Pith. sign in

REVIEW 4 major objections 3 minor 93 references

Turning to Online Forums for Legal Information: A Case Study of GDPR's Legitimate Interests

T0 review · 4 major / 3 minor · reviewed 2026-08-07 · deepseek-v4-flash

Pith's one-line read Most accepted online-forum answers about GDPR's legitimate interests are legally sound, but a significant share are only partly sound or incomplete, and practitioner questions reveal systematic confusion about accountability, personal…

desk verdict A solid qualitative study whose headline soundness percentages rest on a single annotator; deserves review but needs a second annotation or softer framing. read the letter →

arxiv 2506.04260 v2 pith:QPHME6D5 submitted 2025-06-02 cs.CY cs.HC

classification cs.CYcs.HC
keywords GDPRlegitimateinterestsonlineforumslegalinformationcomplianceLawStackExchangesoundnessdataprotection
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

Using GDPR's "legitimate interests" legal basis as a case study, this paper asks whether practitioners who get legal guidance from online forums are being well served. After coding 319 forum posts from Reddit, Stack Overflow, and Law Stack Exchange, it finds that developers, marketers, and business owners are most confused about who is accountable, which legal basis applies, what counts as personal data, and how the legitimate-interest balancing test works. It then has a legal scholar evaluate the 94 accepted answers on Law Stack Exchange and reports that 73.4% are legally sound, 20.2% only partly sound, 6.4% not sound, and 8.9% of sound answers are incomplete. The paper's conclusion is that crowdsourced legal information is mostly reliable but should not be treated as complete legal advice, and that forums and regulators can improve outcomes with scenario-specific guidance, disclaimers, and better question formats. The stakes are concrete: forum answers shape real compliance decisions, and the same content is increasingly absorbed by AI assistants trained on forum data.

What carries the argument

The central object is the accepted-answer corpus: the 94 Law Stack Exchange answers that question posters marked as solving their problem, treated as a proxy for the legal information practitioners actually act on. The argument runs through two connected instruments—thematic coding of 319 forum posts to map where practitioners get confused, and a legal annotation rubric that scores each answer as sound, partly sound, or not sound, and as complete or incomplete, against EU legislation, CJEU case law, EDPB and Article 29 Working Party guidelines, and DPA decisions. The legal basis itself, Article 6(1)(f) GDPR and its three-tier balancing test, is the test case chosen because it is open-textured enough to reveal how vague legal concepts travel through forums.

What would settle it

Have two independent EU data-protection lawyers re-score the same 94 accepted answers against the paper's soundness rubric; if the independently scored share of legally sound answers diverges from the reported 73.4% by more than 10 percentage points, the headline rate is not stable.

Watch

Extended reading notes

Core claim

Legitimate interests under Article 6(1)(f) GDPR are broad, flexible, and poorly understood, and the paper shows both sides of that coin in the wild. On the question side, practitioners cluster around recurring pain points—deciding who in the organization is accountable, handling third-party tools, choosing between consent and legitimate interest, interpreting anonymization, and recognizing what counts as personal data—and the paper interprets these clusters as evidence that genuine effort to comply is being defeated by vague legal language and missing official guidance. On the answer side, a legal scholar with more than five years of experience in EU data-protection law reviewed all 94 accepted Law Stack Exchange answers and concluded that most are legally sound given the facts in the post (73.4%), that a sizeable minority are only partly sound (20.2%) or unsound (6.4%), and that even sound answers sometimes omit important context such as the ePrivacy Directive, the balancing test's burden of proof, or the data subject's right to object. The paper therefore claims that forums are a generally reliable but insufficient gateway to legal information: a useful first filter, yet not a substitute for a lawyer or for regulator-provided, scenario-specific guidance.

Load-bearing premise

The headline percentages rest on one legal scholar's judgment that an answer is legally sound based only on the facts in the poster's question; if that judgment is wrong, the 73.4% figure could move by more than its apparent margin.

Editorial extensions

If this is right

  • Accepted Law Stack Exchange answers can be a useful first-line resource for practitioners, but only as a filter: nearly 9% of sound answers still omit information relevant to applying legitimate interests, and 26.6% of answers are not fully sound.
  • The recurring confusion areas—accountability, legal-basis choice, consent, anonymization, personal data, and the balancing test—mark where regulators should target scenario-specific guidance for practitioners.
  • Requiring posters to state jurisdiction, industry, processing purpose, and their role in processing would give commentators enough context to write more legally sound and complete answers.
  • Forums should surface existing regulator resources, such as DPA guidelines and decision repositories, which appeared in none of the 94 accepted answers.
  • Because AI assistants are trained on forum data, the soundness gaps found here are foreseeable vectors for LLM-generated legal information to inherit the same incompleteness and errors.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • Editorial inference: the 73.4% figure likely overstates how reliably the answers would hold up in practice, since the annotator had only the facts in the post and no regulator's enforcement posture.
  • Editorial inference: a two-annotator replication on the same 94 answers, with an independent legal expert applying the same rubric, would show whether the 73.4% rate is stable; if the re-rated share moves by more than a few points, the headline percentage should be treated with caution.
  • Editorial inference: the method transfers directly to other open-textured GDPR bases (e.g., Article 6(1)(b) contract necessity) and to LLM-generated GDPR guidance, both of which are likely to show the same pattern of sound-but-incomplete answers.
  • Editorial inference: tagging accepted answers with topic, jurisdiction, and a vetting status would let practitioners filter for the specific obligations (like the balancing test or ePrivacy Directive) that the paper found most frequently missing.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

