REVIEW 3 major objections 4 minor 185 references
SoK: From Generation to Consumption of Privacy Documents in Software Systems
T0 review · 3 major / 4 minor · reviewed 2026-08-16 · deepseek-v4-flash
Pith's one-line read This paper maps 290 privacy-document papers into a five-stage lifecycle and argues generation is the least supported stage.
desk verdict A genuinely useful lifecycle SoK with a transparent methodology; the quantitative claims need a coding-reliability check and a real artifact before the numbers can be trusted as field-level facts. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing object is the lifecycle codebook: five research questions (RQ1–RQ5) that define how a privacy document is scoped, generated, analyzed, checked for consistency and compliance, and consumed. The coding procedure — keyword search over titles and abstracts, two-author screening, forward and backward snowballing, and open coding of 425 candidates down to 290 — is what converts the taxonomy into quantitative claims like T4 (generation at 11%). The codebook also supplies the numbering scheme (T# for trends, O# for opportunities, D# for directions) that lets the paper state cross-stage dependencies.
What would settle it
Replicate the corpus construction with full-text searches, a broader venue list, and non-English databases, then re-code the lifecycle stages. If the generation share moves well above 11%, or the policy share moves well below 227 of 290, the paper's quantitative trends are artifacts of search design. A cheaper check: take one year, such as 2023, run the paper's own keyword query without venue restrictions, and count how many relevant papers the 32-venue list missed.
Extended reading notes
Core claim
On the paper's own terms, the central discovery is the lifecycle taxonomy and the imbalance it exposes. Across 290 papers, five stages absorb very different amounts of attention: content analysis (205 papers, 70.7%), consistency and compliance (130, 44.8%), usability (126, 43.4%), and generation (32, 11.0%), with the scope questions (RQ1) running through all of them. The paper argues this imbalance is structural — mature Android program-analysis frameworks make mobile software–policy consistency checking tractable, GDPR gives compliance work a clear regulatory target, and generation tools remain artifact-driven prototypes rather than collaborative workflows. From this map it derives 15 trends, 21 open opportunities, and four directions, the last organized around AI-centric platforms, data foundations, LLM-based policy-code analysis, and dual usability for end-users and developers.
Load-bearing premise
The map stands or falls on whether the 290-paper corpus fairly represents the field, which the paper itself notes is constrained by English-only title and abstract searches and a restricted venue set.
Editorial extensions
If this is right
- If the lifecycle map is accurate, future privacy-document work should invest disproportionately in generation, traceability, and developer-facing tooling, since that is the stage with the least existing support.
- AI-centric platforms will require new document formats and consent mechanisms, because prompts, chat history, and autonomous agent actions do not fit the permission-and-API model that current consistency checking assumes.
- LLM-based analysis of policies should be paired with human-in-the-loop verification and evidence grounding, since the review identifies hallucination and limited explainability as open problems rather than solved ones.
- Consistency research should move from pairwise comparisons, such as policy versus label, to multilateral comparisons across policies, labels, permissions, manifests, and settings.
- Dataset efforts should be longitudinal, multilingual, and multi-source, because the review finds that existing text-only English policy corpora bottleneck almost every stage.
Reading between the lines
- Editorial inference: if T4's 11% figure holds up, the highest-leverage place for new tools is probably generation, because inaccurate or untraceable documents poison every downstream stage — analysis, compliance, and usability alike.
- Editorial inference: the deliberate exclusion of Terms of Service research means consent-related work in that adjacent space is invisible to the map; a ToS-inclusive re-run could shift the compliance-stage counts and opportunities.
