Privacy tools often miss root causes of real world harms

Enhancing Privacy, Neglecting Harms: An Analysis of Real-World Digital Privacy Incidents

Cryptography and SecurityComputers and Society

Summary

People use privacy tools to control their personal information, but these tools often don’t stop privacy problems from happening. The authors looked at 257 privacy incidents reported in the news to understand why. They found that even when people agree to share data, harms can still occur because of complex situations involving many parties. Also, the companies best able to stop these harms usually don’t have strong reasons to do so. This shows that current privacy technologies may need new approaches to actually prevent harm.

Privacy-enhancing technologiesPrivacy harmsInformation flowConsentData privacyMitigationIncentivesPrivacy incidents

Authors

Shannon Veitch, C. Shem, Lena Csomor, Oleksandr Dudiy, Naone Kim, Khoi Le, Lina Saha, Alexander Viand, Anwar Hithnawi, Bailey Kacsmar

Abstract

Privacy-enhancing technologies (PETs) have emerged as a technical means for providing individuals with greater control over their information. Yet despite the growing deployment of PETs, people continue to experience privacy harms. In this work, we revisit our understanding of privacy incidents and the realities of those experiencing privacy harms, to assess whether the goals and abilities of PETs are misaligned with the harms people face. For our study, we collect news articles that correspond to a sample of 257 real-world privacy incidents. We employ content analysis over the articles to develop a new information flow model that encompasses the complexity of data flows and their relation to resulting harms. We demonstrate that our model captures both established and novel aspects of privacy incidents and their mitigations. In particular, it captures why consent is often insufficient to prevent privacy violations, how harms emerge from complex interactions among multiple entities and actions, and reveals a flaw in our understanding of PETs: a focus on enabling functionalities still permits the harms inherent in those functionalities. Moreover, we find that the entities best positioned to implement harm-preventing measures for the incidents in our sample are the least incentivized to do so. Overall, our model and analysis identify limitations of privacy technology research for harm prevention and further identifies paths for transforming how we approach the advancement of these technologies.