4 major / 3 minor

Summary. This paper studies how practitioners use online forums (Reddit, Law Stack Exchange, Stack Overflow) to obtain GDPR legal information, focusing on the legitimate-interest legal basis. The authors collect 319 forum posts, perform a thematic analysis of practitioner questions (Section 4), and conduct a legal-soundness assessment of 94 accepted Law Stack Exchange answers (Section 5). The headline finding is that 73.4% of accepted answers are legally sound, 20.2% partly sound, and 6.4% not sound, with 8.9% of sound answers incomplete. The paper also identifies recurring misunderstandings around roles, consent, personal data, anonymization, and the legitimate-interest balancing test, and offers recommendations for improving forum guidance.

Significance. If the central claim is robust, the paper makes a valuable empirical contribution at the intersection of HCI and data-protection law. It provides concrete evidence about where practitioners struggle with legitimate interests, and it is one of the few studies to evaluate the legal quality of crowdsourced legal information. Strengths include the two-annotator thematic analysis with a reported Cohen's kappa of 0.66, the anchoring of legal judgments in external sources such as EDPB guidelines and CJEU case law, a candid limitations section that acknowledges the uncertainty of the legal assessment, and a careful ethical protocol for quoting forum posts. The main weakness is that the headline legal-soundness percentages rest on a single annotator's judgments with no reliability evidence, which threatens the primary quantitative claim.

major comments (4)
  1. [Section 5, 'Annotation' and Section 5.1] The legal-soundness ratings, which are the basis for the abstract's claim that 'crowdsourced legal information tends to be legally sound, though sometimes incomplete,' are produced by a single co-author with no inter-rater reliability statistic, no second annotator, and no released codebook. Section 6.3 concedes that the labels have 'a margin of doubt' and that only a judicial assessment could provide definitive certainty. Because the classification of borderline cases (e.g., whether an answer that omits the balancing test is 'sound' or 'partly sound') could shift the reported 73.4%/20.2%/6.4% distribution materially, the paper needs a second independent legal annotation, a detailed rubric, or a sensitivity analysis to support the headline claim.
  2. [Section 4, 'Qualitative Analysis' and Section 3.2] The paper reports collecting 319 posts in Section 3.2, but the annotation procedure in Section 4 describes 15 posts coded together and then the annotators splitting the 'remaining half (107 posts),' implying only 229 posts (15 + 107 + 107) were analyzed. This discrepancy is never explained. The authors should clarify how many posts were actually included in the thematic analysis and reconcile this with the stated dataset size.
  3. [Section 5.1, 'Completeness'] The completeness criterion is reported only for the 69 answers already judged legally sound ('Out of these 69 legally sound answers, 8.9% were incomplete'). The paper should state whether completeness was assessed for all 94 answers or only for the sound ones, and if the latter, explain the rationale. This affects the interpretation of the 'sometimes incomplete' conclusion.
  4. [Section 6.3 and Abstract] The limitations section appropriately acknowledges that the legal analysis is 'confined to the facts' in each post and that legal ambiguities remain, but the abstract states the conclusion 'tends to be legally sound' without this caveat. Given the acknowledged uncertainty and the single-annotator design, the paper should temper the abstract and conclusion, or provide evidence that the classification is robust to the identified ambiguities.
minor comments (3)
  1. [Section 5.1] The percentage '8.9% of these 69 legally sound answers' corresponds to approximately 6 answers; stating the raw count alongside the percentage would aid readability and precision.
  2. [Section 3.2, Figure 1] The text says the frequency-terminology graphic 'was taken from [55]'; if the figure is reproduced from a prior publication, the authors should confirm that they have permission or that the original license permits reuse.
  3. [Section 1, Introduction] The phrase 'with the development of Large-Language Models' should read 'large language models' for consistency and grammar.

Circularity Check

0 steps flagged · score 0.0 of 10

No circularity: the legal-soundness result is anchored in external legal sources, and self-citations are background only.

full rationale

This paper is an observational qualitative and legal-annotation study; it contains no derivation chain whose output is equivalent to its input. The central claim that crowdsourced legal information is generally sound but sometimes incomplete is a summary of 94 accepted Law Stack Exchange answers annotated by a legal scholar. The annotation criteria are anchored in external legal authorities as the paper states: 'it was necessary to resort to legislation, judicial and regulatory decisions, and guidelines from the EDPB or from DPAs to confirm whether the provenance of some arguments in the given answers hold' (Section 5, Annotation). The headline percentages (73.4% sound, 20.2% partly sound, 6.4% not sound) are therefore not fitted parameters or predictions derived from the authors' prior work; they are descriptive results of an expert assessment against external legal sources. The self-citations present, chiefly [55] (Kyi et al. 2023) and [76] (Santos et al. 2020), supply background context about cookie banners, legitimate interest misuse, and consent requirements, but none is load-bearing for the paper's central result. The single-annotator design and the lack of a second legal annotation or inter-rater reliability statistic is a methodological validity limitation, explicitly acknowledged in Section 6.3 ('we acknowledge that there is a margin of doubt while labeling answers'), but that is a question of evidence quality, not circularity. The thematic analysis in Section 4 does report two annotators with Cohen's kappa = 0.66, and its findings are not used as inputs to the legal-soundness percentages. No step in the paper reduces, by construction or by self-citation, to its own inputs.