- Editorial inference: a concrete test of direction D3 would be to benchmark LLM-based policy-code alignment against the manual-analysis findings the review collects, using the same 290-paper corpus and the same codebook categories.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. This SoK systematizes the literature on privacy documents (privacy policies, labels, notices, etc.) from a software-engineering lifecycle perspective. The authors systematically searched 32 CORE B+ venues plus snowballing, screened 10121 raw hits down to 290 analyzed papers published 2010–2025, and open-coded them along five research questions spanning definition/scope, generation, analysis, consistency/compliance, and usability. They report 15 research trends, 21 open opportunities, and four research directions, and they provide a quantitative map of the field (e.g., privacy policies appear in 227/290 papers; generation is 11% of the corpus; GDPR is the dominant regulatory frame). The paper's main claim is that this taxonomy and these distributions form an accurate and useful map of the field.
Significance. If the coding is reliable and the corpus is representative, this is the first lifecycle-wide systematization of privacy document research, covering a broader scope than prior surveys (e.g., Schaub et al. 2015, Javed and Sajid 2024). The paper provides a reusable codebook, an explicit venue list, and a clear link between the five RQs and the taxonomy, and its quantitative counts give the community a point of comparison for future work. The strengths are the transparent SLR-based process, the cross-stage analysis (generation→compliance→usability dependencies), and the concrete, actionable research agenda (D1–D4). These contributions merit publication if the synthesis is independently verifiable.
major comments (3)
- [III-B]
- [III-A]
- [III-A]
minor comments (4)
- [I]
- [Fig. 1]
- [VI-B]
- [References]
Circularity Check
No significant circularity: the SoK's trends are inductive corpus counts, not derivations from their own conclusions.
full rationale
This SoK makes no first-principles derivation; its central outputs (15 trends, 21 opportunities, 4 directions) are inductive summaries of a 290-paper corpus coded by three annotators. None of the quantitative claims (e.g., T1 policies in 227/290, T4 generation at 11%, T12 GDPR dominance) is computed from a fitted parameter that is later renamed as a prediction; each is a direct frequency over the manually constructed codebook. The paper's inclusion criteria do shape the corpus (English-only papers, title/abstract keyword screening, ToS exclusion, CORE B+ venues), and Section III-D admits title/abstract-only searching. These choices could bias trends T1 and T3; for example, an English-only paper-language criterion does not by itself force the document-language finding, since English-written papers can analyze German or Chinese policies, and the policy-heavy keyword query may inflate policy-related counts. Such bias is a sampling/validity threat, not a definitional reduction: the trends are not used as inputs to the screening decisions, and there is no equation or fitted value whose output is its own input. The many author self-citations in Section V (e.g., PCapGen [93], PAcT [78], PriGen [74] in O3-O5) are illustrative examples of open opportunities rather than load-bearing evidence for the taxonomy; the taxonomy rests on the coded corpus. Section VI-A's observation that only 12 of 37 manual-coding papers report Cohen's Kappa, and Section III-D's statement that no agreement was calculated for the initial code-development stage, are reproducibility limitations, not circularity. Overall, the paper's synthesis claims are self-contained relative to its own corpus construction; no circularity score above 0 is warranted.
Assumptions & free parameters
assumptions (5)
- domain assumption Privacy documents are defined to include policies, labels, notices, and consent disclosures, but to exclude Terms of Service.
- domain assumption CORE ranking B or higher is a sufficient quality and completeness proxy for the seed venue list.
- domain assumption Absence of the English keywords in title/abstract implies a paper is not primarily about privacy documents.
- domain assumption One round of forward and backward snowballing reaches saturation.
- domain assumption Consensus-based open coding without an inter-annotator agreement metric yields a consistent codebook.
