Pith. sign in

REVIEW 3 major objections 4 minor 185 references

SoK: From Generation to Consumption of Privacy Documents in Software Systems

T0 review · 3 major / 4 minor · reviewed 2026-08-16 · deepseek-v4-flash

Pith's one-line read This paper maps 290 privacy-document papers into a five-stage lifecycle and argues generation is the least supported stage.

desk verdict A genuinely useful lifecycle SoK with a transparent methodology; the quantitative claims need a coding-reliability check and a real artifact before the numbers can be trusted as field-level facts. read the letter →

arxiv 2608.12511 v1 pith:CGWNPU7Y submitted 2026-08-12 cs.CR cs.CL

classification cs.CRcs.CL
keywords privacydocumentspoliciessystematizationofknowledgesoftwarelifecycleengineeringGDPRcompliancelargelanguagemodelsusable
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

Privacy documents are the main way software systems disclose data practices and seek consent, yet research on them has been fragmented across separate surveys: one on NLP methods, one on usability, one on policies. This paper tries to establish a unified view by treating privacy documents as software components with a lifecycle and by systematically reviewing 290 papers from 2010 to 2025. It claims the lifecycle map is accurate: policies dominate at 227 of 290 papers, analysis is the most crowded stage, and generation is the least studied, at 11% of the corpus. A sympathetic reader would take the paper's contribution to be this structural diagnosis plus the 15 trends, 21 open opportunities, and four research directions it derives from it.

What carries the argument

The load-bearing object is the lifecycle codebook: five research questions (RQ1–RQ5) that define how a privacy document is scoped, generated, analyzed, checked for consistency and compliance, and consumed. The coding procedure — keyword search over titles and abstracts, two-author screening, forward and backward snowballing, and open coding of 425 candidates down to 290 — is what converts the taxonomy into quantitative claims like T4 (generation at 11%). The codebook also supplies the numbering scheme (T# for trends, O# for opportunities, D# for directions) that lets the paper state cross-stage dependencies.

What would settle it

Replicate the corpus construction with full-text searches, a broader venue list, and non-English databases, then re-code the lifecycle stages. If the generation share moves well above 11%, or the policy share moves well below 227 of 290, the paper's quantitative trends are artifacts of search design. A cheaper check: take one year, such as 2023, run the paper's own keyword query without venue restrictions, and count how many relevant papers the 32-venue list missed.

Watch

Extended reading notes

Core claim

On the paper's own terms, the central discovery is the lifecycle taxonomy and the imbalance it exposes. Across 290 papers, five stages absorb very different amounts of attention: content analysis (205 papers, 70.7%), consistency and compliance (130, 44.8%), usability (126, 43.4%), and generation (32, 11.0%), with the scope questions (RQ1) running through all of them. The paper argues this imbalance is structural — mature Android program-analysis frameworks make mobile software–policy consistency checking tractable, GDPR gives compliance work a clear regulatory target, and generation tools remain artifact-driven prototypes rather than collaborative workflows. From this map it derives 15 trends, 21 open opportunities, and four directions, the last organized around AI-centric platforms, data foundations, LLM-based policy-code analysis, and dual usability for end-users and developers.

Load-bearing premise

The map stands or falls on whether the 290-paper corpus fairly represents the field, which the paper itself notes is constrained by English-only title and abstract searches and a restricted venue set.

Editorial extensions

If this is right

  • If the lifecycle map is accurate, future privacy-document work should invest disproportionately in generation, traceability, and developer-facing tooling, since that is the stage with the least existing support.
  • AI-centric platforms will require new document formats and consent mechanisms, because prompts, chat history, and autonomous agent actions do not fit the permission-and-API model that current consistency checking assumes.
  • LLM-based analysis of policies should be paired with human-in-the-loop verification and evidence grounding, since the review identifies hallucination and limited explainability as open problems rather than solved ones.
  • Consistency research should move from pairwise comparisons, such as policy versus label, to multilateral comparisons across policies, labels, permissions, manifests, and settings.
  • Dataset efforts should be longitudinal, multilingual, and multi-source, because the review finds that existing text-only English policy corpora bottleneck almost every stage.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • Editorial inference: if T4's 11% figure holds up, the highest-leverage place for new tools is probably generation, because inaccurate or untraceable documents poison every downstream stage — analysis, compliance, and usability alike.
  • Editorial inference: the deliberate exclusion of Terms of Service research means consent-related work in that adjacent space is invisible to the map; a ToS-inclusive re-run could shift the compliance-stage counts and opportunities.
  • Editorial inference: a concrete test of direction D3 would be to benchmark LLM-based policy-code alignment against the manual-analysis findings the review collects, using the same 290-paper corpus and the same codebook categories.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 4 minor

Summary. This SoK systematizes the literature on privacy documents (privacy policies, labels, notices, etc.) from a software-engineering lifecycle perspective. The authors systematically searched 32 CORE B+ venues plus snowballing, screened 10121 raw hits down to 290 analyzed papers published 2010–2025, and open-coded them along five research questions spanning definition/scope, generation, analysis, consistency/compliance, and usability. They report 15 research trends, 21 open opportunities, and four research directions, and they provide a quantitative map of the field (e.g., privacy policies appear in 227/290 papers; generation is 11% of the corpus; GDPR is the dominant regulatory frame). The paper's main claim is that this taxonomy and these distributions form an accurate and useful map of the field.

Significance. If the coding is reliable and the corpus is representative, this is the first lifecycle-wide systematization of privacy document research, covering a broader scope than prior surveys (e.g., Schaub et al. 2015, Javed and Sajid 2024). The paper provides a reusable codebook, an explicit venue list, and a clear link between the five RQs and the taxonomy, and its quantitative counts give the community a point of comparison for future work. The strengths are the transparent SLR-based process, the cross-stage analysis (generation→compliance→usability dependencies), and the concrete, actionable research agenda (D1–D4). These contributions merit publication if the synthesis is independently verifiable.

major comments (3)
  1. [III-B]
  2. [III-A]
  3. [III-A]
minor comments (4)
  1. [I]
  2. [Fig. 1]
  3. [VI-B]
  4. [References]

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity: the SoK's trends are inductive corpus counts, not derivations from their own conclusions.

full rationale

This SoK makes no first-principles derivation; its central outputs (15 trends, 21 opportunities, 4 directions) are inductive summaries of a 290-paper corpus coded by three annotators. None of the quantitative claims (e.g., T1 policies in 227/290, T4 generation at 11%, T12 GDPR dominance) is computed from a fitted parameter that is later renamed as a prediction; each is a direct frequency over the manually constructed codebook. The paper's inclusion criteria do shape the corpus (English-only papers, title/abstract keyword screening, ToS exclusion, CORE B+ venues), and Section III-D admits title/abstract-only searching. These choices could bias trends T1 and T3; for example, an English-only paper-language criterion does not by itself force the document-language finding, since English-written papers can analyze German or Chinese policies, and the policy-heavy keyword query may inflate policy-related counts. Such bias is a sampling/validity threat, not a definitional reduction: the trends are not used as inputs to the screening decisions, and there is no equation or fitted value whose output is its own input. The many author self-citations in Section V (e.g., PCapGen [93], PAcT [78], PriGen [74] in O3-O5) are illustrative examples of open opportunities rather than load-bearing evidence for the taxonomy; the taxonomy rests on the coded corpus. Section VI-A's observation that only 12 of 37 manual-coding papers report Cohen's Kappa, and Section III-D's statement that no agreement was calculated for the initial code-development stage, are reproducibility limitations, not circularity. Overall, the paper's synthesis claims are self-contained relative to its own corpus construction; no circularity score above 0 is warranted.