Assumptions & free parameters 0 free parameters · 4 assumptions · 0 invented entities

This is a qualitative empirical study, so the ledger contains domain assumptions about sampling and annotation rather than mathematical postulates. No free parameters or invented entities are present.

assumptions (4)
  • domain assumption Online forum content materially influences practitioner GDPR compliance decisions
    The paper's motivation relies on cited prior work (e.g., Tahaei et al., Wu et al.) rather than on causal evidence collected here; if forum influence is weak, the policy relevance weakens.
  • domain assumption Accepted answers on Law Stack Exchange are a meaningful proxy for the legal information practitioners rely on
    Section 5 Dataset deliberately restricts to accepted answers because posters mark them as solving their problem; this assumes other users will treat accepted answers as correct.
  • domain assumption Legal soundness can be assessed from the facts stated in the post without knowing the full factual context
    Section 6.3 acknowledges that only a judicial assessment with more fact-finding could render final certainty; the 73.4% soundness figure depends on this premise.
  • domain assumption Practitioner roles can be inferred from post content
    Section 4.1 says roles were inferred from technical versus client questions; misinference would mislabel the distribution of roles.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Turning to Online Forums for Legal Information: A Case Study of GDPR's Legitimate Interests." pith.science (2026). https://pith.science/paper/QPHME6D5

@misc{pith2026250604260,
  author       = {Pith},
  title        = {Pith review of: Turning to Online Forums for Legal Information: A Case Study of GDPR's Legitimate Interests},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/QPHME6D5}},
  note         = {Machine review of arXiv:2506.04260}
}
read the original abstract

Practitioners building online services and tools often turn to online forums such as Reddit, Law Stack Exchange, and Stack Overflow for legal guidance to ensure compliance with the GDPR. The legal information presented in these forums directly impacts present-day industry practitioner's decisions. Online forums can serve as gateways that, depending on the accuracy and quality of the answers provided, may either support or undermine the protection of privacy and data protection fundamental rights. However, there is a need for deeper investigation into practitioners' decision-making processes and their understanding of legal compliance when seeking for legal information online. Using GDPR's ``legitimate interests'' legal ground for processing personal data as a case study, we investigate how practitioners use online forums to identify common areas of confusion in applying legitimate interests in practice, and evaluate how legally sound online forum responses are. Our analysis found that applying the legal basis of legitimate interest is complex for practitioners, with important implications for how the GDPR is implemented in practice. The legal analysis showed that crowdsourced legal information tends to be legally sound, though sometimes incomplete. We outline recommendations to improve the quality of online forums by ensuring that responses are more legally sound and comprehensive, enabling practitioners to apply legitimate interests effectively in practice and uphold the GDPR.

Figures

Figures reproduced from arXiv: 2506.04260 by the authors.

Figure 1
Figure 1. The terminology used to represent the frequency of themes in qualitative re￾search, related to inferred practitioner roles. This graphic was taken from [55]. This figure represents terminology used to describe the frequency of themes in qualitative research. ‘A few’ refers to approximately 0 to 25%, ‘Some’ refers to approximately 25 to 45%, ‘About half’ refers to approximately 45 to 55%, ‘Most’ refers to approximate… view at source ↗

Discussion (0). Sign in to comment.

Reference graph

Works this paper leans on

93 extracted references · 78 canonical work pages

  1. [1]

    Opinion 2/2010 on online behavioural advertising, 2010.https://ec.europa.eu/ justice/article-29/documentation/opinion-recommendation/files/2010/ wp171_en.pdf

  2. [2]

    Court of Justice of the European Union ECLI:EU:C:2016:779, 2016

    Case 582/14 – Patrick Breyer v Germany. Court of Justice of the European Union ECLI:EU:C:2016:779, 2016

  3. [3]

    Court of Justice of the European Union ECLI:EU:C:2017:994, 2017

    Case C-434/16 - Peter Nowak v Data Protection Commissioner. Court of Justice of the European Union ECLI:EU:C:2017:994, 2017

  4. [4]

    https://gdpr4devs.com/, 2025

    GDPR for Developers. https://gdpr4devs.com/, 2025

  5. [5]

    You get where you’re looking for: The impact of informa- tion sources on code security