Cite this review
Pith. "Pith review of SoK: From Generation to Consumption of Privacy Documents in Software Systems." pith.science (2026). https://pith.science/paper/CGWNPU7Y
@misc{pith2026260812511,
author = {Pith},
title = {Pith review of: SoK: From Generation to Consumption of Privacy Documents in Software Systems},
year = {2026},
howpublished = {\url{https://pith.science/paper/CGWNPU7Y}},
note = {Machine review of arXiv:2608.12511}
}
read the original abstract
Privacy documents (e.g., privacy policies) are a central mechanism through which digital services disclose data practices and seek user consent. Over the past decades, research on privacy documents has expanded significantly, encompassing not only traditional privacy policies but also short notices (e.g., privacy labels) and interface-level transparency mechanisms. As this research area continues to grow, it has become increasingly difficult to obtain a coherent view of how privacy documents are created, analyzed, evaluated, and maintained across their lifecycle. This SoK provides a unified, lifecycle-oriented view of privacy documents from a software engineering perspective. We systematically review and analyze 290 papers published between 2010 and 2025, organizing them around five research questions that examine how privacy documents are (1) defined and scoped, (2) generated, (3) analyzed and extracted, (4) checked for inconsistencies and noncompliance, and (5) evaluated and improved for usability. Building on our findings, we identify 15 key research trends and 21 open opportunities. We further chart four broader research directions that highlight (i) emerging challenges in AI-centric platforms, (ii) the need for diverse and up-to-date data foundations, (iii) LLM-based unified policy-code analysis, and (iv) dual usability for end-users and developers. We hope this SoK provides a shared foundation for future research on privacy policies and privacy documents.
Figures
Reference graph
Works this paper leans on
-
[1]
General data protection regulation (GDPR),
GDPR, “General data protection regulation (GDPR),” https://gdpr-info. eu/, Retrieved: 2022-04-25
2022
-
[2]
California consumer privacy act of 2018 (CCPA),
CCPA, “California consumer privacy act of 2018 (CCPA),” https://oag. ca.gov/privacy/ccpa, Accessed: 2022-04-25
2018
-
[3]
Brazilian general data protection law (LGPD),
LGPD, “Brazilian general data protection law (LGPD),” http:// www.planalto.gov.br/ccivil 03/ Ato2015-2018/2018/Lei/L13709.htm, Retrieved: 2022-08-26
2018
-
[4]
Personal information protection law of the people’s re- public of china (PIPL),
PIPL, “Personal information protection law of the people’s re- public of china (PIPL),” http://www.npc.gov.cn/npc/c30834/202108/ a8c4e3672c74491a80b53a172bb753fe.shtml, Accessed: 2022-04-25
2022
-
[5]
Australian privacy principles (APP),
APPs, “Australian privacy principles (APP),” https://www.oaic.gov.au/ privacy/australian-privacy-principles, Accessed: 2022-05-03
2022
-
[6]
The usable privacy policy project: Combining crowdsourc- ing,
N. Sadeh, A. Acquisti, T. D. Breaux, L. F. Cranor, A. M. McDonald, J. R. Reidenberg, N. A. Smith, F. Liu, N. C. Russell, F. Schaub et al., “The usable privacy policy project: Combining crowdsourc- ing,”Machine Learning and Natural Language Processing to Semi- Automatically Answer Those Privacy Questions Users Care About, pp. 1–24, 2013
2013
-
[7]
Privacy policies over time: Curation and analysis of a million-document dataset,
R. Amos, G. Acar, E. Lucherini, M. Kshirsagar, A. Narayanan, and J. Mayer, “Privacy policies over time: Curation and analysis of a million-document dataset,” inProceedings of the Web Conference 2021, 2021, pp. 2165–2176
2021
-
[8]
Identifying the provision of choices in privacy policy text,
K. M. Sathyendra, S. Wilson, F. Schaub, S. Zimmeck, and N. Sadeh, “Identifying the provision of choices in privacy policy text,” inProceed- ings of the 2017 conference on empirical methods in natural language processing, 2017, pp. 2774–2779
2017
Show all 185 references
-
[9]
