Pith. sign in

REVIEW 3 major objections 7 minor 121 references

SoK: Three Facets of Privacy Policies

T0 review · 3 major / 7 minor · reviewed 2026-08-14 · deepseek-v4-flash

Pith's one-line read Privacy policies cannot be expressed in a single format: natural language is needed for legal validity, graphical icons for lay understanding, and machine-readable code for enforcement and audit, so all three facets must be combined.

desk verdict A genuinely useful SoK of privacy-policy representations, with a clever three-facet frame; the field-level absence claims outrun the deliberately representative corpus, and one quantitative section contradicts the main text. read the letter →

arxiv 1908.06814 v4 pith:2A6DK7XZ submitted 2019-08-19 cs.CY cs.HC

classification cs.CYcs.HC
keywords privacypoliciesnaturallanguagegraphicalmachine-readablemulti-facetedlegalcomplianceusabilityenforcement
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

Privacy policies must satisfy three requirements at once: they must be legally valid, understandable by all parties, and enforceable by machines. This paper surveys the three established ways of expressing policies—natural language, graphical icons and labels, and machine-readable policy languages—and argues that each format is tailored to one audience and therefore fails at least one of the three requirements. The central claim is that no single facet can cover all requirements, so future policies must combine all three, for example by generating graphical and machine-readable versions from a legally grounded natural-language core. If the claim is right, the practical path to compliant, usable, enforceable transparency is not choosing a format but building consistency across formats.

What carries the argument

The organizing device is the facet taxonomy: a categorization of privacy-policy expression into natural language, graphical, and machine-readable formats, overlaid on an adapted version of a prior privacy-policy taxonomy (with legal basis added as an item). This lets the authors compare what each format can express, who it serves, and what it omits, and it grounds the argument that the formats are complementary rather than interchangeable.

What would settle it

Find any published or deployed privacy-policy system that simultaneously satisfies all three requirements—recognized as legally valid by a regulator or court, comprehensible to lay users in a controlled study, and machine-enforced with audit logs—and the claim that a single facet cannot cover all requirements is disproved; conversely, surveying a larger corpus and finding only two-facet combinations would confirm it.

Watch

Extended reading notes

Core claim

The paper's core discovery is a systematized map of privacy-policy expression, organized into three facets: natural language (the only format with legal value), graphical representations (designed for lay-user comprehension), and machine-readable privacy languages (designed for automatic enforcement and auditing). Surveying representative work in each facet through a common taxonomy of policy items—first and third party collection, legal basis, data-subject rights, retention, security, policy change, and other—it finds that each facet covers at least one requirement well but neglects others. In particular, no surveyed solution combines all three facets; existing multi-faceted efforts combine at most two. The paper concludes that a single facet cannot cover all requirements, and proposes guidelines for multi-faceted policies in two styles—unified, where one core facet generates the others, and compound, where existing policies are used together with automated consistency checking.

Load-bearing premise

The paper's field-level conclusion rests on the assumption that the representative set of surveyed works is enough to establish that no existing privacy-policy solution covers all three requirements; if a tri-faceted solution exists outside that corpus, the central claim weakens.

Editorial extensions

If this is right

  • Mono-faceted policies—text-only, icon-only, or code-only—cannot simultaneously be legally valid, understandable, and enforceable, so organizations must adopt multi-faceted policies to meet all three requirements.
  • A unified multi-faceted policy should take natural language as the core facet, since it is legally mandatory, and generate machine-readable and graphical versions from it, preserving each facet's distinctive details.
  • Consistency between facets is the central engineering challenge: the machine-readable version must faithfully represent the legal text, and current manual checking cannot scale without tool support.
  • Two taxonomy items are almost entirely uncovered—legal basis and policy change—so new policy languages and icon sets should target these gaps.
  • Existing multi-faceted solutions combine at most two facets; designing a solution covering all three remains an open research direction.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • A tri-faceted policy standard could resemble a nutrition label for privacy plus a machine-readable appendix, where regulators audit the code against the text.
  • The same taxonomy-based gap analysis could be applied to emerging formats such as privacy dashboards, browser-based consent managers, or successors to earlier machine-readable standards to see which items they cover.
  • The paper's consistency challenge suggests a testable benchmark: automatically checking whether a generated graphical or machine-readable policy preserves the meaning of the natural-language original, which could be formalized as a semantic-equivalence problem.
  • If legal basis and policy change remain absent because they are hard to represent, regulators may need to prescribe standard phrasing or icons for those items rather than leaving expression open.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 7 minor

Summary. The paper systematizes privacy-policy research into three 'facets': natural-language, graphical, and machine-readable policies. It adapts an existing taxonomy (adding legal basis and grouping items), surveys representative works in each facet, and categorizes them in Tables 2 and 3. It argues that each facet serves a different audience and that mono-faceted policies cannot simultaneously satisfy legal validity, understandability, and enforceability/auditability. The paper then discusses multi-faceted policies, proposes unified and compound design approaches, and quantifies taxonomy-item coverage by facet in Figure 5 and Section 6.3.

Significance. The paper's conceptual framework and comparative tables are valuable for researchers and regulators: the three-facet decomposition is clear, the taxonomy mapping to GDPR/FIPPs/CCPA/HIPAA/COPPA is a useful reference, and the explicit study of coverage gaps (e.g., legal basis and policy change) is a concrete contribution. The manuscript is transparent about its representative scope, and the detailed tables make the authors' classifications checkable against the cited sources. However, the central absence claims and the quantitative coverage analysis need to be aligned with that scope; with those revisions, the paper would be a solid systematization contribution.