    Yasemin Acar, Michael Backes, Sascha Fahl, Doowon Kim, Michelle L Mazurek, and Christian Stransky. You get where you’re looking for: The impact of informa- tion sources on code security. In2016 IEEE Symposium on Security and Privacy (SP), pages 289–305. IEEE, 2016

  6. [6]

    Decision on the merits 21/2022 of 2 February 2022 Complaint relating to Trans- parency & Consent Framework, 2022

  7. [7]

    Chatgpt: Us lawyer admits using ai for case research, 2023

    Kathryn Armstrong. Chatgpt: Us lawyer admits using ai for case research, 2023

  8. [8]

    Attribution required, 2009

    Jeff Atwood. Attribution required, 2009

Show all 93 references
  1. [9]

    The Right to Erasure in EU Data Protection Law

    Jef Ausloos. The Right to Erasure in EU Data Protection Law . Oxford University Press, Oxford, UK, 2020

  2. [10]

    Harnessing stack overflow for the ide

    Alberto Bacchelli, Luca Ponzanelli, and Michele Lanza. Harnessing stack overflow for the ide. In 2012 Third International Workshop on Recommendation Systems for Software Engineering (RSSE) , pages 26–30. IEEE, 2012. 20 Kyi et al

  3. [11]

    Community under surveillance: Impacts of marginalization on an online labor forum

    Hanna Barakat and Elissa M Redmiles. Community under surveillance: Impacts of marginalization on an online labor forum. InProceedings of the International AAAI Conference on Web and Social Media , volume 16, pages 12–21, 2022

  4. [12]

    What are develop- ers talking about? an analysis of topics and trends in stack overflow.Empirical Software Engineering, 19(3):619–654, 2014

    Anton Barua, Stephen W Thomas, and Ahmed E Hassan. What are develop- ers talking about? an analysis of topics and trends in stack overflow.Empirical Software Engineering, 19(3):619–654, 2014

  5. [13]

    Sok: A privacy framework for security research using social media data

    Kyle Beadle, Kieron Ivy Turk, Aliai Eusebi, Mindy Tran, Marilyne Ordekian, En- rico Mariconti, Yixin Zou, and Marie Vasek. Sok: A privacy framework for security research using social media data. In2025 IEEE Symposium on Security and Pri- vacy (SP), pages 1178–1196. IEEE, 2025

  6. [14]

    Engineering privacy bydesign:Areengineersreadytoliveuptothechallenge? The Information Society, 35(3):122–142, 2019

    Kathrin Bednar, Sarah Spiekermann, and Marc Langheinrich. Engineering privacy bydesign:Areengineersreadytoliveuptothechallenge? The Information Society, 35(3):122–142, 2019

  7. [15]

    Air canada has to honor a refund policy its chatbot made up,

    Ashley Belanger. Air canada has to honor a refund policy its chatbot made up,

  8. [16]

    Opinion 4/2007 on the concept of personal data (WP 136), adopted on 20.06.2007, 2007

    European Data Protection Board. Opinion 4/2007 on the concept of personal data (WP 136), adopted on 20.06.2007, 2007

  9. [17]

    Guidelines 2/2019 on the processing of personal data under article 6(1)(b) gdpr in the context of the provision of online services to data subjects, 2019

    European Data Protection Board. Guidelines 2/2019 on the processing of personal data under article 6(1)(b) gdpr in the context of the provision of online services to data subjects, 2019

  10. [18]

    Guidelines 5/2019 on the criteria of the right to be forgotten in the search engines cases under the gdpr (part 1), 2020

    European Data Protection Board. Guidelines 5/2019 on the criteria of the right to be forgotten in the search engines cases under the gdpr (part 1), 2020

  11. [19]

    Using thematic analysis in psychology.Qual- itative research in Psychology , 3(2):77–101, 2006

    Virginia Braun and Victoria Clarke. Using thematic analysis in psychology.Qual- itative research in Psychology , 3(2):77–101, 2006

  12. [20]

    Data protection by design and by default: Deciphering the eu’s legislative requirements

    Lee A Bygrave. Data protection by design and by default: Deciphering the eu’s legislative requirements. Oslo Law Review, 4(2):105–120, 2017

  13. [21]

    Délibération san-2020-018, 2020

    CNIL. Délibération san-2020-018, 2020

  14. [22]

    Data protection commission announces conclusion of two inquiries into meta ireland, 2023

    Data Protection Commission. Data protection commission announces conclusion of two inquiries into meta ireland, 2023

  15. [23]

    GDPR Devel- oper’s Guide

    Commission Nationale de l’Informatique et des Libertés (CNIL). GDPR Devel- oper’s Guide. https://www.cnil.fr/en/gdpr-developers-guide, June 2020

  16. [24]

    Ouverture et réutilisation de données personnelles sur Internet: la CNIL publie ses recomman- dations

    Commission Nationale de l’Informatique et des Libertés (CNIL). Ouverture et réutilisation de données personnelles sur Internet: la CNIL publie ses recomman- dations. https://www.cnil.fr/fr/ouverture-et-reutilisation-de-donnees- personnelles-sur-internet-la-cnil-publie-ses-reco...