Assumptions & free parameters 0 free parameters · 5 assumptions · 0 invented entities

This is a literature review, so there are no fitted numeric parameters; the quantities that play that role are design choices (keyword string, CORE B+ threshold, 10% saturation sample, English-only restriction), which I list as domain assumptions. The central claim rests on five premises about corpus construction and coding reliability, all stated in Section III. No entities were invented: the T#/O#/D# labels are enumeration schemes, not new constructs.

assumptions (5)
  • domain assumption Privacy documents are defined to include policies, labels, notices, and consent disclosures, but to exclude Terms of Service.
    This scope rule determines what enters the 290-paper corpus and thus what the trends show; stated as an inclusion criterion in Section III-A(b). ToS-adjacent consent research is explicitly cut.
  • domain assumption CORE ranking B or higher is a sufficient quality and completeness proxy for the seed venue list.
    Section III-A(a) restricts the initial venues to CORE B+; snowballing later relaxes the venue restriction, but seed coverage still affects which papers are found.
  • domain assumption Absence of the English keywords in title/abstract implies a paper is not primarily about privacy documents.
    Section III-D states this assumption ('if our search terms were not present in this text, it is likely that privacy documents are not a primary focus'). It biases the corpus against research on non-English documents, which matters for trend T3 and opportunity O2.
  • domain assumption One round of forward and backward snowballing reaches saturation.
    Section III-A(d) verifies saturation on a random 10% sample of snowballed papers only; if saturation is false, relevant work is undercounted and the trend percentages shift.
  • domain assumption Consensus-based open coding without an inter-annotator agreement metric yields a consistent codebook.
    Section III-B and III-D; the authors cite McDonald et al. to justify omitting IRR. All trend percentages inherit the coding variance, which is not quantified.

how reviews work

0 comments
Cite this review

Pith. "Pith review of SoK: From Generation to Consumption of Privacy Documents in Software Systems." pith.science (2026). https://pith.science/paper/CGWNPU7Y

@misc{pith2026260812511,
  author       = {Pith},
  title        = {Pith review of: SoK: From Generation to Consumption of Privacy Documents in Software Systems},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/CGWNPU7Y}},
  note         = {Machine review of arXiv:2608.12511}
}
read the original abstract

Privacy documents (e.g., privacy policies) are a central mechanism through which digital services disclose data practices and seek user consent. Over the past decades, research on privacy documents has expanded significantly, encompassing not only traditional privacy policies but also short notices (e.g., privacy labels) and interface-level transparency mechanisms. As this research area continues to grow, it has become increasingly difficult to obtain a coherent view of how privacy documents are created, analyzed, evaluated, and maintained across their lifecycle. This SoK provides a unified, lifecycle-oriented view of privacy documents from a software engineering perspective. We systematically review and analyze 290 papers published between 2010 and 2025, organizing them around five research questions that examine how privacy documents are (1) defined and scoped, (2) generated, (3) analyzed and extracted, (4) checked for inconsistencies and noncompliance, and (5) evaluated and improved for usability. Building on our findings, we identify 15 key research trends and 21 open opportunities. We further chart four broader research directions that highlight (i) emerging challenges in AI-centric platforms, (ii) the need for diverse and up-to-date data foundations, (iii) LLM-based unified policy-code analysis, and (iv) dual usability for end-users and developers. We hope this SoK provides a shared foundation for future research on privacy policies and privacy documents.

Figures

Figures reproduced from arXiv: 2608.12511 by the authors.

Figure 1
Figure 1. An overview of the paper collection methodology. [PITH_FULL_IMAGE:figures/full_fig_p003_1.png] view at source ↗
Figure 2
Figure 2. Papers published per year from 2010 to 2025. [PITH_FULL_IMAGE:figures/full_fig_p003_2.png] view at source ↗
Figure 3
Figure 3. Category distribution by year range (normalized). [PITH_FULL_IMAGE:figures/full_fig_p008_3.png] view at source ↗

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

185 extracted references · 66 canonical work pages

  1. [1]

    General data protection regulation (GDPR),

    GDPR, “General data protection regulation (GDPR),” https://gdpr-info. eu/, Retrieved: 2022-04-25

  2. [2]

    California consumer privacy act of 2018 (CCPA),

    CCPA, “California consumer privacy act of 2018 (CCPA),” https://oag. ca.gov/privacy/ccpa, Accessed: 2022-04-25

  3. [3]

    Brazilian general data protection law (LGPD),

    LGPD, “Brazilian general data protection law (LGPD),” http:// www.planalto.gov.br/ccivil 03/ Ato2015-2018/2018/Lei/L13709.htm, Retrieved: 2022-08-26

  4. [4]

    Personal information protection law of the people’s re- public of china (PIPL),

    PIPL, “Personal information protection law of the people’s re- public of china (PIPL),” http://www.npc.gov.cn/npc/c30834/202108/ a8c4e3672c74491a80b53a172bb753fe.shtml, Accessed: 2022-04-25

  5. [5]

    Australian privacy principles (APP),

    APPs, “Australian privacy principles (APP),” https://www.oaic.gov.au/ privacy/australian-privacy-principles, Accessed: 2022-05-03

  6. [6]

    The usable privacy policy project: Combining crowdsourc- ing,

    N. Sadeh, A. Acquisti, T. D. Breaux, L. F. Cranor, A. M. McDonald, J. R. Reidenberg, N. A. Smith, F. Liu, N. C. Russell, F. Schaub et al., “The usable privacy policy project: Combining crowdsourc- ing,”Machine Learning and Natural Language Processing to Semi- Automatically Answer Those Privacy Questions Users Care About, pp. 1–24, 2013

  7. [7]

    Privacy policies over time: Curation and analysis of a million-document dataset,

    R. Amos, G. Acar, E. Lucherini, M. Kshirsagar, A. Narayanan, and J. Mayer, “Privacy policies over time: Curation and analysis of a million-document dataset,” inProceedings of the Web Conference 2021, 2021, pp. 2165–2176

  8. [8]

    Identifying the provision of choices in privacy policy text,

    K. M. Sathyendra, S. Wilson, F. Schaub, S. Zimmeck, and N. Sadeh, “Identifying the provision of choices in privacy policy text,” inProceed- ings of the 2017 conference on empirical methods in natural language processing, 2017, pp. 2774–2779

Show all 185 references
  1. [9]

    Researchers’ experiences in analyzing pri- vacy policies: Challenges and opportunities,

    A. Mhaidli, S. Fidan, A. Doan, G. Herakovic, M. Srinath, L. Matheson, S. Wilson, and F. Schaub, “Researchers’ experiences in analyzing pri- vacy policies: Challenges and opportunities,”Proceedings on Privacy Enhancing Technologies, 2023

  2. [10]

    Policychecker: Analyzing the gdpr completeness of mobile apps’ privacy policies,

    A. Xiang, W. Pei, and C. Yue, “Policychecker: Analyzing the gdpr completeness of mobile apps’ privacy policies,” inProceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security, 2023, pp. 3373–3387

  3. [11]

    Vpvet: Vetting privacy policies of virtual reality apps,

    Y . Zhan, Y . Meng, L. Zhou, Y . Xiong, X. Zhang, L. Ma, G. Chen, Q. Pei, and H. Zhu, “Vpvet: Vetting privacy policies of virtual reality apps,” inProceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security, 2024, pp. 1746–1760

  4. [12]

    {POLICYCOMP}: Counterpart comparison of privacy policies uncovers overbroad personal data collection practices,

    L. Zhou, C. Wei, T. Zhu, G. Chen, X. Zhang, S. Du, H. Cao, and H. Zhu, “{POLICYCOMP}: Counterpart comparison of privacy policies uncovers overbroad personal data collection practices,” in32nd USENIX Security Symposium (USENIX Security 23), 2023

  5. [13]

    Share first, ask later (or never?) studying violations of{GDPR’s}explicit consent in android apps,

    T. T. Nguyen, M. Backes, N. Marnau, and B. Stock, “Share first, ask later (or never?) studying violations of{GDPR’s}explicit consent in android apps,” in30th USENIX Security Symposium (USENIX Security 21), 2021, pp. 3667–3684

  6. [14]

    The biggest lie on the internet: Ignoring the privacy policies and terms of service policies of social networking services,

    J. A. Obar and A. Oeldorf-Hirsch, “The biggest lie on the internet: Ignoring the privacy policies and terms of service policies of social networking services,”Information, Communication & Society, vol. 23, no. 1, pp. 128–147, 2020

  7. [15]

    Privacy policies across the ages: content of privacy policies 1996–2021,

    I. Wagner, “Privacy policies across the ages: content of privacy policies 1996–2021,”ACM Transactions on Privacy and Security, vol. 26, no. 3, pp. 1–32, 2023

  8. [16]

    Readability of privacy policies of healthcare websites,

    T. Ermakova, B. Fabian, and E. Babina, “Readability of privacy policies of healthcare websites,” inWirtschaftsinformatik Proceedings, 2015

  9. [17]

    Improving readability of online privacy policies through doop: A domain ontology for online privacy,

    D. A. Audich, R. Dara, and B. Nonnecke, “Improving readability of online privacy policies through doop: A domain ontology for online privacy,”Digital, vol. 1, no. 4, pp. 198–215, 2021

  10. [18]

    Law in books and law in action: The readability of privacy policies and the gdpr,

    S. I. Becher and U. Benoliel, “Law in books and law in action: The readability of privacy policies and the gdpr,” inConsumer law and economics. Springer, 2020, pp. 179–204

  11. [19]

    An informative security and privacy “nutrition

    P. Emami-Naeini, J. Dheenadhayalan, Y . Agarwal, and L. F. Cranor, “An informative security and privacy “nutrition” label for internet of things devices,”IEEE Security & Privacy, vol. 20, no. 2, pp. 31–39, 2021

  12. [20]

    Automating contextual privacy policies: Design and evaluation of a production tool for digital consumer privacy awareness,

    M. Windl, N. Henze, A. Schmidt, and S. S. Feger, “Automating contextual privacy policies: Design and evaluation of a production tool for digital consumer privacy awareness,” inProceedings of the 2022 CHI Conference on Human Factors in Computing Systems, 2022

  13. [21]

    A NEW HOPE: Contextual privacy policies for mobile applications and an approach toward automated 14 generation,

    S. Pan, Z. Tao, T. Hoang, D. Zhang, T. Li, Z. Xing, X. Xu, M. Staples, T. Rakotoarivelo, and D. Lo, “A NEW HOPE: Contextual privacy policies for mobile applications and an approach toward automated 14 generation,” in33rd USENIX Security Symposium (USENIX Security 24). Philadel...