major comments (3)
  1. [Section 6.2 (see also Section 2)] The claim that 'no existing solution encompasses the requirements for legal compliance, understandability, and enforceability' is a field-level absence claim, but the paper explicitly restricts its scope to representative work and states that exhaustive analysis is 'unfeasible and undesirable' (Section 2). A representative corpus supports 'none found in the reviewed corpus,' not 'none exists.' Because this absence claim is load-bearing for the paper's main recommendation and for Section 6.1's 'single facet cannot' statement, the authors should either add a systematic search and inclusion protocol that can support the stronger claim or soften the conclusion to the reviewed corpus.
  2. [Section 6.3 and Figure 5] The heat-map percentages (e.g., Legal basis 5%/0%/95% for graphical policies) are presented as quantitative results, but the manuscript does not document the coding procedure, sample sizes, or inter-rater reliability used to classify solutions as complete, partial, or absent. These numbers underpin the 'forgotten items' discussion. Moreover, the text statement that 'legal basis and policy change are absent from all the studied work' is inconsistent with Figure 5, which shows 5% complete coverage of legal basis for graphical policies, and with Section 3.1, which says legal basis is 'regularly found' in natural-language policies. The figure should include a natural-language column (or its omission should be justified), and the text claim should be scoped accordingly.
  3. [Section 6.1] The categorical statement 'A single facet cannot cover all the requirements of privacy policies' is not established by the illustrative example of a Facebook excerpt, a Privacy Tech icon, and an APPEL-P3P fragment. That example demonstrates limitations of three particular instances, not an impossibility result over the design space of each facet. The claim should be reframed as an absence claim about the reviewed corpus, or supported by a general argument showing why any mono-faceted policy must fail at least one of the three requirements.
minor comments (7)
  1. [Section 3.1 and Table 1] 'HIPPA' should be 'HIPAA' throughout the paper.
  2. [Section 4.1] The sentence 'They present the fine-grained information in a table such as nutrition labels observed on food packaging.' is a verbatim repetition of the preceding sentence and should be removed.
  3. [Section 5.3] 'Cunche et al. [71]' is inconsistent with the reference list, where [71] is authored by Morel, Cunche, and Le Métayer; change to 'Morel et al.'
  4. [Section 5.2] The citation [24] for Rei's Prolog semantics is a general Prolog textbook; the Rei language definition [58] should be cited instead.
  5. [Tables 2 and 3] The legend symbols (e.g., 'We use to denote') do not render in the manuscript text; ensure the glyphs appear in the final PDF.
  6. [Appendix A, Table 4] 'Coarsed grained' should be 'coarse-grained.'
  7. [Sections 5 and 6] The survey uses two of the authors' own works ([71,75]) as evidence for the benefits of machine-readable and multi-faceted policies and as a representative example in Table 3. In a SoK, this conflict of interest should be acknowledged and, where possible, supplemented by independent sources.

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity: the SoK's conclusions are supported by its surveyed corpus and per-facet analysis, not by self-citation chains or by construction.

full rationale

This is a systematization paper rather than a derivation. Its central claim (Section 6.1: "A single facet cannot cover all the requirements of privacy policies") is supported by a per-facet analysis of benefits and limitations (Sections 3.3-3.4, 4.3-4.4, 5.3-5.4) and by an illustrative example comparing a Facebook policy excerpt, a Privacy Tech icon, and an APPEL-P3P fragment. That is an analytic-empirical argument about the surveyed design space, not a result that reduces by construction to its own premises. The taxonomy in Section 2 is adapted from Wilson et al. with the authors' own addition of "legal basis"; adding a category that reflects observed natural-language practice is a modeling choice, not a circular derivation. The paper does cite the authors' own PILOT [75] and consent-framework [71] works as representative machine-readable/multi-faceted solutions and as examples of enforcement/auditability benefits. These self-citations are real and peer-reviewed, but they are not load-bearing: the field-level absence claim in Section 6.2 ("no existing solution encompasses the requirements for legal compliance, understandability, and enforceability") rests on the whole surveyed corpus and on the authors' classification of each work, not on the properties of PILOT or [71] alone; removing those two entries would not by itself change the conclusion's logic. The only substantive concerns are completeness and wording, not circularity: Section 2 explicitly limits the study to "representative work," so Section 6.2's "no existing solution" is stronger than what the sampling method can prove, and Figure 5 omits natural-language coverage even though Section 3.1 says legal basis is "regularly found" in NL policies, making Section 6.3's "absent from all the studied work" ambiguous as to facet. These are external-validity and accuracy issues, not circularity. No equation, fitted parameter, or imported uniqueness theorem is used to force the conclusions.

Assumptions & free parameters 0 free parameters · 3 assumptions · 0 invented entities

The paper is a survey, not a derivation. It has no fitted parameters and introduces no physical or mathematical entities. Its load-bearing axioms are the normative three-requirement yardstick, the completeness of the representative sampling, and the applicability of the Wilson et al. taxonomy.

assumptions (3)
  • domain assumption Privacy policies must be legally valid, understandable by all parties, and enforceable and auditable in data processing systems.
    Section 1 introduces these three requirements as the evaluation yardstick; they are normative and not derived within the paper.
  • ad hoc to paper The representative set of surveyed works is sufficient to support field-level conclusions.
    Section 2 states the paper focuses on highlighting representative work rather than providing an all-encompassing reference, yet Section 6.2 concludes that no existing solution covers all three facets.
  • domain assumption The slight variation of Wilson et al.'s taxonomy does not change its content and captures the legal requirements relevant to GDPR, FIPPs, CCPA, HIPAA, and COPPA.
    Section 2 claims the variation does not change the content and adds only legal basis; the coverage analysis in Section 6.3 depends on the taxonomy's completeness.

how reviews work

0 comments
Cite this review

Pith. "Pith review of SoK: Three Facets of Privacy Policies." pith.science (2026). https://pith.science/paper/2A6DK7XZ

@misc{pith2026190806814,
  author       = {Pith},
  title        = {Pith review of: SoK: Three Facets of Privacy Policies},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/2A6DK7XZ}},
  note         = {Machine review of arXiv:1908.06814}
}
read the original abstract

Privacy policies are the main way to obtain information related to personal data collection and processing. Originally, privacy policies were presented as textual documents. However, the unsuitability of this format for the needs of today's society gave birth to other means of expression. In this paper, we systematically study the different means of expression of privacy policies. In doing so, we have explored the three main categories, which we call facets, ie, natural language, graphical and machine-readable privacy policies. Each of these facets focuses on the particular needs of the communities they come from, ie, law experts, organizations and privacy advocates, and academics, respectively. We then analyze the benefits and limitations of each facet, and explain why solutions based on a single facet do not cover the needs of other communities. Finally, we set guidelines and discuss challenges of an approach to expressing privacy policies which brings together the benefits of each facet as an attempt to overcome their limitations.