  17. [25]

    Llms and stack overflow discussions: Reliability, impact, and challenges.Journal of Systems and Software , page 112541, 2025

    Leuson Da Silva, Jordan Samhi, and Foutse Khomh. Llms and stack overflow discussions: Reliability, impact, and challenges.Journal of Systems and Software , page 112541, 2025

  18. [26]

    Data protection commission reference: In-21-4-2 in the matter of meta platforms ireland ltd

    Irish DPA. Data protection commission reference: In-21-4-2 in the matter of meta platforms ireland ltd. (formerly facebook ireland ltd.), 2022

  19. [27]

    Decision zspr.421.3.2018, 2019

    Polish DPA. Decision zspr.421.3.2018, 2019

  20. [28]

    Ethical and privacy considerations for research using online fandom data.Transformative Works and Cultures, 33, 2020

    Brianna Dym and Casey Fiesler. Ethical and privacy considerations for research using online fandom data.Transformative Works and Cultures, 33, 2020

  21. [29]

    Case C-252/21: Request for a preliminary ruling from the Oberlandesgericht Düsseldorf (Germany) lodged on 22 April 2021 — Facebook Inc

    ECJ. Case C-252/21: Request for a preliminary ruling from the Oberlandesgericht Düsseldorf (Germany) lodged on 22 April 2021 — Facebook Inc. and Others v Bundeskartellamt, 2023

  22. [30]

    Opinion 5/2019 on the interplay be- tween the eprivacy directive and the gdpr, in particular regarding the competence, tasks and powers of data protection authorities, 2019

    European Data Protection Board (EDPB). Opinion 5/2019 on the interplay be- tween the eprivacy directive and the gdpr, in particular regarding the competence, tasks and powers of data protection authorities, 2019. Turning to Online Forums for Legal Information 21

  23. [31]

    Exploring how privacy and security factor into iot device purchase behavior

    Pardis Emami-Naeini, Henry Dixon, Yuvraj Agarwal, and Lorrie Faith Cranor. Exploring how privacy and security factor into iot device purchase behavior. In Proceedings of the 2019 CHI Conference on Human Factors in Computing Sys- tems, CHI ’19, page 1–12, New York, NY, USA, 201...

  24. [32]

    2018 Reform of EU data protection rules

    European Commission. 2018 Reform of EU data protection rules. Avail- able at https://ec.europa.eu/commission/sites/beta-political/files/data- protection-factsheet-changes_en .pdf, 2018

  25. [33]

    Guidelines 07/2020 on the con- cepts of controller and processor in the GDPR Version 1.0, 2020

    European Data Protection Board. Guidelines 07/2020 on the con- cepts of controller and processor in the GDPR Version 1.0, 2020. https://edpb.europa.eu/our-work-tools/public-consultations-art-704/ 2020/guidelines-072020-concepts-controller-and-processor_en

  26. [34]

    Opinion 06/2014 on the notion of legitimate interests of the data controller under article 7 of directive 95/46/ec (wp 217), 2014

    European Data Protection Board (EDPB). Opinion 06/2014 on the notion of legitimate interests of the data controller under article 7 of directive 95/46/ec (wp 217), 2014

  27. [35]

    Guidelines 05/2020 on consent under regulation 2016/679, 2020

    European Data Protection Board (EDPB). Guidelines 05/2020 on consent under regulation 2016/679, 2020

  28. [36]

    SME Data Protection Guide.https: //www.edpb.europa.eu/sme-data-protection-guide/home_en, April 2023

    European Data Protection Board (EDPB). SME Data Protection Guide.https: //www.edpb.europa.eu/sme-data-protection-guide/home_en, April 2023

  29. [37]

    European Data Protection Board (EDPB). Guidelines 1/2024 on processing of per- sonal data based on Article 6(1)(f) GDPR.https://www.edpb.europa.eu/system/ files/2024-10/edpb_guidelines_202401_legitimateinterest_en .pdf, October 2024

  30. [38]

    General disclaimer, 2023

    Law Stack Exchange. General disclaimer, 2023

  31. [39]

    How does accepting an answer work?, 2019

    Stack Exchange. How does accepting an answer work?, 2019

  32. [40]

    Academic papers using stack exchange data, 2022

    Stack Exchange. Academic papers using stack exchange data, 2022

  33. [41]

    Data protection and the legitimate interest of data controllers: Much ado about nothing or the winter of rights?Common Market Law Review , 51(3), 2014

    Federico Ferretti. Data protection and the legitimate interest of data controllers: Much ado about nothing or the winter of rights?Common Market Law Review , 51(3), 2014

  34. [42]

    Reviving purpose limitation and data minimisa- tion in data-driven systems.Technology and Regulation, 2021:44–61, 2021

    Michele Finck and Asia J Biega. Reviving purpose limitation and data minimisa- tion in data-driven systems.Technology and Regulation, 2021:44–61, 2021

  35. [43]

    Stack overflow considered harmful? the impact of copy&paste on android application security

    Felix Fischer, Konstantin Böttinger, Huang Xiao, Christian Stransky, Yasemin Acar, Michael Backes, and Sascha Fahl. Stack overflow considered harmful? the impact of copy&paste on android application security. In2017 IEEE Symposium on Security and Privacy (SP) , pages 121–136. ...