  14. [22]

    Towards context-aware mobile privacy notice: Implementation of a deployable contextual privacy policies generator,

    H. Gong, Z. Tao, S. Pan, Z. Xing, and X. Sun, “Towards context-aware mobile privacy notice: Implementation of a deployable contextual privacy policies generator,”arXiv preprint arXiv:2509.22900, 2025

  15. [23]

    Static checking of gdpr- related privacy compliance for object-oriented distributed systems,

    S. Tokas, O. Owe, and T. Ramezanifarkhani, “Static checking of gdpr- related privacy compliance for object-oriented distributed systems,” Journal of Logical and Algebraic Methods in Programming, vol. 125, p. 100733, 2022

  16. [24]

    Examining the integrity of apple’s privacy labels: Gdpr compliance and unnecessary data collection in ios apps,

    Z. A. Surma, S. Gowdar, and H. J. Pandit, “Examining the integrity of apple’s privacy labels: Gdpr compliance and unnecessary data collection in ios apps,”Information, vol. 15, no. 9, p. 551, 2024

  17. [25]

    i-right: Identifying and classifying gdpr user rights in fitness tracker and smart home privacy policies,

    A. D. Kounoudes, G. M. Kapitsaki, and I. Katakis, “i-right: Identifying and classifying gdpr user rights in fitness tracker and smart home privacy policies,” inInternational Conference on Web Information Systems Engineering. Springer, 2024, pp. 243–254

  18. [26]

    Setting the bar low: Are websites complying with the minimum requirements of the ccpa?

    M. Van Nortwick and C. Wilson, “Setting the bar low: Are websites complying with the minimum requirements of the ccpa?”Proceedings on Privacy Enhancing Technologies, 2022

  19. [27]

    A systematic review of privacy policy litera- ture,

    Y . Javed and A. Sajid, “A systematic review of privacy policy litera- ture,”ACM Computing Surveys, vol. 57, no. 2, pp. 1–43, 2024

  20. [28]

    Natural language processing of privacy policies: A survey,

    A. Adhikari, S. Das, and R. Dewri, “Natural language processing of privacy policies: A survey,”arXiv preprint arXiv:2501.10319, 2025

  21. [29]

    Privacy policy: challenges and trends in research,

    H. Alamri, C. Maple, and G. Epiphaniou, “Privacy policy: challenges and trends in research,” inIET Conference Proceedings CP846. IET, 2023, pp. 170–181

  22. [30]

    A design space for effective privacy notices,

    F. Schaub, R. Balebako, A. L. Durity, and L. F. Cranor, “A design space for effective privacy notices,” inSymposium on Usable Privacy and Security (SOUPS). USENIX Association, 2015, pp. 1–17

  23. [31]

    Polisis: Automated analysis and presentation of privacy policies using deep learning,

    H. Harkous, K. Fawaz, R. Lebret, F. Schaub, K. G. Shin, and K. Aberer, “Polisis: Automated analysis and presentation of privacy policies using deep learning,” in27th USENIX Security Symposium (USENIX Security 18), 2018, pp. 531–548

  24. [32]

    {PolicyLint}: investigating internal privacy pol- icy contradictions on google play,

    B. Andow, S. Y . Mahmud, W. Wang, J. Whitaker, W. Enck, B. Reaves, K. Singh, and T. Xie, “{PolicyLint}: investigating internal privacy pol- icy contradictions on google play,” in28th USENIX security symposium (USENIX security 19), 2019, pp. 585–602

  25. [33]

    Actions speak louder than words:{Entity-Sensitive} privacy policy and data flow analysis with{PoliCheck},

    B. Andow, S. Y . Mahmud, J. Whitaker, W. Enck, B. Reaves, K. Singh, and S. Egelman, “Actions speak louder than words:{Entity-Sensitive} privacy policy and data flow analysis with{PoliCheck},” in29th USENIX Security Symposium (USENIX Security 20), 2020

  26. [34]

    {PoliGraph}: Automated privacy policy analysis using knowledge graphs,

    H. Cui, R. Trimananda, A. Markopoulou, and S. Jordan, “{PoliGraph}: Automated privacy policy analysis using knowledge graphs,” in32nd USENIX Security Symposium, 2023, pp. 1037–1054

  27. [35]

    How private is your period?: A systematic analysis of menstrual app privacy policies,

    L. Shipp and J. Blasco, “How private is your period?: A systematic analysis of menstrual app privacy policies,”Proceedings on Privacy Enhancing Technologies, 2020

  28. [36]

    Evolution of composition, read- ability, and structure of privacy policies over two decades,

    A. Adhikari, S. Das, and R. Dewri, “Evolution of composition, read- ability, and structure of privacy policies over two decades,”Proceedings on Privacy Enhancing Technologies, 2023

  29. [37]

    Evaluating the readability of privacy policies in mobile environments,

    R. I. Singh, M. Sumeeth, and J. Miller, “Evaluating the readability of privacy policies in mobile environments,”International Journal of Mobile Human Computer Interaction (IJMHCI), vol. 3, no. 1, pp. 55– 78, 2011

  30. [38]

    Systematic literature reviews in software engineering– a systematic literature review,

    B. Kitchenham, O. P. Brereton, D. Budgen, M. Turner, J. Bailey, and S. Linkman, “Systematic literature reviews in software engineering– a systematic literature review,”Information and software technology, vol. 51, no. 1, pp. 7–15, 2009

  31. [39]

    Core conference rankings search page,

    Computing Research and Education Association of Australasia (CORE), “Core conference rankings search page,” https://portal.core. edu.au/conf-ranks/, accessed: 2025-12-22

  32. [40]

    dblp: computer science bibliography,

    dblp team, “dblp: computer science bibliography,” 2025, https://dblp. uni-trier.de/ Accessed: 2025-11-03

  33. [41]

    Multilingual scraper of privacy policies and terms of service,

    D. Bernhard, L. Nenadic, S. Bechtold, and K. Kubicek, “Multilingual scraper of privacy policies and terms of service,” inProceedings of the 2025 Symposium on Computer Science and Law, 2025, pp. 55–63

  34. [42]

    Guidelines for snowballing in systematic literature studies and a replication in software engineering,

    C. Wohlin, “Guidelines for snowballing in systematic literature studies and a replication in software engineering,” inProceedings of the 18th International Conference on Evaluation and Assessment in Software Engineering. Association for Computing Machinery, 2014. [Online]. Ava...

  35. [43]

    Qualitative data analysis a methods sourcebook,

    A. Hubermanet al., “Qualitative data analysis a methods sourcebook,” 2014

  36. [44]

    Qualitative content analysis: A step-by-step guide,

    P. Mayring, “Qualitative content analysis: A step-by-step guide,” 2021

  37. [45]

    Reliability and inter- rater reliability in qualitative research: Norms and guidelines for cscw and hci practice,

    N. McDonald, S. Schoenebeck, and A. Forte, “Reliability and inter- rater reliability in qualitative research: Norms and guidelines for cscw and hci practice,”Proceedings of the ACM on human-computer interaction, vol. 3, no. CSCW, pp. 1–23, 2019

  38. [46]

    A lon- gitudinal measurement of privacy policy evolution for large language models,

    Z. Tao, S. Pan, Z. Xing, E. Black, T. Gillis, and C. Chen, “A lon- gitudinal measurement of privacy policy evolution for large language models,”arXiv preprint arXiv:2511.21758, 2025

  39. [47]

    Modeling language vagueness in privacy policies using deep neural networks

    F. Liu, N. L. Fella, and K. Liao, “Modeling language vagueness in privacy policies using deep neural networks.” inAAAI Fall Symposia, 2016

  40. [48]

    Do cookie banners respect my choice?: Measuring legal compliance of banners from iab europe’s transparency and consent framework,

    C. Matte, N. Bielova, and C. Santos, “Do cookie banners respect my choice?: Measuring legal compliance of banners from iab europe’s transparency and consent framework,” in2020 IEEE Symposium on Security and Privacy (SP). IEEE, 2020, pp. 791–809

  41. [49]

    Automating cookie consent and{GDPR}violation detection,

    D. Bollinger, K. Kubicek, C. Cotrini, and D. Basin, “Automating cookie consent and{GDPR}violation detection,” in31st USENIX Security Symposium (USENIX Security 22), 2022, pp. 2893–2910

  42. [50]

