Mobile apps frequently request excessive data access, raising significant privacy concerns. While regulations like GDPR emphasize data minimization, they provide limited guidance on concretely defining and enforcing necessary data access. Existing regulatory mechanisms primarily rely on expert-driven audits that face challenges in scalability, neutrality, and alignment with user expectations. In this paper, we propose a novel paradigm--democratizing privacy assessment, inspired by prior work on user-centric privacy perceptions--which repositions users as active evaluators in the privacy auditing process, recognizing that user perceptions of data usage play a crucial role in assessing the appropriateness and necessity of data access. To operationalize this paradigm, we introduce DePRa, a prototype system developed through participatory design, featuring contextual explanation provision, category-based representative selection, an intuitive rating interface, and preference-based rating adjustment. We evaluated DePRa with 200 everyday mobile app users, analyzing how effectively it captures user opinions on sensitive data access, comparing their privacy ratings with expert assessments, and exploring risk preference-based score calibration. Our findings show the feasibility and promise of democratized privacy assessment, highlighting its potential to complement expert auditing and support inclusive privacy evaluation.
翻译:移动应用频繁请求超出必要的数据访问权限,引发严重的隐私担忧。尽管通用数据保护条例等法规强调数据最小化原则,但在具体定义和实施必要数据访问方面提供的指导有限。现有监管机制主要依赖专家主导的审查,面临可扩展性、中立性以及与用户期望契合度的挑战。本文提出一种新范式——民主化隐私评估,其灵感源于以用户为中心的隐私感知相关研究,将用户重新定位为隐私审计过程中的主动评估者,认识到用户对数据使用的感知在评估数据访问的适当性和必要性中发挥关键作用。为落实这一范式,我们通过参与式设计开发了原型系统DePRa,该系统具备情境化解释提供、基于类别的代表性选择、直观的评级界面以及基于偏好的评分调整功能。我们通过对200名普通移动应用用户进行实证评估,分析了该系统捕捉用户对敏感数据访问看法的有效性,比较了用户隐私评级与专家评估的差异,并探索了基于风险偏好的评分校准方法。研究结果表明,民主化隐私评估具备可行性和发展前景,有望补充专家审计机制,支持包容性隐私评估体系。