  36. [44]

    A lawful basis for online proctoring, 2018

    Y Fouad, A Lodder, J Hurdey, et al. A lawful basis for online proctoring, 2018

  37. [45]

    Platform privacies: Governance, collaboration, and the different meanings of “privacy” in ios and android development.New Media & Society, 20(4):1640–1657, 2018

    Daniel Greene and Katie Shilton. Platform privacies: Governance, collaboration, and the different meanings of “privacy” in ios and android development.New Media & Society, 20(4):1640–1657, 2018

  38. [46]

    it’s a scavenger hunt

    Hana Habib, Sarah Pearman, Jiamin Wang, Yixin Zou, Alessandro Acquisti, Lor- rie Faith Cranor, Norman Sadeh, and Florian Schaub. "it’s a scavenger hunt": Usability of websites’ opt-out and data deletion choices. InProceedings of the 2020 CHI Conference on Human Factors in Comp...

  39. [47]

    Evaluating large language models in generating synthetic hci research data: a case study

    Perttu Hämäläinen, Mikke Tavast, and Anton Kunnari. Evaluating large language models in generating synthetic hci research data: a case study. InProceedings of the 2023 CHI Conference on Human Factors in Computing Systems , pages 1–19, 2023

  40. [48]

    those things are writ- ten by lawyers, and programmers are reading that

    Stefan Albert Horstmann, Samuel Domiks, Marco Gutfleisch, Mindy Tran, Yasemin Acar, Veelasha Moonsamy, and Alena Naiakshina. “those things are writ- ten by lawyers, and programmers are reading that.” mapping the communication 22 Kyi et al. gap between software developers and p...

  41. [49]

    Sorry for Bugging you so much

    Stefan Albert Horstmann, Sandy Hong, David Klein, Raphael Serafini, Martin Degeling, Martin Johns, Veelasha Moonsamy, and Alena Naiakshina. “Sorry for Bugging you so much.” Exploring Developers’ Behavior Towards Privacy- Compliant Implementation. In 2025 IEEE Symposium on Secu...

  42. [50]

    Data controllers and data processors: what the difference is and what the governance implications are, 2018

    Information Commissioner’s Office. Data controllers and data processors: what the difference is and what the governance implications are, 2018. https: //ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the- general-data-protection-regulation-gdpr/controllers-and-...

  43. [51]

    Data protection by design and by default: Framing guiding principles into legal obligations in the gdpr.Eur

    Lina Jasmontaite, Irene Kamara, Gabriela Zanfir-Fortuna, and Stefano Leucci. Data protection by design and by default: Framing guiding principles into legal obligations in the gdpr.Eur. Data Prot. L. Rev. , 4:168, 2018

  44. [52]

    Understanding the balancing act behind the le- gitimate interest of the controller ground: A pragmatic approach.Brussels Privacy Hub, 4(12), 2018

    Irene Kamara and Paul De Hert. Understanding the balancing act behind the le- gitimate interest of the controller ground: A pragmatic approach.Brussels Privacy Hub, 4(12), 2018

  45. [53]

    A fait accompli? an empirical study into the absence of consent to third-party tracking in android apps

    Konrad Kollnig, Pierre Dewitte, Max Van Kleek, Ge Wang, Daniel Omeiza, Helena Webb, and Nigel Shadbolt. A fait accompli? an empirical study into the absence of consent to third-party tracking in android apps. InSeventeenth Symposium on Usable Privacy and Security (SOUPS 2021) ...

  46. [54]

    The eu general data protection regulation: A commentary/update of selected articles

    Christopher Kuner, Lee A Bygrave, Christopher Docksey, Laura Drechsler, and Luca Tosoni. The eu general data protection regulation: A commentary/update of selected articles. Update of Selected Articles (May 4, 2021) , 2021

  47. [55]

    Investigating deceptive design in gdpr’s legiti- mate interest

    Lin Kyi, Sushil Ammanaghatta Shivakumar, Franziska Roesner, Cristiana Santos, Frederike Zufall, and Asia Biega. Investigating deceptive design in gdpr’s legiti- mate interest. In Proceedings of the 2023 CHI Conference on Human Factors in Computing Systems, pages 1–15, 2023

  48. [56]

    Verletzung des Persönlichkeitsrechts durch Datenschutzverstoß (Violation of the right of personality due to data pro- tection infringement)

    LG München I (Regional Court Munich I). Verletzung des Persönlichkeitsrechts durch Datenschutzverstoß (Violation of the right of personality due to data pro- tection infringement). Available at https://www.gesetze-bayern.de/Content/ Document/Y-300-Z-BECKRS-B-2022-N-612?hl=true , 2022

  49. [57]

    Tianshi Li, Elizabeth Louie, Laura Dabbish, and Jason I Hong. How developers talk about personal data and what it means for user privacy: A case study of a de- veloper forum on reddit.Proceedings of the ACM on Human-Computer Interaction, 4(CSCW3):1–28, 2021