    Automated cookie notice analysis and enforcement,

    R. Khandelwal, A. Nayak, H. Harkous, and K. Fawaz, “Automated cookie notice analysis and enforcement,” in32nd USENIX Security Symposium (USENIX Security 23), 2023, pp. 1109–1126

  43. [51]

    Auto- mated{Large-Scale}analysis of cookie notice compliance,

    A. Bouhoula, K. Kubicek, A. Zac, C. Cotrini, and D. Basin, “Auto- mated{Large-Scale}analysis of cookie notice compliance,” in33rd USENIX Security Symposium (USENIX Security 24), 2024, pp. 1723– 1739

  44. [52]

    Supporting informed choices about browser cookies: The impact of personalised cookie banners,

    T. Biselli, L. Utz, and C. Reuter, “Supporting informed choices about browser cookies: The impact of personalised cookie banners,” Proceedings on Privacy Enhancing Technologies, 2024

  45. [53]

    Crumbling cookie categories: Deconstructing common cookie categories to create categories that people understand,

    S. Jiwani, R. Sasheendran, A. Abhyankar, E. Bouma-Sims, and L. Cra- nor, “Crumbling cookie categories: Deconstructing common cookie categories to create categories that people understand,”Proceedings on Privacy Enhancing Technologies, 2024

  46. [54]

    Toward the cure of privacy policy reading phobia: Automated gener- ation of privacy nutrition labels from privacy policies,

    S. Pan, T. Hoang, D. Zhang, Z. Xing, X. Xu, Q. Lu, and M. Staples, “Toward the cure of privacy policy reading phobia: Automated gener- ation of privacy nutrition labels from privacy policies,”arXiv preprint arXiv:2306.10923, 2023

  47. [55]

    Toggles, dollar signs, and triangles: How to (in) effectively convey privacy choices with icons and link texts,

    H. Habib, Y . Zou, Y . Yao, A. Acquisti, L. Cranor, J. Reidenberg, N. Sadeh, and F. Schaub, “Toggles, dollar signs, and triangles: How to (in) effectively convey privacy choices with icons and link texts,” inProceedings of the 2021 CHI Conference on Human Factors in Computing ...

  48. [56]

    Are we getting well-informed? an in-depth study of runtime privacy notice practice in mobile apps,

    S. Li, Z. Yang, Y . Nan, S. Yu, Q. Zhu, and M. Yang, “Are we getting well-informed? an in-depth study of runtime privacy notice practice in mobile apps,” inProceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security, 2024, pp. 1581–1595

  49. [57]

    Ml-based compliance verification of data processing agreements against gdpr,

    O. Amaral, S. Abualhaija, and L. Briand, “Ml-based compliance verification of data processing agreements against gdpr,” in2023 IEEE 31st international requirements engineering conference (RE). IEEE, 2023, pp. 53–64

  50. [58]

    (un) informed consent: Studying gdpr consent notices in the field,

    C. Utz, M. Degeling, S. Fahl, F. Schaub, and T. Holz, “(un) informed consent: Studying gdpr consent notices in the field,” inProceedings of the 2019 acm sigsac conference on computer and communications security, 2019, pp. 973–990

  51. [59]

    A tale of two regulatory regimes: Creation and analysis of a bilingual privacy policy corpus,

    S. Arora, H. Hosseini, C. Utz, V . B. Kumar, T. Dhellemmes, A. Ravichander, P. Story, J. Mangat, R. Chen, M. Degelinget al., “A tale of two regulatory regimes: Creation and analysis of a bilingual privacy policy corpus,” inProceedings of the thirteenth language resources and e...

  52. [60]

    Regulatory compliance with limited enforceability: Evidence from privacy policies,

    B. Ganglmair, J. Kr ¨amer, and J. Gambato, “Regulatory compliance with limited enforceability: Evidence from privacy policies,”ZEW-Centre for European Economic Research Discussion Paper, no. 24-012, 2024

  53. [61]

    Privacy policies in medium-sized european town ad- ministrations: A comparative analysis of english and german-speaking countries,

    H. Hosseini, “Privacy policies in medium-sized european town ad- ministrations: A comparative analysis of english and german-speaking countries,” inProceedings of the 11th International Conference on Information Systems Security and Privacy (ICISSP 2025), 2025

  54. [62]

    A bilingual longitudinal analysis of privacy policies measuring the impacts of the gdpr and the ccpa/cpra,

    H. Hosseini, C. Utz, M. Degeling, and T. Hupperich, “A bilingual longitudinal analysis of privacy policies measuring the impacts of the gdpr and the ccpa/cpra,” 2024

  55. [63]

    Fair balancing? evaluating llm-based privacy policy ethics assessments

    V . Freiberger and E. Buchmann, “Fair balancing? evaluating llm-based privacy policy ethics assessments.” inEWAF, 2024

  56. [64]

    Effective regulation and firm compliance: The case of german privacy policies,

    J. Gambato, B. Ganglmair, and J. K. Kr ¨amer, “Effective regulation and firm compliance: The case of german privacy policies,” National Bureau of Economic Research, Tech. Rep., 2024. 15

  57. [65]

    Evaluating the privacy policy of android apps: a privacy policy compliance study for popular apps in china and europe,

    K. Liu, G. Xu, X. Zhang, G. Xu, and Z. Zhao, “Evaluating the privacy policy of android apps: a privacy policy compliance study for popular apps in china and europe,”Scientific Programming, vol. 2022, no. 1, p. 2508690, 2022

  58. [66]

    Personal information protection and privacy policy compliance of health code apps in china: Scale development and content analysis,

    J. Jiang and Z. Zheng, “Personal information protection and privacy policy compliance of health code apps in china: Scale development and content analysis,”JMIR mHealth and uHealth, vol. 11, 2023

  59. [67]

    An analysis of privacy policies of public covid- 19 apps: Evidence from india,

    S. J. De and R. Shukla, “An analysis of privacy policies of public covid- 19 apps: Evidence from india,”Journal of Public Affairs, vol. 22, p. e2801, 2022

  60. [68]

    A study of south asian websites on privacy compliance,

    Y . Javed, K. M. Salehin, and M. Shehab, “A study of south asian websites on privacy compliance,”IEEE Access, vol. 8, 2020

  61. [69]

    Privacyflash pro: automat- ing privacy policy generation for mobile apps,

    S. Zimmeck, R. Goldstein, and D. Baraka, “Privacyflash pro: automat- ing privacy policy generation for mobile apps,” in28th Network and Distributed System Security Symposium (NDSS 2021). NDSS, 2021

  62. [70]

    A large-scale empirical study of online automated privacy policy generators for mobile apps,

    S. Pan, D. Zhang, M. Staples, Z. Xing, J. Chen, X. Xu, and J. Hoang, “A large-scale empirical study of online automated privacy policy generators for mobile apps,”arXiv preprint arXiv:2305.03271, 2023

  63. [71]

    Optimizing a policy authoring framework for security and privacy policies,

    M. Johnson, J. Karat, C.-M. Karat, and K. Grueneberg, “Optimizing a policy authoring framework for security and privacy policies,” in Proceedings of the Sixth Symposium on Usable Privacy and Security, 2010, pp. 1–9

  64. [72]

    Toward automatically generating privacy policy for android apps,

    L. Yu, T. Zhang, X. Luo, L. Xue, and H. Chang, “Toward automatically generating privacy policy for android apps,”IEEE Transactions on Information Forensics and Security, vol. 12, no. 4, pp. 865–880, 2016

  65. [73]

    Matcha: An ide plugin for creating accurate privacy nutrition labels,

    T. Li, L. F. Cranor, Y . Agarwal, and J. I. Hong, “Matcha: An ide plugin for creating accurate privacy nutrition labels,”Proceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies, vol. 8, no. 1, pp. 1–38, 2024

  66. [74]

    Towards fine- grained localization of privacy behaviors,

    V . Jain, S. Ghanavati, S. T. Peddinti, and C. McMillan, “Towards fine- grained localization of privacy behaviors,” in2023 IEEE 8th European Symposium on Security and Privacy (EuroS&P). IEEE, 2023, pp. 258–277

  67. [75]

    Enhancing transparency and accountability of tpls with pbom: A privacy bill of materials,

    Y . Xiao, A. Nadkarni, and X. Liao, “Enhancing transparency and accountability of tpls with pbom: A privacy bill of materials,” in Proceedings of the 2024 Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses, 2023, pp. 1–11

  68. [76]

    Autoppg: Towards automatic generation of privacy policy for android applications,

    L. Yu, T. Zhang, X. Luo, and L. Xue, “Autoppg: Towards automatic generation of privacy policy for android applications,” inProceedings of the 5th Annual ACM CCS Workshop on Security and Privacy in Smartphones and Mobile Devices, 2015, pp. 39–50

  69. [77]

    Creating consistent privacy notices by translating code segments into privacy captions,

