4.6 Article

Automatic Assessment of Privacy Policies under the GDPR

Journal

APPLIED SCIENCES-BASEL
Volume 11, Issue 4, Pages -

Publisher

MDPI
DOI: 10.3390/app11041762

Keywords

privacy policies; GDPR; privacy goals; privacy assessment; machine learning

Funding

  1. European Commission [H2020-871042, H2020-101006879]
  2. Government of Catalonia [2017 SGR 705]
  3. Spanish Government [RTI2018-095094-BC21, TIN2016-80250-R]
  4. Norwegian Research Council [308904]

Ask authors/readers for more resources

This paper introduces a system that can automatically assess the compliance of privacy policies and provide clear and intuitive privacy scores to users. By using this system, users can understand the risks and severity associated with services, enabling them to make informed decisions. The proposed method has been applied to the policies of 10 well-known internet services, with results consistent with related works.
To comply with the EU General Data Protection Regulation (GDPR), companies managing personal data have been forced to review their privacy policies. However, privacy policies will not solve any problems as long as users do not read or are not able to understand them. In order to assist users in both issues, we present a system that automatically assesses privacy policies. Our proposal quantifies the degree of policy compliance with respect to the data protection goals stated by the GPDR and presents clear and intuitive privacy scores to the user. In this way, users will become immediately aware of the risks associated with the services and their severity; this will empower them to take informed decisions when accepting (or not) the terms of a service. We leverage manual annotations and machine learning to train a model that automatically tags privacy policies according to their compliance (or not) with the data protection goals of the GDPR. In contrast with related works, we define clear annotation criteria consistent with the GDPR, and this enables us not only to provide aggregated scores, but also fine-grained ratings that help to understand the reasons of the assessment. The latter is aligned with the concept of explainable artificial intelligence. We have applied our method to the policies of 10 well-known internet services. Our scores are sound and consistent with the results reported in related works.

Authors

I am an author on this paper
Click your name to claim this paper and add it to your profile.

Reviews

Primary Rating

4.6
Not enough ratings

Secondary Ratings

Novelty
-
Significance
-
Scientific rigor
-
Rate this paper

Recommended

No Data Available
No Data Available