  50. [58]

    Gdpr privacy policies in claudette: Challenges of omission, context and multilingualism

    R¯ uta Liepin,a, Giuseppe Contissa, Kasper Drazewski, Francesca Lagioia, Marco Lippi, Hans Wolfgang Micklitz, Przemyslaw Palka, Giovanni Sartor, and Paolo Torroni. Gdpr privacy policies in claudette: Challenges of omission, context and multilingualism. In ASAIL@ICAIL, 2019

  51. [59]

    Fabrication as ethical practice: Qualitative inquiry in am- biguous internet contexts.Information, Communication & Society , 15(3):334–353, 2012

    Annette Markham. Fabrication as ethical practice: Qualitative inquiry in am- biguous internet contexts.Information, Communication & Society , 15(3):334–353, 2012

  52. [60]

    Purposes in iab europe’s tcf: which legal basis and how are they used by advertisers? InAnnual Privacy Forum, pages 163–185

    Célestin Matte, Cristiana Santos, and Nataliia Bielova. Purposes in iab europe’s tcf: which legal basis and how are they used by advertisers? InAnnual Privacy Forum, pages 163–185. Springer, 2020

  53. [61]

    Interrater reliability: the kappa statistic

    Mary L McHugh. Interrater reliability: the kappa statistic. Biochemia medica, 22(3):276–282, 2012

  54. [62]

    Norwwgian dpa against meta platfroms case 21/03530-16, 2023

  55. [63]

    noyb.eu. GDPRhub. https://gdprhub.eu/, 2025. Turning to Online Forums for Legal Information 23

  56. [64]

    Case c-210/16 wirtschaftsakademie schleswig-holstein, ecli:eu:c:2018:388, 2018

    European Court of Justice. Case c-210/16 wirtschaftsakademie schleswig-holstein, ecli:eu:c:2018:388, 2018

  57. [65]

    Case c-40/17 fashion id gmbh & co.kg v ver- braucherzentrale nrw ev, ecli:eu:c:2019:629, 2019

    European Court of Justice. Case c-40/17 fashion id gmbh & co.kg v ver- braucherzentrale nrw ev, ecli:eu:c:2019:629, 2019

  58. [66]

    Case c-673/17 verbraucherzentrale bundesverband v

    European Court of Justice. Case c-673/17 verbraucherzentrale bundesverband v. planet49, ecli:eu:c:2019:801, 2019

  59. [67]

    Guidance on the use of cookies and similar technologies, 2019

    Information Commissioner’s Office. Guidance on the use of cookies and similar technologies, 2019. https://ico.org.uk/media/for-organisations/guide-to- pecr/guidance-on-the-use-of-cookies-and-similar-technologies-1-0 .pdf

  60. [68]

    Crowd documentation: Exploring the coverage and the dynamics of api discussions on stack overflow

    ChrisParnin,ChristophTreude,LarsGrammel,andMargaret-AnneStorey. Crowd documentation: Exploring the coverage and the dynamics of api discussions on stack overflow. Georgia Institute of Technology, Tech. Rep , 11, 2012

  61. [69]

    Understanding Developers Privacy Concerns Through Reddit Thread Analysis

    Jonathan Parsons, Michael Schrider, Oyebanjo Ogunlela, and Sepideh Ghanavati. Understanding Developers Privacy Concerns Through Reddit Thread Analysis. arXiv preprint arXiv:2304.07650 , 2023

  62. [70]

    Opinion 2/2010 on online behavioural advertising, 2010

    Article 29 Working Party. Opinion 2/2010 on online behavioural advertising, 2010

  63. [71]

    Opinion 04/2012 on cookie consent exemption (WP 194), 2012

    Article 29 Working Party. Opinion 04/2012 on cookie consent exemption (WP 194), 2012

  64. [72]

    Google spain sl and google inc

    Article 29 Working Party. Google spain sl and google inc. v agencia española de protección de datos (aepd) and mario costeja gonzález, 2014

  65. [73]

    Guidelines on transparency under regulation 2016/679, wp260 rev.01, 2016

    Article 29 Working Party. Guidelines on transparency under regulation 2016/679, wp260 rev.01, 2016

  66. [74]

    Studying reddit: A systematic overview of disciplines, approaches, methods, and ethics

    Nicholas Proferes, Naiyan Jones, Sarah Gilbert, Casey Fiesler, and Michael Zim- mer. Studying reddit: A systematic overview of disciplines, approaches, methods, and ethics. Social Media + Society , 7(2):20563051211019004, 2021

  67. [75]

    Multitask prompted training enables zero-shot task generalization.arXiv preprint arXiv:2110.08207, 2021

    Victor Sanh, Albert Webson, Colin Raffel, Stephen H Bach, Lintang Sutawika, Zaid Alyafeai, Antoine Chaffin, Arnaud Stiegler, Teven Le Scao, Arun Raja, et al. Multitask prompted training enables zero-shot task generalization.arXiv preprint arXiv:2110.08207, 2021

  68. [76]