    V . Jain, “Creating consistent privacy notices by translating code segments into privacy captions,” in2022 IEEE 30th International Requirements Engineering Conference (RE), pp. 201–206

  70. [78]

    Pact: Detecting and classifying privacy behavior of android applica- tions,

    V . Jain, S. D. Gupta, S. Ghanavati, S. T. Peddinti, and C. McMillan, “Pact: Detecting and classifying privacy behavior of android applica- tions,” inProceedings of the 15th ACM Conference on Security and Privacy in Wireless and Mobile Networks, 2022, pp. 104–118

  71. [79]

    Visual configuration of mobile privacy policies,

    A. Aydin, D. Piorkowski, O. Tripp, P. Ferrara, and M. Pistoia, “Visual configuration of mobile privacy policies,” inInternational Conference on Fundamental Approaches to Software Engineering. Springer, 2017, pp. 338–355

  72. [80]

    Toward automatically generating privacy policy for smart home apps,

    Y . Li, Y . Zhang, H. Zhu, and S. Du, “Toward automatically generating privacy policy for smart home apps,” inIEEE INFOCOM 2021-IEEE Conference on Computer Communications Workshops (INFOCOM WKSHPS). IEEE, 2021, pp. 1–7

  73. [81]

    A user requirements-oriented privacy policy self-adaption scheme in cloud computing,

    C. Ke, F. Xiao, Z. Huang, and F. Xiao, “A user requirements-oriented privacy policy self-adaption scheme in cloud computing,”Frontiers of Computer Science, vol. 17, no. 2, p. 172203, 2023

  74. [82]

    Extracting lpl privacy policy purposes from annotated web service source code,

    K. Hjerppe, J. Ruohonen, and V . Lepp ¨anen, “Extracting lpl privacy policy purposes from annotated web service source code,”Software and Systems Modeling, vol. 22, no. 1, pp. 331–349, 2023

  75. [83]

    Pripocog: Empowering end-users’ data protection decisions,

    J. Leicht, J. Lukasewycz, and M. Heisel, “Pripocog: Empowering end-users’ data protection decisions,” inProceedings of the 27th International Conference on Enterprise Information Systems - Volume 2: ICEIS, INSTICC. SciTePress, 2025, pp. 668–679

  76. [84]

    Make privacy policies longer and appoint llm readers,

    P. Pałka, F. Lagioia, R. Liepina, M. Lippi, and G. Sartor, “Make privacy policies longer and appoint llm readers,”Artificial Intelligence and Law, pp. 1–33, 2025

  77. [85]

    Privacy policies on the fediverse: A case study of mastodon instances,

    E. Tosch, L. Garcia, C. Li, and C. Martens, “Privacy policies on the fediverse: A case study of mastodon instances,”Proceedings on Privacy Enhancing Technologies, 2024

  78. [86]

    Privacy bills of materials (pribom): A transparent privacy information inventory for collaborative privacy notice generation in mobile app development,

    Z. Tao, S. Pan, Z. Xing, X. Sun, O. Haggag, J. Grundy, J. Li, and L. Zhu, “Privacy bills of materials (pribom): A transparent privacy information inventory for collaborative privacy notice generation in mobile app development,” inThe 25th Privacy Enhancing Technologies Symposi...

  79. [87]

    Analysis of privacy policies to enhance informed consent,

    R. Pardo and D. Le M ´etayer, “Analysis of privacy policies to enhance informed consent,” inIFIP Annual Conference on Data and Applica- tions Security and Privacy. Springer, 2019, pp. 177–198

  80. [88]

    Privee: An architecture for auto- matically analyzing web privacy policies,

    S. Zimmeck and S. M. Bellovin, “Privee: An architecture for auto- matically analyzing web privacy policies,” in23rd USENIX Security Symposium (USENIX Security 14). San Diego, CA: USENIX Asso- ciation, Aug. 2014, pp. 1–16

  81. [89]

    Challenges in classifying privacy policies by machine learning with word-based features,

    K. Fukushima, T. Nakamura, D. Ikeda, and S. Kiyomoto, “Challenges in classifying privacy policies by machine learning with word-based features,” inproceedings of the 2nd international conference on cryp- tography, security and privacy, 2018, pp. 62–66

  82. [90]

    Privacy policy question answering assistant: A query-guided extractive summarization approach,

    M. Keymanesh, M. Elsner, and S. Parthasarathy, “Privacy policy question answering assistant: A query-guided extractive summarization approach,”arXiv preprint arXiv:2109.14638, 2021

  83. [91]

    What about my privacy? helping users understand online privacy poli- cies,

    W. Brunotte, L. Chazette, L. Kohler, J. Klunder, and K. Schneider, “What about my privacy? helping users understand online privacy poli- cies,” inProceedings of the International Conference on Software and System Processes and International Conference on Global Software Engine...

  84. [92]

    Genaipabench: A benchmark for generative ai-based privacy assis- tants,

    A. Hamid, H. R. Samidi, T. Finin, P. Pappachan, and R. Yus, “Genaipabench: A benchmark for generative ai-based privacy assis- tants,”arXiv preprint arXiv:2309.05138, 2023

  85. [93]

    Automated generation of accurate privacy captions from android source code using large language models,

    V . Jain, S. Ghanavati, S. T. Peddinti, and C. McMillan, “Automated generation of accurate privacy captions from android source code using large language models,”arXiv preprint arXiv:2601.06276, 2026

  86. [94]

    Collaborative privacy policy authoring in a social networking context,

    R. Wishart, D. Corapi, S. Marinovic, and M. Sloman, “Collaborative privacy policy authoring in a social networking context,” in2010 IEEE International Symposium on Policies for Distributed Systems and Networks. IEEE, 2010, pp. 1–8

  87. [95]

    Is it a trap? a large-scale empirical study and comprehensive as- sessment of online automated privacy policy generators for mobile apps,

    S. Pan, D. Zhang, M. Staples, Z. Xing, J. Chen, X. Xu, and T. Hoang, “Is it a trap? a large-scale empirical study and comprehensive as- sessment of online automated privacy policy generators for mobile apps,” in33rd USENIX Security Symposium (USENIX Security 24). Philadelphia,...

  88. [96]

    ” i don’t use ai for everything

    S. Pan, L. Wang, T. Zhang, Z. Xing, Y . Zhao, Q. Lu, and X. Sun, “” i don’t use ai for everything”: Exploring utility, attitude, and responsibility of ai-empowered tools in software development,”arXiv preprint arXiv:2409.13343, 2024

  89. [97]

    Ai in software engineer- ing: Perceived roles and their impact on adoption,

    I. Zakharov, E. Koshchenko, and A. Sergeyuk, “Ai in software engineer- ing: Perceived roles and their impact on adoption,” inProceedings of the 33rd ACM International Conference on the Foundations of Software Engineering, 2025, pp. 1305–1309

  90. [98]

    Purext: Automated extraction of the purpose-aware rule from the natural language privacy policy in iot,

    L. Yang, X. Chen, Y . Luo, X. Lan, and L. Chen, “Purext: Automated extraction of the purpose-aware rule from the natural language privacy policy in iot,”Security and Communication Networks, vol. 2021, no. 1, p. 5552501, 2021

  91. [99]

    Privonto: A semantic framework for the analysis of privacy policies,

    A. Oltramari, D. Piraviperumal, F. Schaub, S. Wilson, S. Cherivirala, T. B. Norton, N. C. Russell, P. Story, J. Reidenberg, and N. Sadeh, “Privonto: A semantic framework for the analysis of privacy policies,” Semantic Web, vol. 9, no. 2, pp. 185–203, 2018

  92. [100]

    Guileak: Tracing privacy policy claims on user input data for android applications,

    X. Wang, X. Qin, M. B. Hosseini, R. Slavin, T. D. Breaux, and J. Niu, “Guileak: Tracing privacy policy claims on user input data for android applications,” inProceedings of the 40th International Conference on Software Engineering, 2018, pp. 37–47

  93. [101]

    Analyzing regulatory rules for privacy and security requirements,

    T. Breaux and A. Ant ´on, “Analyzing regulatory rules for privacy and security requirements,”IEEE transactions on software engineering, vol. 34, no. 1, pp. 5–20, 2008

  94. [102]

    A framework for expressing and enforcing purpose-based privacy policies,

    M. Jafari, R. Safavi-Naini, P. W. Fong, and K. Barker, “A framework for expressing and enforcing purpose-based privacy policies,”ACM Transactions on Information and System Security (TISSEC), vol. 17, no. 1, pp. 1–31, 2014

  95. [103]

    Rsl-il4privacy: A domain-specific language for the rigorous specification of privacy policies,

    J. Caramujo, A. Rodrigues da Silva, S. Monfared, A. Ribeiro, P. Calado, and T. Breaux, “Rsl-il4privacy: A domain-specific language for the rigorous specification of privacy policies,”Requirements Engineering, vol. 24, no. 1, pp. 1–26, 2019