Researchers’ experiences in analyzing pri- vacy policies: Challenges and opportunities,
A. Mhaidli, S. Fidan, A. Doan, G. Herakovic, M. Srinath, L. Matheson, S. Wilson, and F. Schaub, “Researchers’ experiences in analyzing pri- vacy policies: Challenges and opportunities,”Proceedings on Privacy Enhancing Technologies, 2023
2023
-
[10]
Policychecker: Analyzing the gdpr completeness of mobile apps’ privacy policies,
A. Xiang, W. Pei, and C. Yue, “Policychecker: Analyzing the gdpr completeness of mobile apps’ privacy policies,” inProceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security, 2023, pp. 3373–3387
2023
-
[11]
Vpvet: Vetting privacy policies of virtual reality apps,
Y . Zhan, Y . Meng, L. Zhou, Y . Xiong, X. Zhang, L. Ma, G. Chen, Q. Pei, and H. Zhu, “Vpvet: Vetting privacy policies of virtual reality apps,” inProceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security, 2024, pp. 1746–1760
2024
-
[12]
{POLICYCOMP}: Counterpart comparison of privacy policies uncovers overbroad personal data collection practices,
L. Zhou, C. Wei, T. Zhu, G. Chen, X. Zhang, S. Du, H. Cao, and H. Zhu, “{POLICYCOMP}: Counterpart comparison of privacy policies uncovers overbroad personal data collection practices,” in32nd USENIX Security Symposium (USENIX Security 23), 2023
2023
-
[13]
Share first, ask later (or never?) studying violations of{GDPR’s}explicit consent in android apps,
T. T. Nguyen, M. Backes, N. Marnau, and B. Stock, “Share first, ask later (or never?) studying violations of{GDPR’s}explicit consent in android apps,” in30th USENIX Security Symposium (USENIX Security 21), 2021, pp. 3667–3684
2021
-
[14]
The biggest lie on the internet: Ignoring the privacy policies and terms of service policies of social networking services,
J. A. Obar and A. Oeldorf-Hirsch, “The biggest lie on the internet: Ignoring the privacy policies and terms of service policies of social networking services,”Information, Communication & Society, vol. 23, no. 1, pp. 128–147, 2020
2020
-
[15]
Privacy policies across the ages: content of privacy policies 1996–2021,
I. Wagner, “Privacy policies across the ages: content of privacy policies 1996–2021,”ACM Transactions on Privacy and Security, vol. 26, no. 3, pp. 1–32, 2023
1996
-
[16]
Readability of privacy policies of healthcare websites,
T. Ermakova, B. Fabian, and E. Babina, “Readability of privacy policies of healthcare websites,” inWirtschaftsinformatik Proceedings, 2015
2015
-
[17]
Improving readability of online privacy policies through doop: A domain ontology for online privacy,
D. A. Audich, R. Dara, and B. Nonnecke, “Improving readability of online privacy policies through doop: A domain ontology for online privacy,”Digital, vol. 1, no. 4, pp. 198–215, 2021
2021
-
[18]
Law in books and law in action: The readability of privacy policies and the gdpr,
S. I. Becher and U. Benoliel, “Law in books and law in action: The readability of privacy policies and the gdpr,” inConsumer law and economics. Springer, 2020, pp. 179–204
2020
-
[19]
An informative security and privacy “nutrition
P. Emami-Naeini, J. Dheenadhayalan, Y . Agarwal, and L. F. Cranor, “An informative security and privacy “nutrition” label for internet of things devices,”IEEE Security & Privacy, vol. 20, no. 2, pp. 31–39, 2021
2021
-
[20]
Automating contextual privacy policies: Design and evaluation of a production tool for digital consumer privacy awareness,
M. Windl, N. Henze, A. Schmidt, and S. S. Feger, “Automating contextual privacy policies: Design and evaluation of a production tool for digital consumer privacy awareness,” inProceedings of the 2022 CHI Conference on Human Factors in Computing Systems, 2022
2022
-
[21]
A NEW HOPE: Contextual privacy policies for mobile applications and an approach toward automated 14 generation,
S. Pan, Z. Tao, T. Hoang, D. Zhang, T. Li, Z. Xing, X. Xu, M. Staples, T. Rakotoarivelo, and D. Lo, “A NEW HOPE: Contextual privacy policies for mobile applications and an approach toward automated 14 generation,” in33rd USENIX Security Symposium (USENIX Security 24). Philadel...