    Cristiana Santos, Nataliia Bielova, and Célestin Matte. Are cookie banners indeed compliant with the law? deciphering EU legal requirements on consent and tech- nical means to verify compliance of cookie banners.Technology and Regulation, pages 91–135, 2020

  69. [77]

    Consent management platforms under the gdpr: processors and/or con- trollers? In Annual Privacy Forum, pages 47–69

    Cristiana Santos, Midas Nouwens, Michael Toth, Nataliia Bielova, and Vincent Roca. Consent management platforms under the gdpr: processors and/or con- trollers? In Annual Privacy Forum, pages 47–69. Springer, 2021

  70. [78]

    Why developers cannot embed privacy into software systems? an empirical investigation

    Awanthika Senarath and Nalin AG Arachchilage. Why developers cannot embed privacy into software systems? an empirical investigation. InProceedings of the 22nd International Conference on Evaluation and Assessment in Software Engi- neering 2018, pages 211–216, 2018

  71. [79]

    Learning to limit data collection via scaling laws: A computational inter- pretation for the legal principle of data minimization

    Divya Shanmugam, Fernando Diaz, Samira Shabanian, Michèle Finck, and Asia Biega. Learning to limit data collection via scaling laws: A computational inter- pretation for the legal principle of data minimization. In2022 ACM Conference on Fairness, Accountability, and Transparen...

  72. [80]

    The challenges of privacy by design.Communications of the ACM, 55(7):38–40, 2012

    Sarah Spiekermann. The challenges of privacy by design.Communications of the ACM, 55(7):38–40, 2012

  73. [81]

    How website owners face privacy is- sues: Thematic analysis of responses from a covert notification study reveals diverse circumstances and challenges

    Alina Stöver, Nina Gerber, Henning Pridöhl, Max Maass, Sebastian Bretthauer, Matthias Hollick, Dominik Herrmann, et al. How website owners face privacy is- sues: Thematic analysis of responses from a covert notification study reveals diverse circumstances and challenges. Proce...

  74. [82]

    Privacy, permissions, and the health app ecosystem: A stack overflow exploration

    Mohammad Tahaei, Julia Bernd, and Awais Rashid. Privacy, permissions, and the health app ecosystem: A stack overflow exploration. InProceedings of the 2022 European Symposium on Usable Security , pages 117–130, 2022

  75. [83]

    Privacy champions in software teams: Understanding their motivations, strategies, and challenges

    Mohammad Tahaei, Alisa Frik, and Kami Vaniea. Privacy champions in software teams: Understanding their motivations, strategies, and challenges. InProceedings of the 2021 CHI Conference on Human Factors in Computing Systems , pages 1–15, 2021

  76. [84]

    Understanding privacy-related advice on stack overflow.Proc

    Mohammad Tahaei, Tianshi Li, and Kami Vaniea. Understanding privacy-related advice on stack overflow.Proc. Priv. Enhancing Technol. , 2022(2):114–131, 2022

  77. [85]

    Understanding privacy- related questions on stack overflow

    Mohammad Tahaei, Kami Vaniea, and Naomi Saphra. Understanding privacy- related questions on stack overflow. InProceedings of the 2020 CHI Conference on Human Factors in Computing Systems , pages 1–14, 2020

  78. [86]

    Your complete guide to General Data Protection Regulation (GDPR) compliance

    Robb Taylor-Hiscock. Your complete guide to General Data Protection Regulation (GDPR) compliance. OneTrust Blog, April 2021

  79. [87]

    Directive 2009/136/ec of the european parliament and of the council, 2009

    European Union. Directive 2009/136/ec of the european parliament and of the council, 2009

  80. [88]

    Stack overflow and github: Associations between software development and crowdsourced knowledge

    Bogdan Vasilescu, Vladimir Filkov, and Alexander Serebrenik. Stack overflow and github: Associations between software development and crowdsourced knowledge. In 2013 International Conference on Social Computing,pages188–195.IEEE,2013

  81. [89]

    Algorithms that remem- ber: model inversion attacks and data protection law

    Michael Veale, Reuben Binns, and Lilian Edwards. Algorithms that remem- ber: model inversion attacks and data protection law. Philosophical Transac- tions of the Royal Society A: Mathematical, Physical and Engineering Sciences , 376(2133):20180083, 2018

  82. [90]

    Qualitative approaches to empirical legal research , pages 926–948

    Lisa Webley. Qualitative approaches to empirical legal research , pages 926–948. Oxford Handbooks. Oxford University Press, United Kingdom, November 2010

  83. [91]

    How to source developers from stack overflow, 2021

    Tom Winter. How to source developers from stack overflow, 2021

  84. [92]

    How do de- velopers utilize source code from stack overflow?Empirical Software Engineering, 24(2):637–673, 2019

    Yuhao Wu, Shaowei Wang, Cor-Paul Bezemer, and Katsuro Inoue. How do de- velopers utilize source code from stack overflow?Empirical Software Engineering, 24(2):637–673, 2019

  85. [2024]

    https://www.wired.com/story/air-canada-chatbot-refund-policy/

Pith tools

Reviewed August 7, 2026 · model on record in the stance chip above.