Towards the access to information regarding the Personal Data Handling: A proposal for improvement and simplification of Privacy and Security Policies

Resumo


The emergence of data-driven business models has boosted computational activities supported by the manipulation of personal data, as their capacity to generate information about people (users), their habits and preferences is enormous. Regulations, such as the European Union's General Data Protection Regulation (GPDR) and the Brazilian government's "Lei Geral de Proteção de Dados" (LGPD), require that data subjects receive clear information about the manipulation of their data. However, this information is often contained in long and complex privacy policies, making it difficult for users to access and understand. To ensure Personal Data Transparency, this information must be presented clearly and objectively, facilitating discovery, analysis, and decision-making by data subjects. This work proposes and evaluates a Human-Computer Interaction strategy to improve Personal Data Transparency and promote access to and understanding information by data subjects. Given the difficulties encountered in Privacy Policies, this simplified strategy was proposed, based on User-Centered Design and TR-Model guidelines, to facilitate the access and the use of information. The evaluation of the prototypes involved 42 participants and resulted in a positive score of 77 on the System Usability Scale (SUS). Although the feedback was mostly favorable, the need to improve the consistency of the information presented was highlighted due to the variation between simple and complex data.

Palavras-chave: Simplified Strategy, Personal Data Transparency, Privacy Policies, User-Centered Design

Referências

Alvin Wang, Alan Chang, Alex Mark, and Kevin Louie. 2024. Materialize: A modern responsive front-end framework based on Material Design. Retrieved 2021-05-13 from [link]

Maria Cecília C Baranauskas, Clarisse Sieckenius De Souza, and Roberto Pereira. 2014. I grandihc-br—grandes desafios de pesquisa em interaçao humano-computador no brasil. Relatório Técnico. Comissão Especial de Interação Humano-Computador (CEIHC) da Sociedade Brasileira de Computação (SBC) (2014), 27–30.

Bojana Bellamy and Chema Alonso. 2016. Reframing data transparency. Technical Report. Centre for Information Policy Leadership and Telefónica Senior Roundtable.

Christoph Bier, Kay Kühne, and Jürgen Beyerer. 2016. PrivacyInsight: The Next Generation Privacy Dashboard. In Privacy Technologies and Policy, Stefan Schiffner, Jetzabel Serna, Demosthenes Ikonomou, and Kai Rannenberg (Eds.). Springer International Publishing, Cham, 135–152.

Piero Bonatti, Sabrina Kirrane, Axel Polleres, and Rigo Wenning. 2017. Transparent Personal Data Processing: The Road Ahead. In Computer Safety, Reliability, and Security. Springer International Publishing, Cham, 337–349.

Brasil. 2018. Lei Nº 13.709, de 14 de agosto de 2018 Lei Geral de Proteção de Dados Pessoais (LGPD). Diário Oficial [da] República Federativa do Brasil (2018). [link]

John Brooke. 1995. SUS: A ’Quick and Dirty’ Usability Scale. Usability Evaluation In Industry July (1995), 207–212. DOI: 10.1201/9781498710411-35

Ann Cavoukian and Justin B Weiss. 2012. Privacy by Design and User Interfaces : Emerging Design Criteria – Keep it User-Centric. , 15 pages.

George Chalhoub, Ivan Flechais, Norbert Nthala, Ruba Abu-Salma, and Elie Tom. 2020. Factoring User Experience into the Security and Privacy Design of Smart Home Devices: A Case Study. In Extended Abstracts of the 2020 CHI Conference on Human Factors in Computing Systems (Honolulu, HI, USA) (CHI EA ’20). Association for Computing Machinery, New York, NY, USA, 1–9. DOI: 10.1145/3334480.3382850

Wolfie Christl. 2017. How Companies Use Personal Data Against People. Automated Disadvantage, Personalized Persuasion, and the Societal Ramifications of the Commercial Use of Personal Information. Technical Report. CrackedLabs. [link]

Thiago Coleti, Pedro Corrêa, Marcelo Morandini, and Lucia Filgueiras. 2022. Desafios e propostas para Transparência de Dados Pessoais com foco nos titulares dos dados. In Anais do I Workshop Investigações em Interação Humano-Dados (Diamantina/MG). SBC, Porto Alegre, RS, Brasil, 1–6. DOI: 10.5753/wide.2022.227498

Thiago Adriano Coleti, Pedro Luiz Pizzigatti Corrêa, Lucia Vilela Leite Filgueiras, and Marcelo Morandini. 2020. TR-Model. A Metadata Profile Application for Personal Data Transparency. IEEE Access 8, 1 (2020), 75184–75209. DOI: 10.1109/ACCESS.2020.2988566

Walter de Abreu Cybis, Adriana Betiol Holts, and Richard Faust. 2015. Ergonomia e Usabilidade: Conhecimentos, Métodos e Aplicações. Novatec Editora, São Paulo. 487 pages.