  96. [104]

    Towards privacy policy conceptual modeling,

    K. Krasnashchok, M. Mustapha, A. Al Bassit, and S. Skhiri, “Towards privacy policy conceptual modeling,” inInternational Conference on Conceptual Modeling. Springer, 2020, pp. 429–438

  97. [105]

    Ambiguity and generality in natural language privacy policies,

    M. B. Hosseini, J. Heaps, R. Slavin, J. Niu, and T. Breaux, “Ambiguity and generality in natural language privacy policies,” in2021 IEEE 16 29th International Requirements Engineering Conference (RE). IEEE, 2021, pp. 70–81

  98. [106]

    Consent verifi- cation monitoring,

    M. Robol, T. D. Breaux, E. Paja, and P. Giorgini, “Consent verifi- cation monitoring,”ACM Transactions on Software Engineering and Methodology, vol. 32, no. 1, pp. 1–33, 2023

  99. [107]

    Enhancing the description-to-behavior fidelity in android apps with privacy policy,

    L. Yu, X. Luo, C. Qian, S. Wang, and H. K. N. Leung, “Enhancing the description-to-behavior fidelity in android apps with privacy policy,” IEEE Transactions on Software Engineering, 2018

  100. [108]

    The effect of platform policies on app privacy compliance: A study of child-directed apps,

    N. Alomar, J. Reardon, A. Girish, N. Vallina-Rodriguez, and S. Egel- man, “The effect of platform policies on app privacy compliance: A study of child-directed apps,”Proceedings on Privacy Enhancing Technologies, 2025

  101. [109]

    Unpacking privacy labels: A measurement and developer perspective on google’s data safety section,

    R. Khandelwal, A. Nayak, P. Chung, K. Fawaz, A. Bianchi, Z. B. Celik, Y . Yarom, X. S. Shen, Z. Fang, S. Zhanget al., “Unpacking privacy labels: A measurement and developer perspective on google’s data safety section,” in33rd USENIX Security Symposium (USENIX Security 24), 202...

  102. [110]

    An empirical analysis of data deletion and{Opt-Out}choices on 150 websites,

    H. Habib, Y . Zou, A. Jannu, N. Sridhar, C. Swoopes, A. Acquisti, L. F. Cranor, N. Sadeh, and F. Schaub, “An empirical analysis of data deletion and{Opt-Out}choices on 150 websites,” inFifteenth Symposium on Usable Privacy and Security (SOUPS 2019), 2019

  103. [111]

    Re- viewing the data security and privacy policies of mobile apps for depression,

    K. O’Loughlin, M. Neary, E. C. Adkins, and S. M. Schueller, “Re- viewing the data security and privacy policies of mobile apps for depression,”Internet interventions, vol. 15, pp. 110–115, 2019

  104. [112]

    Lessons in vcr repair: compliance of android app developers with the california consumer privacy act (ccpa),

    N. Samarin, S. Kothari, Z. Siyed, O. Bjorkman, R. Yuan, P. Wijesekera, N. Alomar, J. Fischer, C. Hoofnagle, and S. Egelman, “Lessons in vcr repair: compliance of android app developers with the california consumer privacy act (ccpa),”arXiv preprint arXiv:2304.00944, 2023

  105. [113]

    Smart home privacy policies demystified: A study of availability, content, and coverage,

    S. Manandhar, K. Kafle, B. Andow, K. Singh, and A. Nadkarni, “Smart home privacy policies demystified: A study of availability, content, and coverage,” in31st USENIX Security Symposium (USENIX Security 22), 2022, pp. 3521–3538

  106. [114]

    Feasibility of structured, machine- readable privacy notices,

    V . Jesus, A. Patel, and D. Kumar, “Feasibility of structured, machine- readable privacy notices,” in2023 10th International Conference on Behavioural and Social Computing (BESC). IEEE, 2023, pp. 1–8

  107. [115]

    Domain specialization as the key to make large language models disruptive: A comprehensive survey,

    C. Ling, X. Zhao, J. Lu, C. Deng, C. Zheng, J. Wang, T. Chowdhury, Y . Li, H. Cui, X. Zhanget al., “Domain specialization as the key to make large language models disruptive: A comprehensive survey,” ACM Computing Surveys, vol. 58, no. 3, pp. 1–39, 2025

  108. [116]

    Evaluating llms towards automated assessment of privacy policy understandability,

    K. Mori, D. Ito, T. Fukunaga, T. Watanabe, Y . Takata, M. Kamizono, and T. Mori, “Evaluating llms towards automated assessment of privacy policy understandability,” inProceedings of the 2025 Symposium on Usable Security and Privacy, 2025

  109. [117]

    A survey on hallucination in large language models: Principles, taxonomy, challenges, and open questions,

    L. Huang, W. Yu, W. Ma, W. Zhong, Z. Feng, H. Wang, Q. Chen, W. Peng, X. Feng, B. Qinet al., “A survey on hallucination in large language models: Principles, taxonomy, challenges, and open questions,”ACM Transactions on Information Systems, vol. 43, no. 2, pp. 1–55, 2025

  110. [118]

    Au- tomated extraction of semantic legal metadata using natural language processing,

    A. Sleimi, N. Sannier, M. Sabetzadeh, L. Briand, and J. Dann, “Au- tomated extraction of semantic legal metadata using natural language processing,” in2018 IEEE 26th International Requirements Engineer- ing Conference (RE). IEEE, 2018, pp. 124–135

  111. [119]

    Measuring compliance implications of third-party libraries’ privacy label disclosure guidelines,

    Y . Xiao, C. Zhang, Y . Qin, F. F. S. Alharbi, L. Xing, and X. Liao, “Measuring compliance implications of third-party libraries’ privacy label disclosure guidelines,” inProceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security, 2024

  112. [120]

    Advancing gdpr adherence: Leveraging generative ai for in-depth privacy policy analysis in android apps,

    T. Duc, T. Nghiem, H. Khanh, T. Khoa, M. Triet, L. Bang, N. Ngan, and N. Trong, “Advancing gdpr adherence: Leveraging generative ai for in-depth privacy policy analysis in android apps,” inInternational Conference on Artificial Intelligence and Soft Computing. Springer, 2024, ...

  113. [121]

    Privacychat: Utilizing large language model for fine-grained information extraction over privacy policies,

    R. C. Salvi, C. Blake, and M. Bahir, “Privacychat: Utilizing large language model for fine-grained information extraction over privacy policies,” inInternational Conference on Information. Springer, 2024, pp. 223–231

  114. [122]

    Analyzing corporate privacy policies using ai chatbots,

    Z. Huang, J. Tang, M. Karir, M. Liu, and A. Sarabi, “Analyzing corporate privacy policies using ai chatbots,” inProceedings of the 2024 ACM on Internet Measurement Conference, 2024

  115. [123]

    Honesty is the best policy: On the accuracy of apple privacy labels compared to apps’ privacy policies,

    M. M. Ali, D. G. Balash, M. Kodwani, C. Kanich, and A. J. Aviv, “Honesty is the best policy: On the accuracy of apple privacy labels compared to apps’ privacy policies,”arXiv preprint arXiv:2306.17063, 2023

  116. [124]

    The creation and analysis of a website privacy policy corpus,

    S. Wilson, F. Schaub, A. A. Dara, F. Liu, S. Cherivirala, P. G. Leon, M. S. Andersen, S. Zimmecket al., “The creation and analysis of a website privacy policy corpus,” inProceedings of the 54th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Pap...

  117. [125]

    Automated extraction and presentation of data practices in privacy policies,

    D. Bui, K. G. Shin, J.-M. Choi, and J. Shin, “Automated extraction and presentation of data practices in privacy policies,”Proceedings on Privacy Enhancing Technologies, 2021

  118. [126]

    Democratizing gdpr compliance: Ai-driven privacy policy interpretation,

    S. Mittal, S. Gupta, K. Bansal, and G. Aggarwal, “Democratizing gdpr compliance: Ai-driven privacy policy interpretation,” inProceedings of the 2024 Sixteenth International Conference on Contemporary Computing, 2024, pp. 735–743

  119. [127]

    Factors related to gdpr compliance promises in privacy policies: A machine learning and nlp approach,

    A.-J. Aberkane, S. vanden Broucke, and G. Poels, “Factors related to gdpr compliance promises in privacy policies: A machine learning and nlp approach,”International Journal of Information Systems and Project Management, vol. 13, no. 2, p. 3, 2025

  120. [128]

    Policygpt: Automated analysis of privacy policies with large language models,

    C. Tang, Z. Liu, C. Ma, Z. Wu, Y . Li, W. Liu, D. Zhu, Q. Li, X. Li, T. Liuet al., “Policygpt: Automated analysis of privacy policies with large language models,”arXiv preprint arXiv:2309.10238, 2023

  121. [129]

    Unilaw-r1: A large language model for legal reasoning with reinforcement learning and iterative inference,

    H. Cai, S. Zhao, L. Zhang, X. Shen, Q. Xu, W. Shen, Z. Wen, and T. Ban, “Unilaw-r1: A large language model for legal reasoning with reinforcement learning and iterative inference,” inProceedings of the 2025 Conference on Empirical Methods in Natural Language Processing, 2025, ...