2024
-
[22]
Towards context-aware mobile privacy notice: Implementation of a deployable contextual privacy policies generator,
H. Gong, Z. Tao, S. Pan, Z. Xing, and X. Sun, “Towards context-aware mobile privacy notice: Implementation of a deployable contextual privacy policies generator,”arXiv preprint arXiv:2509.22900, 2025
2025
-
[23]
Static checking of gdpr- related privacy compliance for object-oriented distributed systems,
S. Tokas, O. Owe, and T. Ramezanifarkhani, “Static checking of gdpr- related privacy compliance for object-oriented distributed systems,” Journal of Logical and Algebraic Methods in Programming, vol. 125, p. 100733, 2022
2022
-
[24]
Examining the integrity of apple’s privacy labels: Gdpr compliance and unnecessary data collection in ios apps,
Z. A. Surma, S. Gowdar, and H. J. Pandit, “Examining the integrity of apple’s privacy labels: Gdpr compliance and unnecessary data collection in ios apps,”Information, vol. 15, no. 9, p. 551, 2024
2024
-
[25]
i-right: Identifying and classifying gdpr user rights in fitness tracker and smart home privacy policies,
A. D. Kounoudes, G. M. Kapitsaki, and I. Katakis, “i-right: Identifying and classifying gdpr user rights in fitness tracker and smart home privacy policies,” inInternational Conference on Web Information Systems Engineering. Springer, 2024, pp. 243–254
2024
-
[26]
Setting the bar low: Are websites complying with the minimum requirements of the ccpa?
M. Van Nortwick and C. Wilson, “Setting the bar low: Are websites complying with the minimum requirements of the ccpa?”Proceedings on Privacy Enhancing Technologies, 2022
2022
-
[27]
A systematic review of privacy policy litera- ture,
Y . Javed and A. Sajid, “A systematic review of privacy policy litera- ture,”ACM Computing Surveys, vol. 57, no. 2, pp. 1–43, 2024
2024
-
[28]
Natural language processing of privacy policies: A survey,
A. Adhikari, S. Das, and R. Dewri, “Natural language processing of privacy policies: A survey,”arXiv preprint arXiv:2501.10319, 2025
2025 arXiv
-
[29]
Privacy policy: challenges and trends in research,
H. Alamri, C. Maple, and G. Epiphaniou, “Privacy policy: challenges and trends in research,” inIET Conference Proceedings CP846. IET, 2023, pp. 170–181
2023
-
[30]
A design space for effective privacy notices,
F. Schaub, R. Balebako, A. L. Durity, and L. F. Cranor, “A design space for effective privacy notices,” inSymposium on Usable Privacy and Security (SOUPS). USENIX Association, 2015, pp. 1–17
2015
-
[31]
Polisis: Automated analysis and presentation of privacy policies using deep learning,
H. Harkous, K. Fawaz, R. Lebret, F. Schaub, K. G. Shin, and K. Aberer, “Polisis: Automated analysis and presentation of privacy policies using deep learning,” in27th USENIX Security Symposium (USENIX Security 18), 2018, pp. 531–548
2018
-
[32]
{PolicyLint}: investigating internal privacy pol- icy contradictions on google play,
B. Andow, S. Y . Mahmud, W. Wang, J. Whitaker, W. Enck, B. Reaves, K. Singh, and T. Xie, “{PolicyLint}: investigating internal privacy pol- icy contradictions on google play,” in28th USENIX security symposium (USENIX security 19), 2019, pp. 585–602
2019
-
[33]
Actions speak louder than words:{Entity-Sensitive} privacy policy and data flow analysis with{PoliCheck},
B. Andow, S. Y . Mahmud, J. Whitaker, W. Enck, B. Reaves, K. Singh, and S. Egelman, “Actions speak louder than words:{Entity-Sensitive} privacy policy and data flow analysis with{PoliCheck},” in29th USENIX Security Symposium (USENIX Security 20), 2020
2020
-
[34]
{PoliGraph}: Automated privacy policy analysis using knowledge graphs,