Zohar Efroni, Jakob Metzger, Lena Mischau, and Marie Schirmbeck. 2019. Privacy icons: A risk-based approach to visualisation of data processing. European Data Protection Law Review 5, 3 (2019), 352–366. DOI: 10.21552/edpl/2019/3/9

European Parliament and Council of the European Union. [n. d.]. Regulation (EU) 2016/679 of the European Parliament and of the Council. [link]

Muge Fazlioglu. 2017. Transparency and the GDPR: Practical guidance and interpretive assistance from the Article 29 Working Party. Retrieved 2021-05-10 from [link]

Lucia Vilela Leite Filgueiras, Adriano da Silva Ferreira Leal, Thiago Adriano Coleti, Marcelo Morandini, Pedro Luiz Pizzigatti Corrêa, and Solange N. AlvesSouza. 2019. Keep System Status Visible: Impact of Notifications on the Perception of Personal Data Transparency. In Human-Computer Interaction. Perspectives on Design. Springer, Cham, 513–529.

Simone Fischer-Hübner, Julio Angulo, Farzaneh Karegar, and Tobias Pulls. 2016. Transparency, Privacy and Trust Technology for Tracking and Controlling My Data Disclosures: Does This Work?. In IFIP International Conference on Trust Management. [link]

M. Gharib, P. Lollini, and A. Bondavalli. 2017. A conceptual model for analyzing information quality in System-of-Systems. In 12th System of Systems Engineering Conference, SoSE 2017. DOI: 10.1109/SYSOSE.2017.7994946

Google for Developers. 2007-2024. Design para dispositivos móveis. [link]

Groen Eduard C Groen, Denis Feth, , Polst Svenja, Tolsdorf Jan, Wiefling Stephan, Iacono Luigi Lo, and Schmitt Hartmut. 2023. Achieving Usable Security and Privacy Through Human-Centered Design. Springer International Publishing, 83–113. DOI: 10.1007/978-3-031-28643-8_5

Richard Mortier Derek McAuley Jon Crowcroft Hamed Haddadi. 2013. Human-data interaction. University of Cambridge 837 (2013), 1– 9. [link]

Rex Hartson and Pardha Pyla. 2012. UX Book. Process and guidelines for ensuring a quality user experience. Morgan Kaufmann Elsevier. 973 pages.

Mahmood Hosseini, Alimohammad Shahri, Keith Phalp, and Raian Ali. 2016. Foundations for Transparency Requirements Engineering. In Proceedings of 22nd International Working Conference on Requirements Engineering: Foundation for Software Quality (REFSQ’16). 225–231. DOI: 10.1007/978-3-319-302829_15

Dandan Huang, Melanie Tory, Bon Adriel Aseniero, Lyn Bartram, Scott Bateman, Sheelagh Carpendale, Anthony Tang, and Robert Woodbury. 2015. Personal visualization and personal visual analytics. IEEE Transactions on Visualization and Computer Graphics 21, 3 (2015), 420–433. DOI: 10.1109/TVCG.2014.2359887.

Duha Ibdah, Nada Lachtar, Satya Meenakshi Raparthi, and Anys Bacha. 2021. Why Should i Read the Privacy Policy, i Just Need the Service’: A Study on Attitudes and Perceptions Toward Privacy Policies. IEEE Access 9 (2021), 166465–166487. DOI: 10.1109/ACCESS.2021.3130086

Mikhail Kuznetsov, Evgenia Novikova, Igor Kotenko, and Elena Doynikova. 2022. Privacy Policies of IoT Devices : Collection and Analysis. Sensors 22, 1838 (2022), 1–23.

Travis Lowdermilk. 2013. Design Centrado ao Usuário (1 ed.). Vol. 1. O´Relly Novatec.

Similarweb LTD. 2024. Ranking dos Sites Principais: Sites Mais Visitados do Mundo. Retrieved 2021-05-13 from [link]

Mark Otto and Jacob Thornton. 2024. Build fast, responsive sites with Bootstrap. Retrieved 2021-05-13 from [link]

Gregory Maus. 2015. Decoding, hacking, and optimizing societies: Exploring potential applications of human data analytics in sociological engineering, both internally and as offensive weapons. In Proceedings of the 2015 Science and Information Conference, SAI 2015. 538–547. DOI: 10.1109/SAI.2015.7237195

Richard Mortier, Jianxin Zhao, Jon Crowcroft, Liang Wang, Qi Li, Hamed Haddadi, Yousef Amar, Andy Crabtree, James Colley, Tom Lodge, et al. 2016. Personal data management with the databox: What’s inside the box?. In Proceedings of the 2016 ACM Workshop on Cloud-Assisted Networking. 49–54.