Figures

Figures reproduced from arXiv: 1908.06814 by the authors.

Figure 1
Figure 1. Excerpt of the Privacy Tech icons Another notable example of privacy icons are the android permissions [47], created by Google. They present icons combined with simple natural language. For each application installed on a mobile phone running Android, the permission manager presents a short graphical policy. Only little information is presented (the type of data collected, and processing in recent versions, but not … view at source ↗
Figure 2
Figure 2. Example of a flow diagram in Polisis Emami-Naeini et al. [38] conduct a survey in order to rank the factors of IoT devices purchase. They determine that security and privacy were among the most important factors of purchase, and consequently developed an IoT privacy label to improve information visualization. Cranor analyzes the impact of the development of standardized mechanisms of notice and choice in [28], and m… view at source ↗
Figure 3
Figure 3. Privacy Bird 6Note that icons are considered as part of standardization efforts in [28]. Inria [PITH_FULL_IMAGE:figures/full_fig_p014_3.png] view at source ↗
Figures from the paper (3 more)
Figure 4
Figure 4. Figure 4: Works on multi-faceted privacy policies grouped by combination of facets. [PITH_FULL_IMAGE:figures/full_fig_p024_4.png]
Figure 5
Figure 5. Figure 5: Coverage of taxonomy items by different types of privacy policies, and the privacy [PITH_FULL_IMAGE:figures/full_fig_p025_5.png]
Figure 5
Figure 5. Figure 5: The three last columns list the benefits, limitations and tools of each facet. [PITH_FULL_IMAGE:figures/full_fig_p036_5.png]

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

121 extracted references · 64 canonical work pages

  1. [1]

    URL http://link.springer.com/ 10.1007/978-3-642-20317-6

    Privacy and Identity Management for Life, 2011. URL http://link.springer.com/ 10.1007/978-3-642-20317-6

  2. [2]

    URL https://www.bankinfosecurity.com/californias-new-privacy-law-its-almost- gdpr-in-us-a-11149

    California’s New Privacy Law: It’s Almost GDPR in the US, 2018-07-02. URL https://www.bankinfosecurity.com/californias-new-privacy-law-its-almost- gdpr-in-us-a-11149

  3. [3]

    Create an online store with 3dcart store builder., 2019-03-26

    3DCart. Create an online store with 3dcart store builder., 2019-03-26. URL https: //www.3dcart.com/personalized-policy.html

  4. [4]

    Privacy Commons Icon Set .:aaron.helton:., 2009

    Helton Aaron. Privacy Commons Icon Set .:aaron.helton:., 2009. URL https: //web-beta.archive.org/web/20090601215200/http://aaronhelton.wordpress.com/ 2009/02/20/privacy-commons-icon-set

  5. [5]

    Logic in access control

    Mart´ ın Abadi. Logic in access control. In Proceedings of 18th IEEE Symposium on Logic in Computer Science (LICS 2003), 22-25 June 2003, Ottawa, Canada , page 228, 2003. doi: 10.1109/LICS.2003.1210062

  6. [6]

    Multi-layered privacy notices: A better way

    Marty Abrams and Malcolm Crompton. Multi-layered privacy notices: A better way. 2 (1):1–4, 2005

  7. [7]

    An XPath-based preference language for P3P

    Rakesh Agrawal, Jerry Kiernan, Ramakrishnan Srikant, and Yirong Xu. An XPath-based preference language for P3P. In Proceedings of the 12th International Conference on World Wide Web , pages 629–639. ACM, 2003. URL http://dl.acm.org/citation.cfm?id= 775241

  8. [8]

    Waleed Ammar, Shomir Wilson, Norman Sadeh, and Noah A. Smith. Automatic catego- rization of privacy policies: A pilot study. 2012. URL http://repository.cmu.edu/lti/ 199/

Show all 121 references
  1. [9]

    Parducci, D

    Anne Anderson, Anthony Nadalin, B. Parducci, D. Engovatov, H. Lockhart, M. Kudo, P. Humenn, S. Godik, S. Anderson, S. Crocker, et al. Extensible access control markup language (xacml) version 1.0. 2003. URL http://courses.cs.vt.edu/cs5204/fall05- kafura/Papers/Security/XACML-S...

  2. [10]

    Automating the Gener- ation of Privacy Policies for Context-Sharing Applications

    Wolfgang Apolinarski, Marcus Handte, and Pedro Jose Marron. Automating the Gener- ation of Privacy Policies for Context-Sharing Applications. pages 73–80. IEEE, 2015-07. ISBN 978-1-4673-6654-0. doi: 10 .1109/IE.2015.18. URL http://ieeexplore.ieee.org/ document/7194273/

  3. [11]

    E-P3P privacy policies and privacy authorization

    Paul Ashley, Satoshi Hada, G ˜A¼nter Karjoth, and Matthias Schunter. E-P3P privacy policies and privacy authorization. In Proceedings of the 2002 ACM Workshop on Pri- vacy in the Electronic Society , pages 103–109. ACM, 2002. URL http://dl.acm.org/ citation.cfm?id=644538

  4. [12]

    Enterprise privacy authorization language (EPAL)

    Paul Ashley, Satoshi Hada, G ˜A¼nter Karjoth, Calvin Powers, and Matthias Schunter. Enterprise privacy authorization language (EPAL). 2003

  5. [13]

    A-PPL: An Accountability Policy Language

    Monir Azraoui, Kaoutar Elkhiyaoui, Melek ¨Onen, Karin Bernsmed, Anderson Santana de Oliveira, and Jakub Sendor. A-PPL: An Accountability Policy Language. In Data Privacy Management, Autonomous Spontaneous Security, and Security Assurance - 9th RR n° 9287 26 V. Morel & R. Pardo...