  122. [130]

    Privacy at scale: Intro- ducing the privaseer corpus of web privacy policies,

    M. Srinath, S. Wilson, and C. L. Giles, “Privacy at scale: Intro- ducing the privaseer corpus of web privacy policies,”arXiv preprint arXiv:2004.11131, 2020

  123. [131]

    Maps: Scaling privacy compliance analysis to a million apps,

    S. Zimmeck, P. Story, D. Smullen, A. Ravichander, Z. Wang, J. Reiden- berg, N. C. Russell, and N. Sadeh, “Maps: Scaling privacy compliance analysis to a million apps,”Proceedings on Privacy Enhancing Tech- nologies, vol. 2019, no. 3, pp. 66–86, 2019

  124. [132]

    Privacy policies in social media: Providing translated privacy notice,

    B. Ur, M. Sleeper, and L. F. Cranor, “Privacy policies in social media: Providing translated privacy notice,” inProceedings of the 1st Workshop on Privacy and Security in Online Social Media, 2012

  125. [133]

    Lalaine: Measuring and characterizing non-compliance of apple privacy labels,

    Y . Xiao, Z. Li, Y . Qin, X. Bai, J. Guan, X. Liao, and L. Xing, “Lalaine: Measuring and characterizing non-compliance of apple privacy labels,” in32nd USENIX Security Symposium (USENIX Security 23), 2023, pp. 1091–1108

  126. [134]

    Longitudinal compliance analysis of android applications with pri- vacy policies,

    S. S. Hashmi, N. Waheed, G. Tangari, M. Ikram, and S. Smith, “Longitudinal compliance analysis of android applications with pri- vacy policies,” inInternational Conference on Mobile and Ubiquitous Systems: Computing, Networking, and Services. Springer, 2021

  127. [135]

    “trust me over my privacy policy

    A. Ragab, M. Mannan, and A. Youssef, ““trust me over my privacy policy”: Privacy discrepancies in romantic ai chatbot apps,” in2024 IEEE European Symposium on Security and Privacy Workshops (Eu- roS&PW). IEEE, 2024, pp. 484–495

  128. [136]

    Consistency analysis of data-usage purposes in mobile apps,

    D. Bui, Y . Yao, K. G. Shin, J.-M. Choi, and J. Shin, “Consistency analysis of data-usage purposes in mobile apps,” inProceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security, 2021, pp. 2824–2843

  129. [137]

    An automated approach to auditing disclosure of third-party data collection in website privacy policies,

    T. Libert, “An automated approach to auditing disclosure of third-party data collection in website privacy policies,” inProceedings of the 2018 World Wide Web Conference, 2018, pp. 207–216

  130. [138]

    {OVRseen}: Auditing network traffic and privacy policies in oculus {VR},

    R. Trimananda, H. Le, H. Cui, J. T. Ho, A. Shuba, and A. Markopoulou, “{OVRseen}: Auditing network traffic and privacy policies in oculus {VR},” in31st USENIX security symposium (USENIX security 22), 2022, pp. 3789–3806

  131. [139]

    Minis- cope: Automated ui exploration and privacy inconsistency detection of miniapps via two-phase iterative hybrid analysis,

    S. Wang, Y . Li, K. Wang, Y . Liu, H. Li, Y . Liu, and H. Wang, “Minis- cope: Automated ui exploration and privacy inconsistency detection of miniapps via two-phase iterative hybrid analysis,”ACM Transactions on Software Engineering and Methodology, vol. 34, no. 6, pp. 1–29, 2025

  132. [140]

    Investigating documented privacy changes in android os,

    C. Yan, M. H. Meng, F. Xie, and G. Bai, “Investigating documented privacy changes in android os,”Proceedings of the ACM on Software Engineering, vol. 1, no. FSE, pp. 2701–2724, 2024

  133. [141]

    Ptpdroid: Detecting violated user privacy disclosures to third-parties of android apps,

    Z. Tan and W. Song, “Ptpdroid: Detecting violated user privacy disclosures to third-parties of android apps,” in2023 IEEE/ACM 45th International Conference on Software Engineering (ICSE). IEEE, 2023, pp. 473–485

  134. [142]

    A privacy and security analysis of early-deployed covid-19 contact tracing android apps,

    M. Hatamian, S. Wairimu, N. Momen, and L. Fritsch, “A privacy and security analysis of early-deployed covid-19 contact tracing android apps,”Empirical software engineering, vol. 26, no. 3, p. 36, 2021

  135. [143]

    Analysis of privacy compliance by classifying policies before and after the japanese law revision,

    K. Mori, T. Nagai, Y . Takata, M. Kamizono, and T. Mori, “Analysis of privacy compliance by classifying policies before and after the japanese law revision,”Journal of information processing, vol. 31, 2023. 17

  136. [144]

    Act on the protection of personal information (act no. 57 of 2003),

    Japanese Government / Ministry of Justice, “Act on the protection of personal information (act no. 57 of 2003),” https://www.japaneselawtranslation.go.jp/en/laws/view/4241/en, Japanese Law Translation Database System, 2003, last version: Act No. 37 of 2021

  137. [145]

    Classifying potentially non- compliant portuguese language sentences concerning privacy policies,

    M. Tocchini, I. M. Rocha, R. M. de Barros, J. O. e Silva, A. F. Garcia, F. Zular, J. Maranh˜ao, and J. S. Sichman, “Classifying potentially non- compliant portuguese language sentences concerning privacy policies,” inBrazilian Conference on Intelligent Systems. Springer, 2024

  138. [146]

    Lei geral de protec ¸˜ao de dados (lgpd) / general data protec- tion law (law no. 13,709 of august 14, 2018),

    Ag ˆencia Nacional de Protec ¸˜ao de Dados (ANPD), Federative Republic of Brazil, “Lei geral de protec ¸˜ao de dados (lgpd) / general data protec- tion law (law no. 13,709 of august 14, 2018),” National Data Protection Authority (ANPD), Brazil, 2018, english version accessed J...

  139. [147]

    Creation and analysis of an international corpus of privacy laws,

    S. Gupta, E. Poplavska, N. O’Toole, S. Arora, T. Norton, N. Sadeh, and S. Wilson, “Creation and analysis of an international corpus of privacy laws,”arXiv preprint arXiv:2206.14169, 2022

  140. [148]

    Accessed: 2026-04-21

    (2025) Iso/iec 27701:2025, information security, cybersecurity and privacy protection — privacy information management systems — requirements and guidance. Accessed: 2026-04-21. [Online]. Available: https://www.iso.org/standard/27701

  141. [149]

    Accessed: 2026-04-21

    (2025) The national institute of standards and technology privacy framework. Accessed: 2026-04-21. [Online]. Available: https://www. nist.gov/privacy-framework

  142. [150]

    Android Developers, Google Play Console Help Center,

    “Android Developers, Google Play Console Help Center,” android- developer/answer, Accessed: 2022-04-30

  143. [151]

    Guttman,An introduction to computer security: the NIST handbook

    B. Guttman,An introduction to computer security: the NIST handbook. US Department of Commerce, Technology Administration, National Institute of . . . , 1995, vol. 800, no. 12

  144. [152]

    Engineering privacy,

    S. Spiekermann and L. F. Cranor, “Engineering privacy,”IEEE Trans- actions on software engineering, vol. 35, no. 1, pp. 67–82, 2008

  145. [153]

    On the privacy of mental health apps: An empirical investigation and its implications for app development,

    L. H. Iwaya, M. A. Babar, A. Rashid, and C. Wijayarathna, “On the privacy of mental health apps: An empirical investigation and its implications for app development,”Empirical Software Engineering, vol. 28, no. 1, p. 2, 2023

  146. [154]

    Temporal mode- checking for runtime monitoring of privacy policies,

    O. Chowdhury, L. Jia, D. Garg, and A. Datta, “Temporal mode- checking for runtime monitoring of privacy policies,” inInternational Conference on Computer Aided Verification. Springer, 2014

  147. [155]

    Atlas: Automatically detecting discrepancies between privacy policies and privacy labels,

    A. Jain, D. Rodriguez, J. M. Del Alamo, and N. Sadeh, “Atlas: Automatically detecting discrepancies between privacy policies and privacy labels,” in2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW). IEEE, 2023, pp. 94–107

  148. [156]

    Mobile-app privacy nutrition labels missing key ingre- dients for success,

    L. F. Cranor, “Mobile-app privacy nutrition labels missing key ingre- dients for success,”Communications of the ACM, vol. 65, no. 11, pp. 26–28, 2022

  149. [157]

    Data safety vs. app privacy: Comparing the usability of android and ios privacy labels,

    Y . Lin, J. Juneja, E. Birrell, and L. Cranor, “Data safety vs. app privacy: Comparing the usability of android and ios privacy labels,” arXiv preprint arXiv:2312.03918, 2023

  150. [158]

    Accessed: 2022-10-10

    Understand app privacy and security practices with google play’s data safety section. Accessed: 2022-10-10. [Online]. Available: https://support.google.com/googleplay/answer/11416267

  151. [159]

    App privacy details on the app store,

    “App privacy details on the app store,” https://developer.apple.com/ app-store/app-privacy-details/, Accessed: 2022-04-30

  152. [160]

    A First Look at Privacy Risks of Android Task-executable V oice Assistant Applications ,

    S. Pan, Y . Ge, and X. Sun, “ A First Look at Privacy Risks of Android Task-executable V oice Assistant Applications ,” in2025 32nd Asia-Pacific Software Engineering Conference (APSEC). Los Alamitos, CA, USA: IEEE Computer Society, Dec. 2025, pp. 347–358. [Online]. Available: ...