Patrick Murmann and Simone Fischer-Hübner. 2017. Tools for Achieving Usable Ex Post Transparency: A Survey. IEEE Access 5 (2017), 22965–22991. DOI: 10.1109/ACCESS.2017.2765539

Theresa Neil. 2014. Mobile Design Pattern Gallery (2 ed.). OReilly. 299 pages.

Dominik Pacholczyk. 2014. Mobile UI Design Patterns. A Deeper Look At the Hottest Apps Today. UXPin. 135 pages. arXiv:arXiv:1011.1669v3

Dominik Pacholczyk. 2014. Web UI Design Patterns. A Deeper Look At The Hottest Websites and Web Apps Today. UXPin. [link]

Thomas F.J.M. Pasquier and David Eyers. 2016. Information flow audit for transparency and compliance in the handling of personal data. In Proceedings 2016 IEEE International Conference on Cloud Engineering Workshops, IC2EW 2016. 112–117. DOI: 10.1109/IC2EW.2016.29

Rogério Pereira. 2019. User Experience Design. Como criar produtos digitais com foco nas pessoas. Casa do Código. 210 pages.

Robert W. Reeder, Clare-Marie Karat, John Karat, and Carolyn Brodie. 2007. Usability Challenges in Security and Privacy Policy-Authoring Interfaces. In Human-Computer Interaction – INTERACT 2007. Springer Berlin Heidelberg, Berlin, Heidelberg, 141–155.

Louis Rosenfeld, Peter Morville, and Jorge Arango. 2015. Information Architecture: For the Web and Beyond (4th ed.). O’Reilly Media, Inc.

Nayara Santos, Guilherme Schüler, Julio Sieg, Gustavo Duarte, César Marcon, Isabel Manssour, Márcio Pinho, Sabrina Marczak, and Milene Silveira. 2022. Análise e Comparação de Usabilidade em Configurações de Privacidade: um Estudo de Caso das Redes Sociais Instagram, Facebook e Twitter. In Anais Estendidos do XXI Simpósio Brasileiro de Fatores Humanos em Sistemas Computacionais (Diamantina). SBC, Porto Alegre, RS, Brasil, 108–111. DOI: 10.5753/ihc_estendido.2022.225344

Patrick Santos, Luciana Salgado, and José Viterbo. 2018. Assessing the Communicability of Human-Data Interaction Mechanisms in Transparency Enhancing Tools. In Proceedings of the 2018 Federated Conference on Computer Science and Information Systems, Vol. 15. 897–906. DOI: 10.15439/2018f174

Bruce Schneier. 2015. Data and Goliath. The Hidden Battles to Collect Your Data and Control Your World. W. W. Norton & Company. 320 pages.

Nili Steinfeld. 2016. "i agree to the terms and conditions": (How) do users read privacy policies online? An eye-tracking experiment. Computers in Human Behavior 55 (2016), 992–1000. DOI: 10.1016/j.chb.2015.09.038

Constantine Stephanidis, Gavriel Salvendy, Margherita Antona, Jessie YC Chen, Jianming Dong, Vincent G Duffy, Xiaowen Fang, Cali Fidopiastis, Gino Fragomeni, Limin Paul Fu, et al . 2019. Seven HCI grand challenges. International Journal of Human–Computer Interaction 35, 14 (2019), 1229–1269.

SUS. 2024. Conecte SUS. Retrieved 2021-05-10 from [link].

Fabricio Teixeira. 2022. Introdução e boas práticas em UX Design. Casa do Código. 262 pages.

Mariana de Toledo. 2020. Lei Geral de Proteção de Dados. um guia completo. , 32 pages.

Matteo Turilli and Luciano Floridi. 2009. The ethics of information transparency. Ethics and Information Technology 11, 2 (2009), 105–112. DOI: 10.1007/s10676-009-9187-9 arXiv:arXiv:1011.1669v3

UI Patterns Learning Loop ApS. 2007-2024. User Interface Design patterns. [link]

Eric Zeng, Shrirang Mare, and Franziska Roesner. 2019. End user security privacy concerns with smart homes. In Proceedings of the 13th Symposium on Usable Privacy and Security, SOUPS 2017. 65–80.
Publicado
07/11/2024
MARIALVA YVANO, Michel; COLETI, Thiago Adriano; DELLA MURA, Wellington Aparecido; FIORAVANTE, Carla Carolina; MOREIRA DE SOUZA, Maria Luiza; AMADEU TEIXEIRA, Larissa; MORANDINI, Marcelo. Towards the access to information regarding the Personal Data Handling: A proposal for improvement and simplification of Privacy and Security Policies. In: SIMPÓSIO BRASILEIRO SOBRE FATORES HUMANOS EM SISTEMAS COMPUTACIONAIS (IHC), 23. , 2024, Brasília/DF. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2024 . p. 435-445.