  6. [14]

    Principles of Model Checking

    Christel Baier and Joost-Pieter Katoen. Principles of Model Checking . MIT Press, 2008. ISBN 978-0-262-02649-9

  7. [15]

    DataTags, data handling pol- icy spaces and the tags language

    Michael Bar-Sinai, Latanya Sweeney, and Merce Crosas. DataTags, data handling pol- icy spaces and the tags language. In Security and Privacy Workshops (SPW), 2016 IEEE, pages 1–8. IEEE, 2016. URL http://ieeexplore.ieee.org/abstract/document/ 7527746/

  8. [16]

    Mitchell, and Helen Nissenbaum

    Adam Barth, Anupam Datta, John C. Mitchell, and Helen Nissenbaum. Privacy and contextual integrity: Framework and applications. In 2006 IEEE Symposium on Security and Privacy (S&P’06) , pages 15–pp. IEEE, 2006. URL http://ieeexplore.ieee.org/ xpls/abs all.jsp?arnumber=1624011

  9. [17]

    Becker, Alexander Malkis, and Laurent Bussard

    Moritz Y. Becker, Alexander Malkis, and Laurent Bussard. S4P: A generic language for specifying privacy preferences and policies. 2010. URL http://www.msr-waypoint.com/ pubs/122108/main.pdf

  10. [18]

    Customer Profile Exchange (Cpexchange) Specifica- tion

    Kathy Bohrer and Bobby Holland. Customer Profile Exchange (Cpexchange) Specifica- tion. 2000. URL http://mail.ctiforum.com/standard/standard/www.cpexchange.org/ cpexchangev1 0F.pdf

  11. [19]

    Brodie, Clare-Marie Karat, and John Karat

    Carolyn A. Brodie, Clare-Marie Karat, and John Karat. An empirical study of natu- ral language parsing of privacy policy rules using the SPARCLE policy workbench. In Proceedings of the Second Symposium on Usable Privacy and Security - SOUPS ’06 , page 8. ACM Press, 2006. ISBN ...

  12. [20]

    Searching for Privacy: Design and Implementation of a P3P-Enabled Search Engine

    Simon Byers, Lorrie Faith Cranor, Dave Kormann, and Patrick McDaniel. Searching for Privacy: Design and Implementation of a P3P-Enabled Search Engine. In David Martin and Andrei Serjantov, editors, Privacy Enhancing Technologies, volume 3424, pages 314–

  13. [21]

    F. H. Cate. The Limits of Notice and Choice. 8(2):59–62, 2010-03. ISSN 1540-7993. doi: 10/cgjkcd

  14. [22]

    The Failure of Fair Information Practice Principles

    Fred H Cate. The Failure of Fair Information Practice Principles. page 38, 2008

  15. [23]

    An unsolvable problem of elementary number theory

    Alonzo Church. An unsolvable problem of elementary number theory. American Journal of Mathematics, 58(2):345–363, 1936. ISSN 00029327, 10806377

  16. [24]

    Clocksin and Christopher S

    William F. Clocksin and Christopher S. Mellish. Programming in Prolog (4. ed.). Springer,

  17. [25]

    The CNIL’s restricted committee imposes a financial penalty of 50 Million euros against GOOGLE LLC, 2019-01-21

    CNIL. The CNIL’s restricted committee imposes a financial penalty of 50 Million euros against GOOGLE LLC, 2019-01-21. URL https://www.cnil.fr/en/cnils-restricted- committee-imposes-financial-penalty-50-million-euros-against-google-llc . Inria SoK: Three Facets of Privacy Policies 27

  18. [26]

    A machine learning solution to assess privacy policy completeness:(short paper)

    Elisa Costante, Yuanhao Sun, Milan Petkovi´ c, and Jerry den Hartog. A machine learning solution to assess privacy policy completeness:(short paper). In Proceedings of the 2012 ACM Workshop on Privacy in the Electronic Society , pages 91–96. ACM, 2012. URL http://dl.acm.org/ci...

  19. [27]

    The platform for privacy preferences 1.0 (P3P1

    Lorrie Cranor, Marc Langheinrich, Massimo Marchiori, Martin Presler-Marshall, and Joseph Reagle. The platform for privacy preferences 1.0 (P3P1. 0) specification. 16,

  20. [28]

    Necessary but not sufficient: Standardized mechanisms for pri- vacy notice and choice

    Lorrie Faith Cranor. Necessary but not sufficient: Standardized mechanisms for pri- vacy notice and choice. 10:273, 2012. URL http://heinonline.org/hol-cgi-bin/ get pdf.cgi?handle=hein.journals/jtelhtel10&section=22

  21. [29]

    Privacy Bird, 2019-03-26

    CyLab Usable Privacy and Security Laboratory. Privacy Bird, 2019-03-26. URL http: //www.privacybird.org/

  22. [30]

    Personalized Privacy Assistants for the Internet of Things

    Anupam Das, Martin Degeling, Daniel Smullen, and Norman Sadeh. Personalized Privacy Assistants for the Internet of Things. 2018, 2018. doi: 10 .1109/MPRV.2018.03367733

  23. [31]

    We Value Your Privacy

    Martin Degeling, Christine Utz, Christopher Lentzsch, Henry Hosseini, Florian Schaub, and Thorsten Holz. We Value Your Privacy ... Now Take Some Cookies: Measuring the GDPR’s Impact on Web Privacy. 2019. doi: 10/gfxgxm. URL http://arxiv.org/abs/1808.05096

  24. [32]

    Privacy Policy Online (2011), 2019-03-26

    Daniel DelPercio. Privacy Policy Online (2011), 2019-03-26. URL http:// www.PrivacyPolicyOnline.com

  25. [33]

    Expe- riences in the Logical Specification of the HIPAA and GLBA Privacy Laws

    Henry DeYoung, Deepak Garg, Limin Jia, Dilsun Kirli Kaynar, and Anupam Datta. Expe- riences in the Logical Specification of the HIPAA and GLBA Privacy Laws. In Proceedings of the 2010 ACM Workshop on Privacy in the Electronic Society, WPES 2010, Chicago, Illinois, USA, October ...

  26. [34]

    Privacy Icons, 2016-03-04

    Disconnect. Privacy Icons, 2016-03-04. URL https://web.archive.org/web/ 20160304013156/https://disconnect.me/icons

  27. [35]

    An open source privacy policy for mobile apps, 2012-07-24

    Docracy. An open source privacy policy for mobile apps, 2012-07-24. URL https://web.archive.org/web/20171124185357/https://blog.docracy.com/post/ 27931026976/an-open-source-privacy-policy-for-mobile-apps

  28. [36]

    Timing is everything?: The effects of timing and placement of online privacy indicators

    Serge Egelman, Janice Tsai, Lorrie Faith Cranor, and Alessandro Acquisti. Timing is everything?: The effects of timing and placement of online privacy indicators. In Proceed- ings of the SIGCHI Conference on Human Factors in Computing Systems , pages 319–328. ACM, 2009. URL htt...