H. Cui, R. Trimananda, A. Markopoulou, and S. Jordan, “{PoliGraph}: Automated privacy policy analysis using knowledge graphs,” in32nd USENIX Security Symposium, 2023, pp. 1037–1054
2023
-
[35]
How private is your period?: A systematic analysis of menstrual app privacy policies,
L. Shipp and J. Blasco, “How private is your period?: A systematic analysis of menstrual app privacy policies,”Proceedings on Privacy Enhancing Technologies, 2020
2020
-
[36]
Evolution of composition, read- ability, and structure of privacy policies over two decades,
A. Adhikari, S. Das, and R. Dewri, “Evolution of composition, read- ability, and structure of privacy policies over two decades,”Proceedings on Privacy Enhancing Technologies, 2023
2023
-
[37]
Evaluating the readability of privacy policies in mobile environments,
R. I. Singh, M. Sumeeth, and J. Miller, “Evaluating the readability of privacy policies in mobile environments,”International Journal of Mobile Human Computer Interaction (IJMHCI), vol. 3, no. 1, pp. 55– 78, 2011
2011
-
[38]
Systematic literature reviews in software engineering– a systematic literature review,
B. Kitchenham, O. P. Brereton, D. Budgen, M. Turner, J. Bailey, and S. Linkman, “Systematic literature reviews in software engineering– a systematic literature review,”Information and software technology, vol. 51, no. 1, pp. 7–15, 2009
2009
-
[39]
Core conference rankings search page,
Computing Research and Education Association of Australasia (CORE), “Core conference rankings search page,” https://portal.core. edu.au/conf-ranks/, accessed: 2025-12-22
2025
-
[40]
dblp: computer science bibliography,
dblp team, “dblp: computer science bibliography,” 2025, https://dblp. uni-trier.de/ Accessed: 2025-11-03
2025
-
[41]
Multilingual scraper of privacy policies and terms of service,
D. Bernhard, L. Nenadic, S. Bechtold, and K. Kubicek, “Multilingual scraper of privacy policies and terms of service,” inProceedings of the 2025 Symposium on Computer Science and Law, 2025, pp. 55–63
2025
-
[42]
Guidelines for snowballing in systematic literature studies and a replication in software engineering,
C. Wohlin, “Guidelines for snowballing in systematic literature studies and a replication in software engineering,” inProceedings of the 18th International Conference on Evaluation and Assessment in Software Engineering. Association for Computing Machinery, 2014. [Online]. Ava...
2014
-
[43]
Qualitative data analysis a methods sourcebook,
A. Hubermanet al., “Qualitative data analysis a methods sourcebook,” 2014
2014
-
[44]
Qualitative content analysis: A step-by-step guide,
P. Mayring, “Qualitative content analysis: A step-by-step guide,” 2021
2021
-
[45]
Reliability and inter- rater reliability in qualitative research: Norms and guidelines for cscw and hci practice,
N. McDonald, S. Schoenebeck, and A. Forte, “Reliability and inter- rater reliability in qualitative research: Norms and guidelines for cscw and hci practice,”Proceedings of the ACM on human-computer interaction, vol. 3, no. CSCW, pp. 1–23, 2019
2019
-
[46]
A lon- gitudinal measurement of privacy policy evolution for large language models,
Z. Tao, S. Pan, Z. Xing, E. Black, T. Gillis, and C. Chen, “A lon- gitudinal measurement of privacy policy evolution for large language models,”arXiv preprint arXiv:2511.21758, 2025
2025
-
[47]
Modeling language vagueness in privacy policies using deep neural networks
F. Liu, N. L. Fella, and K. Liao, “Modeling language vagueness in privacy policies using deep neural networks.” inAAAI Fall Symposia, 2016
2016
-
[48]
