Asking for Privacy: Contrasting Consumer Questions with Questions in Privacy Policies
Abstract
Privacy policies are text documents intended to inform consumers about the data practices of apps and websites, but they can be challenging to read. Some organizations try to address the obstacles by organizing their privacy policies as question-answer pairs. We use a combination of automated and manual analysis methods to compare two corpora: PrivaSeerQA, a corpus we create and release consisting of 1.2 million question-answer pairs extracted from 345,073 privacy policies, and PrivacyQA, a previously released corpus of 1,750 questions people ask about app privacy. We find a mixture of thematic overlaps (e.g., data types and data uses) and divergences (e.g., levels of granularity and the issue of location tracking). We also find that privacy policies have a greater focus on the visibility of data, while users have a greater focus on their data being sold. The contrasts suggest that QA-structured privacy policies still do not fully meet consumers' needs, although the structure clarifies what specific topics of user interest are missing.