  29. [37]

    Is This Thing On?: Crowd- sourcing Privacy Indicators for Ubiquitous Sensing Platforms

    Serge Egelman, Raghudeep Kannavara, and Richard Chow. Is This Thing On?: Crowd- sourcing Privacy Indicators for Ubiquitous Sensing Platforms. pages 1669–1678. ACM Press, 2015. ISBN 978-1-4503-3145-6. doi: 10 .1145/2702123.2702251. URL http: //dl.acm.org/citation.cfm?doid=27021...

  30. [38]

    Exploring How Privacy and Security Factor into IoT Device Purchase Behavior

    Pardis Emami-Naeini, Henry Dixon, Yuvraj Agarwal, and Lorrie Faith Cranor. Exploring How Privacy and Security Factor into IoT Device Purchase Behavior. In Proceedings of the 2019 CHI Conference on Human Factors in Computing Systems - CHI ’19 , pages 1–12. ACM Press, 2019. ISBN...

  31. [39]

    General Data Protection Regulation, 2016-04-26

    European Parliament. General Data Protection Regulation, 2016-04-26

  32. [40]

    FAIR INFORMATION PRACTICES IN THE ELECTRONIC MARKETPLACE

    Federal Trade Commission. FAIR INFORMATION PRACTICES IN THE ELECTRONIC MARKETPLACE. page 208, 2000-06

  33. [41]

    Children’s Online Privacy Protection Rule; Fi- nal Rule, 2013-01-17

    Federal Trade Commission. Children’s Online Privacy Protection Rule; Fi- nal Rule, 2013-01-17. URL https://www.ftc.gov/system/files/documents/ federal register notices/2013/01/2012-31341.pdf

  34. [42]

    Freedman, Tomas Sander, and Adam Shostack

    Joan Feigenbaum, Michael J. Freedman, Tomas Sander, and Adam Shostack. Privacy en- gineering for digital rights management systems. In Security and Privacy in Digital Rights Management, ACM CCS-8 Workshop DRM 2001, Philadelphia, PA, USA, November 5, 2001, Revised Papers, volum...

  35. [43]

    Deceived by Design, 2018-06-27

    Forbrukerr ˜A¥det. Deceived by Design, 2018-06-27. URL https:// fil.forbrukerradet.no/wp-content/uploads/2018/06/2018-06-27-deceived-by- design-final.pdf

  36. [44]

    Free Privacy Policy Generator & Template with GDPR - Free Privacy Policy, 2019-03-26

    FreePrivacyPolicies.com. Free Privacy Policy Generator & Template with GDPR - Free Privacy Policy, 2019-03-26. URL https://www.freeprivacypolicy.com/

  37. [45]

    LPL, Towards a GDPR- Compliant Privacy Language: Formal Definition and Usage

    Armin Gerl, Nadia Bennani, Harald Kosch, and Lionel Brunie. LPL, Towards a GDPR- Compliant Privacy Language: Formal Definition and Usage. Trans. Large-Scale Data- and Knowledge-Centered Systems, 37:41–80, 2018

  38. [46]

    Getterms.io, 2019-03-26

    GetTerms. Getterms.io, 2019-03-26. URL http://getterms.io/

  39. [47]

    Android Permissions overview, 2019-03-26

    Google. Android Permissions overview, 2019-03-26. URL https:// developer.android.com/guide/topics/permissions/overview

  40. [48]

    Gray, Yubo Kou, Bryan Battles, Joseph Hoggatt, and Austin L

    Colin M. Gray, Yubo Kou, Bryan Battles, Joseph Hoggatt, and Austin L. Toombs. The Dark (Patterns) Side of UX Design. In Proceedings of the 2018 CHI Conference on Human Factors in Computing Systems - CHI ’18 , pages 1–14. ACM Press, 2018. ISBN 978-1-4503- 5620-6. doi: 10/gfxvpz...

  41. [49]

    Margaret D. Hagan. User-Centered Privacy Communication Design. 2016. URL https: //www.usenix.org/system/files/conference/soups2016/wfpn16-paper-hagan.pdf

  42. [50]

    Shin, and Karl Aberer

    Hamza Harkous, Kassem Fawaz, R ˜A©mi Lebret, Florian Schaub, Kang G. Shin, and Karl Aberer. Polisis: Automated Analysis and Presentation of Privacy Policies Using Deep Learning. 2018-02-07. URL http://arxiv.org/abs/1802.02561

  43. [51]

    Basin, Christian Schaefer, and Thomas Walter

    Manuel Hilty, Alexander Pretschner, David A. Basin, Christian Schaefer, and Thomas Walter. A Policy Language for Distributed Usage Control. In Proceedings of the 12th European Symposium On Research in Computer Security, ESORICS’07 , volume 4734 of Lecture Notes in Computer Sci...

  44. [52]

    Holzmann

    Gerard J. Holzmann. The SPIN Model Checker - Primer and Reference Manual . Addison- Wesley, 2004. ISBN 978-0-321-22862-8

  45. [53]

    Logic in computer science - modelling and reasoning about systems (2

    Michael Huth and Mark Dermot Ryan. Logic in computer science - modelling and reasoning about systems (2. ed.) . Cambridge University Press, 2004. Inria SoK: Three Facets of Privacy Policies 29

  46. [54]

    Features — Compliance Solutions, 2019-03-26

    Iubenda. Features — Compliance Solutions, 2019-03-26. URL https://www.iubenda.com/ en/features

  47. [55]

    Terms of service, 2019-03-26

    Iubenda. Terms of service, 2019-03-26. URL https://www.iubenda.comhttps:// www.iubenda.com/en/user/tos

  48. [56]

    P2U: A Privacy Policy Specification Language for Secondary Data Sharing and Usage

