这给用户理解产品隐私实践及其影响带来了显著困难。为缓解这些问题,我们探索通过补充来源(包括隐私政策、应用评论和社区整理的隐私评估)中的相关内容来增强隐私标签的方法。我们的用户研究表明,对这些信息源的感知有用性与信任度因人而异,并受过往经验影响。本研究强调了考虑隐私实践中的多样化信息需求以及整合不同来源以构建更有用的隐私解决方案的重要性。