  153. [161]

    Derivation of new readability formulas (automated readability index, fog count and flesch reading ease formula) for navy enlisted personnel,

    J. P. Kincaid, R. P. Fishburne Jr, R. L. Rogers, and B. S. Chissom, “Derivation of new readability formulas (automated readability index, fog count and flesch reading ease formula) for navy enlisted personnel,” Naval Technical Training Command Millington TN Research Branch, Te...

  154. [162]

    Privacy at scale: Introducing the privaseer corpus of web privacy policies,

    M. Srinath, S. Wilson, and C. L. Giles, “Privacy at scale: Introducing the privaseer corpus of web privacy policies,” inProceedings of the 59th Annual Meeting of the Association for Computational Linguistics and the 11th International Joint Conference on Natural Language Proce...

  155. [163]

    How short is too short? implications of length and framing on the effectiveness of privacy notices,

    J. Gluck, F. Schaub, A. Friedman, H. Habib, N. Sadeh, L. F. Cranor, and Y . Agarwal, “How short is too short? implications of length and framing on the effectiveness of privacy notices,” inTwelfth symposium on usable privacy and security (SOUPS 2016), 2016, pp. 321–340

  156. [164]

    Impact of app privacy label disclosure on demand: An empirical analysis,

    R. Garg and R. Telang, “Impact of app privacy label disclosure on demand: An empirical analysis,”Available at SSRN 4588747, 2022

  157. [165]

    How usable are ios app privacy labels?

    S. Zhang, Y . Feng, Y . Yao, L. F. Cranor, and N. Sadeh, “How usable are ios app privacy labels?”Proceedings on Privacy Enhancing Technologies, 2022

  158. [166]

    Understanding ios privacy nutrition labels: An exploratory large-scale analysis of app store data,

    Y . Li, D. Chen, T. Li, Y . Agarwal, L. F. Cranor, and J. I. Hong, “Understanding ios privacy nutrition labels: An exploratory large-scale analysis of app store data,” inCHI Conference on Human Factors in Computing Systems Extended Abstracts, 2022, pp. 1–7

  159. [167]

    Exploring{Expandable-Grid}designs to make{iOS}app privacy labels more usable,

    S. Zhang, L. Klucinec, K. Norton, N. Sadeh, and L. F. Cranor, “Exploring{Expandable-Grid}designs to make{iOS}app privacy labels more usable,” inTwentieth Symposium on Usable Privacy and Security (SOUPS 2024), 2024, pp. 139–157

  160. [168]

    Unifying privacy policy detection,

    H. Hosseini, M. Degeling, C. Utz, and T. Hupperich, “Unifying privacy policy detection,”Proceedings on Privacy Enhancing Technologies, 2021

  161. [169]

    Less is not more: Improving findability and action- ability of privacy controls for online behavioral advertising,

    J. Im, R. Wang, W. Lyu, N. Cook, H. Habib, L. F. Cranor, N. Banovic, and F. Schaub, “Less is not more: Improving findability and action- ability of privacy controls for online behavioral advertising,” inPro- ceedings of the 2023 CHI Conference on Human Factors in Computing Sys...

  162. [170]

    The privacy policy landscape after the gdpr,

    T. Linden, R. Khandelwal, H. Harkous, and K. Fawaz, “The privacy policy landscape after the gdpr,”arXiv preprint arXiv:1809.08396, 2018

  163. [171]

    A large-scale investigation of semantically incompatible apis behind compatibility issues in android apps,

    S. Pan, T. Guo, L. Zhang, P. Liu, Z. Xing, and X. Sun, “A large-scale investigation of semantically incompatible apis behind compatibility issues in android apps,”arXiv preprint arXiv:2406.17431, 2024

  164. [172]

    A” nutrition label

    P. G. Kelley, J. Bresee, L. F. Cranor, and R. W. Reeder, “A” nutrition label” for privacy,” inProceedings of the 5th Symposium on Usable Privacy and Security, 2009, pp. 1–12

  165. [173]

    Standardizing privacy notices: an online study of the nutrition label approach,

    P. G. Kelley, L. Cesca, J. Bresee, and L. F. Cranor, “Standardizing privacy notices: an online study of the nutrition label approach,” in Proceedings of the SIGCHI Conference on Human factors in Comput- ing Systems, 2010, pp. 1573–1582

  166. [174]

    Privacy as part of the app decision-making process,

    P. G. Kelley, L. F. Cranor, and N. Sadeh, “Privacy as part of the app decision-making process,” inProceedings of the SIGCHI conference on human factors in computing systems, 2013, pp. 3393–3402

  167. [175]

    Ask the experts: What should be on an iot privacy and security label?

    P. Emami-Naeini, Y . Agarwal, L. F. Cranor, and H. Hibshi, “Ask the experts: What should be on an iot privacy and security label?” in2020 IEEE Symposium on Security and Privacy (SP), 2020

  168. [176]

    App Privacy Details App Store,

    “App Privacy Details App Store,” developer.apple/app-store/, Accessed: 2023-02-20

  169. [177]

    Cranor,Web privacy with P3P

    L. Cranor,Web privacy with P3P. ” O’Reilly Media, Inc.”, 2002

  170. [178]

    Platform for privacy preferences (p3p) project,

    Lorrie Cranor and Rigo Wenning, “Platform for privacy preferences (p3p) project,” 2025, https://www.w3.org/P3P/ Accessed: 2025-11-03

  171. [179]

    A survey of privacy policy languages,

    P. Kumaraguru, L. Cranor, J. Lobo, and S. Calo, “A survey of privacy policy languages,” inWorkshop on Usable IT Security Management (USM 07): Proceedings of the 3rd Symposium on Usable Privacy and Security, ACM, 2007

  172. [180]

    Contextual privacy policies for mobile appli- cations and an approach toward automated generation,

    Z. Tao and S. Pan, “Contextual privacy policies for mobile appli- cations and an approach toward automated generation,” inSE2026. Gesellschaft f ¨ur Informatik, Bonn, 2026, pp. 10–18 420

  173. [181]

    Clear: Towards con- textual llm-empowered privacy policy analysis and risk generation for large language model applications,

    C. Chen, D. Zhou, Y . Ye, T. J.-j. Li, and Y . Yao, “Clear: Towards con- textual llm-empowered privacy policy analysis and risk generation for large language model applications,”arXiv preprint arXiv:2410.13387, 2024

  174. [182]

    Informing the design of a personalized privacy assistant for the internet of things,

    J. Colnago, Y . Feng, T. Palanivel, S. Pearman, M. Ung, A. Acquisti, L. F. Cranor, and N. Sadeh, “Informing the design of a personalized privacy assistant for the internet of things,” inProceedings of the 2020 CHI Conference on Human Factors in Computing Systems, 2020

  175. [183]

    From procedures to peril: Towards risk transparency in information privacy for users,

    N. Ebert, S. Fischer-H ¨ubner, S. Human, A. Kitkowska, K. Kollnig, J. Mitrovi´c, S. Pan, T. Schaltegger, F. Schaub, D. Smullenet al., “From procedures to peril: Towards risk transparency in information privacy for users,”Telecommunications Policy, vol. 50, no. 5, p. 103195, 2026

  176. [184]

    Accessed: 2026-04-21

    (2026) The usable privacy policy project. Accessed: 2026-04-21. [Online]. Available: https://usableprivacy.org/data

  177. [185]

    Honeysuckle: Annotation-guided code generation of in-app privacy notices,

    T. Li, E. B. Neundorfer, Y . Agarwal, and J. I. Hong, “Honeysuckle: Annotation-guided code generation of in-app privacy notices,”Pro- ceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies, vol. 5, no. 3, pp. 1–27, 2021. 18

Pith tools

Reviewed August 16, 2026 · model on record in the stance chip above.