    Johnson Iyilade and Julita Vassileva. P2U: A Privacy Policy Specification Language for Secondary Data Sharing and Usage. pages 18–22. IEEE, 2014-05. ISBN 978-1-4799-5103-1. doi: 10 .1109/SPW.2014.12. URL http://ieeexplore.ieee.org/document/6957279/

  49. [57]

    Privacy policies as decision-making tools: An evalu- ation of online privacy notices

    Carlos Jensen and Colin Potts. Privacy policies as decision-making tools: An evalu- ation of online privacy notices. In Proceedings of the SIGCHI Conference on Human Factors in Computing Systems , pages 471–478. ACM, 2004. URL http://dl.acm.org/ citation.cfm?id=985752

  50. [58]

    Lalana Kagal. Rei. 2002. URL http://ebiquity.umbc.edu/get/a/publication/57.pdf

  51. [59]

    Security and privacy policy languages: A survey, categorization and gap identification

    Saffija Kasem-Madani and Michael Meier. Security and privacy policy languages: A survey, categorization and gap identification. 2015. URL https://arxiv.org/abs/1512.00201

  52. [60]

    Patrick Gage Kelley, Joanna Bresee, Lorrie Faith Cranor, and Robert W. Reeder. A nutrition label for privacy. In Proceedings of the 5th Symposium on Usable Privacy and Security, page 4. ACM, 2009. URL http://dl.acm.org/citation.cfm?id=1572538

  53. [61]

    Standardizing privacy notices: An online study of the nutrition label approach

    Patrick Gage Kelley, Lucian Cesca, Joanna Bresee, and Lorrie Faith Cranor. Standardizing privacy notices: An online study of the nutrition label approach. In Proceedings of the SIGCHI Conference on Human Factors in Computing Systems , pages 1573–1582. ACM,

  54. [62]

    Generating User-Understandable Privacy Preferences

    Jan Kolter and G ˜A¼nther Pernul. Generating User-Understandable Privacy Preferences. pages 299–306. IEEE, 2009. ISBN 978-1-4244-3572-2. doi: 10 .1109/ARES.2009.89. URL http://ieeexplore.ieee.org/document/5066486/

  55. [63]

    Privacy preferences for E-Mail messages

    Ulrich K ˜A¶nig and Jan Schallaboeck. Privacy preferences for E-Mail messages. 2012. URL https://tools.ietf.org/html/koenig-privicons-03.txt

  56. [64]

    Appel: A p3p preference exchange language

    Marc Langheinrich, Lorrie Cranor, and Massimo Marchiori. Appel: A p3p preference exchange language. 2002. URL https://www.w3.org/TR/P3P-preferences/

  57. [65]

    A formal privacy management framework

    Daniel Le M ˜A©tayer. A formal privacy management framework. In International Work- shop on Formal Aspects in Security and Trust , pages 162–176. Springer, 2008. URL http://link.springer.com/chapter/10.1007/978-3-642-01465-9 11

  58. [66]

    Geospatial Extensible Access Control Markup Lan- guage (GeoXACML)

    Andreas Matheus and J Herrmann. Geospatial Extensible Access Control Markup Lan- guage (GeoXACML). Open Geospatial Consortium Inc. OGC , 2008

  59. [67]

    May, Carl A

    Michael J. May, Carl A. Gunter, and Insup Lee. Privacy APIs: Access Control Techniques to Analyze and Verify Legal Privacy Policies. In Proceedings of the 19th IEEE Computer Security Foundations Workshop, CSFW’06 , pages 85–97. IEEE Computer Society, 2006. ISBN 0-7695-2615-2

  60. [68]

    McDonald and Lorrie Faith Cranor

    Aleecia M. McDonald and Lorrie Faith Cranor. The cost of reading privacy policies. 4:543,

  61. [69]

    Icons of privacy (original), 2007

    Matthias Mehldau. Icons of privacy (original), 2007. URL https://netzpolitik.org/ wp-upload/data-privacy-icons-v01 .pdf

  62. [70]

    PrivacyInformer: An Automated Privacy Description Genera- tor for the MIT App Inventor, 2014

    Daniela Yidan Miao. PrivacyInformer: An Automated Privacy Description Genera- tor for the MIT App Inventor, 2014. URL http://citeseerx.ist.psu.edu/viewdoc/ download?doi=10.1.1.1029.2434&rep=rep1&type=pdf

  63. [71]

    Morel, M

    V. Morel, M. Cunche, and D. Le M ˜A©tayer. A generic information and consent framework for the iot. In Proceedings of the 18th IEEE International Conference On Trust, Security And Privacy In Computing And Communications(TrustCom) , pages 366–373, 2019. doi: 10.1109/TrustCom/Bi...

  64. [72]

    Short Form Notice Code of Conduct to Promote Transparency in Mobile Apps Practices, 2013

    National Telecommunications and Information Administration. Short Form Notice Code of Conduct to Promote Transparency in Mobile Apps Practices, 2013. URL https:// www.ntia.doc.gov/files/ntia/publications/july 25 code draft.pdf

  65. [73]

    Privacy as contextual integrity

    Helen Nissenbaum. Privacy as contextual integrity. 79:119, 2004. URL http://heinonline.org/hol-cgi-bin/get pdf.cgi?handle=hein.journals/ washlr79&section=16

  66. [74]

    Skills matter: Further results from the survey of adult skills, 2016

    Organisation for Economic Co-operation and Development. Skills matter: Further results from the survey of adult skills, 2016. OCLC: ocn953634518

  67. [75]

    Analysis of privacy policies to enhance informed consent

    Ra´ ul Pardo and Daniel Le M´ etayer. Analysis of privacy policies to enhance informed consent. In Proceedings of the 33rd Annual IFIP WG 11.3 Conference on Data and Appli- cations Security and Privacy , volume 11559 of Lecture Notes in Computer Science , pages 177–198, 2019. ...

  68. [76]

    Jaehong Park and Ravi S. Sandhu. The UCON ABC Usage Control Model. ACM Trans. Inf. Syst. Secur. , 7(1):128–174, 2004

  69. [77]

    Tesfay, Dennis-Kenji Kipker, Mattea Stelter, and Sebastian Pape

    Niklas Paul, Welderufael B. Tesfay, Dennis-Kenji Kipker, Mattea Stelter, and Sebastian Pape. Assessing Privacy Policies of Internet of Things Services. In Lech Jan Janczewski and Miros law Kuty lowski, editors,ICT Systems Security and Privacy Protection , volume 529, pages 156...

  70. [78]

    Chrome Polisis, 2019-03-26

    Polisis. Chrome Polisis, 2019-03-26. URL https://chrome.google.com/webstore/ detail/polisis/bkddolgokpghlbhhkflbbhhjghjdojck

  71. [79]

    Firefox Polisis, 2019-03-26

    Polisis. Firefox Polisis, 2019-03-26. URL https://addons.mozilla.org/en-US/firefox/ addon/polisis/

  72. [80]

    Polisis, 2019-03-26

    Polisis. Polisis, 2019-03-26. URL https://www.pribot.org/polisis

  73. [81]

    Alexander Pretschner, Manuel Hilty, and David A. Basin. Distributed Usage Control. Commun. ACM, 49(9):39–44, 2006

  74. [82]

    Privacy Policy Generator, 2019-03-26

    Privacy Policy Generator. Privacy Policy Generator, 2019-03-26. URL https:// privacypolicygenerator.info/

  75. [83]

    Privacy icons, 2018

    Privacy Tech. Privacy icons, 2018. URL https://www.privacytech.fr/privacy-icons/. Inria SoK: Three Facets of Privacy Policies 31

  76. [84]

    Privacy Policy Generator: Free, GDPR, CalOPPA - PrivacyPoli- cies.com, 2019-03-26

    PrivacyPolicies.com. Privacy Policy Generator: Free, GDPR, CalOPPA - PrivacyPoli- cies.com, 2019-03-26. URL https://www.privacypolicies.com/

  77. [85]

    Making Privacy Policies not Suck, 2010

    Aza Raskin. Making Privacy Policies not Suck, 2010. URL http://www.azarask.in/blog/ post/making-privacy-policies-not-suck/

  78. [86]

    Privacy Icons - MozillaWiki, 2011

    Aza Raskin. Privacy Icons - MozillaWiki, 2011. URL https://wiki.mozilla.org/ Privacy Icons

  79. [87]

    Reidenberg, Travis Breaux, Lorrie Faith Cranor, Brian French, Amanda Gran- nis, James T

    Joel R. Reidenberg, Travis Breaux, Lorrie Faith Cranor, Brian French, Amanda Gran- nis, James T. Graves, Fei Liu, Aleecia McDonald, Thomas B. Norton, and Rohan Ra- manath. Disagreeable privacy policies: Mismatches between meaning and users’ under- standing. 30:39, 2015. URL ht...

  80. [88]

    Reidenberg, Jaspreet Bhatia, Travis Breaux, and Thomas B

    Joel R. Reidenberg, Jaspreet Bhatia, Travis Breaux, and Thomas B. Norton. Automated comparisons of ambiguity in privacy policies and the impact of regulation. 2016. URL http://papers.ssrn.com/sol3/papers.cfm?abstract id=2715164

  81. [89]

    Reidenberg, Jaspreet Bhatia, Travis D

    Joel R. Reidenberg, Jaspreet Bhatia, Travis D. Breaux, and Thomas B. Norton. Ambi- guity in Privacy Policies and the Impact of Regulation. 45(S2):S163–S190, 2016-06. ISSN 0047-2530, 1537-5366. doi: 10/gdcdzm. URL https://www.journals.uchicago.edu/doi/ 10.1086/688669

  82. [90]

    DaPIS: An Ontology-Based Data Pro- tection Icon Set

    Arianna Rossi and Monica Palmirani. DaPIS: An Ontology-Based Data Pro- tection Icon Set. pages 181–195, 2019. ISSN 0922-6389. doi: 10/gf7fbn. URL http://www.medra.org/servlet/aliasResolver?alias=iospressISBN&isbn=978- 1-61499-984-3&spage=181&doi=10 .3233/FAIA190020

  83. [91]

    When Design Met Law: Design Patterns for Information Transparency

    Arianna Rossi, Rossana Ducato, Helena Haapio, and Stefania Passera. When Design Met Law: Design Patterns for Information Transparency. page 43, 2019

  84. [92]

    International Data Protection and Digital Identity Management Tools, presentation at IGF 2006

    Mary Rundle. International Data Protection and Digital Identity Management Tools, presentation at IGF 2006. 2006

  85. [93]

    Breaux, Lorrie Faith Cranor, Aleecia M

    Norman Sadeh, Alessandro Acquisti, Travis D. Breaux, Lorrie Faith Cranor, Aleecia M. McDonald, Joel R. Reidenberg, Noah A. Smith, Fei Liu, N. Cameron Russell, Florian Schaub, et al. The usable privacy policy project, 2013. URL http://ra.adm.cs.cmu.edu/ anon/usr0/ftp/home/anon/...

  86. [94]

    Sandhu, Edward J

    Ravi S. Sandhu, Edward J. Coyne, Hal L. Feinstein, and Charles E. Youman. Role-Based Access Control Models. IEEE Computer, 29(2):38–47, 1996. ISSN 0018-9162

  87. [95]

    Durity, and Lorrie Faith Cranor

    Florian Schaub, Rebecca Balebako, Adam L. Durity, and Lorrie Faith Cranor. A de- sign space for effective privacy notices. In Eleventh Symposium On Usable Privacy and Security (SOUPS 2015) , pages 1–17, 2015. URL https://www.usenix.org/conference/ soups2015/proceedings/presenta...

  88. [96]

    Daniel J. Solove. A taxonomy of privacy. 154:477, 2005. URL http://heinonline.org/ hol-cgi-bin/get pdf.cgi?handle=hein.journals/pnlr154&section=20

  89. [97]

    Assembly Bill No

    State of California. Assembly Bill No. 375 California Consumer Privacy Act, 2018-06-28

  90. [98]

    Sunstein

    Cass R. Sunstein. Choosing Not to Choose. 2014. ISSN 1556-5068. doi: 10/gftmr3. URL http://www.ssrn.com/abstract=2377364. RR n° 9287 32 V. Morel & R. Pardo

  91. [99]

    Sharing sensitive data with confidence: The datatags system

    Latanya Sweeney, Merc ˜A¨ Crosas, and Michael Bar-Sinai. Sharing sensitive data with confidence: The datatags system. 2015. URL http://techscience.org/a/2015101601/

  92. [100]

    Privacy policy, 2012-01-23T08:05:39+00:00

    Alasdair Taylor. Privacy policy, 2012-01-23T08:05:39+00:00. URL https:// seqlegal.com/free-legal-documents/privacy-policy

  93. [101]

    Terms of Service Classification, 2019-03-26

    Terms of Service; Didn’t Read. Terms of Service Classification, 2019-03-26. URL https: //tosdr.org/classification.html

  94. [102]

    Generic Privacy Policy template, 2019-03-26

    Termsfeed. Generic Privacy Policy template, 2019-03-26. URL https:// www.termsfeed.com/assets/pdf/privacy-policy-template.pdf

  95. [103]

    Tsai, Serge Egelman, Lorrie Cranor, and Alessandro Acquisti

    Janice Y. Tsai, Serge Egelman, Lorrie Cranor, and Alessandro Acquisti. The Ef- fect of Online Privacy Information on Purchasing Behavior: An Experimental Study. 22(2):254–268, 2011-06. ISSN 1047-7047, 1526-5536. doi: 10/cxhgzz. URL http: //pubsonline.informs.org/doi/abs/10.128...

  96. [104]

    Health Insurance Portability and Accountability Act, 1996

    United States Congress. Health Insurance Portability and Accountability Act, 1996. URL https://www.hhs.gov/sites/default/files/privacysummary.pdf

  97. [105]

    Gramm—Leach—Bliley Act, 1999

    United States Congress. Gramm—Leach—Bliley Act, 1999

  98. [106]

    (Un)informed Consent: Studying GDPR Consent Notices in the Field

    Christine Utz, Martin Degeling, Sascha Fahl, Florian Schaub, and Thorsten Holz. (Un)informed Consent: Studying GDPR Consent Notices in the Field. page 18, 2019

  99. [107]

    Qualitative Privacy Description Language

    Jasper van de Ven and Frank Dylla. Qualitative Privacy Description Language. In An- nual Privacy Forum , pages 171–189. Springer, 2016. URL http://link.springer.com/ chapter/10.1007/978-3-319-44760-5 11

  100. [108]

    What happens to my data? A novel approach to informing users of data processing practices

    Bibi Van den Berg and Simone Van der Hof. What happens to my data? A novel approach to informing users of data processing practices. 2012. doi: 10 .5210/fm.v17i7.4010. URL https://papers.ssrn.com/sol3/papers.cfm?abstract id=2100417

  101. [109]

    Cameron Russell, et al

    Shomir Wilson, Florian Schaub, Aswarth Abhilash Dara, Frederick Liu, Sushain Cherivirala, Pedro Giovanni Leon, Mads Schaarup Andersen, Sebastian Zimmeck, Kan- thashree Mysore Sathyendra, N. Cameron Russell, et al. The creation and analysis of a website privacy policy corpus. I...

  102. [110]

    Opinion 8/2014 on the Recent Developments on the Internet of Things

    WP29. Opinion 8/2014 on the Recent Developments on the Internet of Things. 2014

  103. [111]

    Guidelines on transparency under Regulation 2016/679, 2017-12-15

    WP29. Guidelines on transparency under Regulation 2016/679, 2017-12-15

  104. [112]

    A language for automatically en- forcing privacy policies

    Jean Yang, Kuat Yessenov, and Armando Solar-Lezama. A language for automatically en- forcing privacy policies. page 85. ACM Press, 2012. ISBN 978-1-4503-1083-3. doi: 10 .1145/ 2103656.2103669. URL http://dl.acm.org/citation.cfm?doid=2103656.2103669

  105. [113]

    AutoPPG: Towards Automatic Generation of Privacy Policy for Android Applications

    Le Yu, Tao Zhang, Xiapu Luo, and Lei Xue. AutoPPG: Towards Automatic Generation of Privacy Policy for Android Applications. pages 39–50. ACM Press, 2015. ISBN 978-1-4503- 3819-6. doi: 10 .1145/2808117.2808125. URL http://dl.acm.org/citation.cfm?doid= 2808117.2808125. Inria SoK...

  106. [114]

    German, and K

    Razieh Nokhbeh Zaeem, Rachel L. German, and K. Suzanne Barber. PrivacyCheck: Auto- matic Summarization of Privacy Policies Using Data Mining. 18(4):1–18, 2016. ISSN 1533- 5399, 1557-6051. doi: 10 .1145/3127519. URL https://dl.acm.org/doi/10.1145/3127519

  107. [115]

    Privacy Rights Markup Language Specification

    Zero-knowledge. Privacy Rights Markup Language Specification. 2001

  108. [116]

    Bellovin

    Sebastian Zimmeck and Steven M. Bellovin. Privee: An Architecture for Automati- cally Analyzing Web Privacy Policies. USENIX Association, 2014. ISBN 978-1-931971- 15-7. URL https://www.usenix.org/system/files/conference/usenixsecurity14/ sec14-paper-zimmeck.pdf. OCLC: 25432094...

  109. [328]

    ISBN 978-3-540-26203-9 978-3-540-31960-3

    Springer Berlin Heidelberg, 2005. ISBN 978-3-540-26203-9 978-3-540-31960-3. doi: 10.1007/11423409 20. URL http://link.springer.com/10.1007/11423409 20

  110. [1994]

    ISBN 978-3-540-58350-9

  111. [2002]

    URL https://elearn.inf.tu-dresden.de/hades/teleseminare/wise0405/Act.% 208%20Models%20Languages%20Pierangela/Materials/P3P.pdf

  112. [2008]

    RR n° 9287 30 V

    URL http://heinonline.org/hol-cgi-bin/get pdf.cgi?handle=hein.journals/ isjlpsoc4&section=27. RR n° 9287 30 V. Morel & R. Pardo

  113. [2010]

    URL http://dl.acm.org/citation.cfm?id=1753561

Pith tools

Reviewed August 14, 2026 · model on record in the stance chip above.