Do cookie banners respect my choice?: Measuring legal compliance of banners from iab europe’s transparency and consent framework,
C. Matte, N. Bielova, and C. Santos, “Do cookie banners respect my choice?: Measuring legal compliance of banners from iab europe’s transparency and consent framework,” in2020 IEEE Symposium on Security and Privacy (SP). IEEE, 2020, pp. 791–809
2020
-
[49]
Automating cookie consent and{GDPR}violation detection,
D. Bollinger, K. Kubicek, C. Cotrini, and D. Basin, “Automating cookie consent and{GDPR}violation detection,” in31st USENIX Security Symposium (USENIX Security 22), 2022, pp. 2893–2910
2022
-
[50]
Automated cookie notice analysis and enforcement,
R. Khandelwal, A. Nayak, H. Harkous, and K. Fawaz, “Automated cookie notice analysis and enforcement,” in32nd USENIX Security Symposium (USENIX Security 23), 2023, pp. 1109–1126
2023
-
[51]
Auto- mated{Large-Scale}analysis of cookie notice compliance,
A. Bouhoula, K. Kubicek, A. Zac, C. Cotrini, and D. Basin, “Auto- mated{Large-Scale}analysis of cookie notice compliance,” in33rd USENIX Security Symposium (USENIX Security 24), 2024, pp. 1723– 1739
2024
-
[52]
Supporting informed choices about browser cookies: The impact of personalised cookie banners,
T. Biselli, L. Utz, and C. Reuter, “Supporting informed choices about browser cookies: The impact of personalised cookie banners,” Proceedings on Privacy Enhancing Technologies, 2024
2024
-
[53]
Crumbling cookie categories: Deconstructing common cookie categories to create categories that people understand,
S. Jiwani, R. Sasheendran, A. Abhyankar, E. Bouma-Sims, and L. Cra- nor, “Crumbling cookie categories: Deconstructing common cookie categories to create categories that people understand,”Proceedings on Privacy Enhancing Technologies, 2024
2024
-
[54]
Toward the cure of privacy policy reading phobia: Automated gener- ation of privacy nutrition labels from privacy policies,
S. Pan, T. Hoang, D. Zhang, Z. Xing, X. Xu, Q. Lu, and M. Staples, “Toward the cure of privacy policy reading phobia: Automated gener- ation of privacy nutrition labels from privacy policies,”arXiv preprint arXiv:2306.10923, 2023
2023 arXiv
-
[55]
Toggles, dollar signs, and triangles: How to (in) effectively convey privacy choices with icons and link texts,
H. Habib, Y . Zou, Y . Yao, A. Acquisti, L. Cranor, J. Reidenberg, N. Sadeh, and F. Schaub, “Toggles, dollar signs, and triangles: How to (in) effectively convey privacy choices with icons and link texts,” inProceedings of the 2021 CHI Conference on Human Factors in Computing ...
2021
-
[56]
Are we getting well-informed? an in-depth study of runtime privacy notice practice in mobile apps,
S. Li, Z. Yang, Y . Nan, S. Yu, Q. Zhu, and M. Yang, “Are we getting well-informed? an in-depth study of runtime privacy notice practice in mobile apps,” inProceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security, 2024, pp. 1581–1595
2024
-
[57]
Ml-based compliance verification of data processing agreements against gdpr,
O. Amaral, S. Abualhaija, and L. Briand, “Ml-based compliance verification of data processing agreements against gdpr,” in2023 IEEE 31st international requirements engineering conference (RE). IEEE, 2023, pp. 53–64
2023
-
[58]
(un) informed consent: Studying gdpr consent notices in the field,
C. Utz, M. Degeling, S. Fahl, F. Schaub, and T. Holz, “(un) informed consent: Studying gdpr consent notices in the field,” inProceedings of the 2019 acm sigsac conference on computer and communications security, 2019, pp. 973–990
2019
-
[59]
A tale of two regulatory regimes: Creation and analysis of a bilingual privacy policy corpus,
S. Arora, H. Hosseini, C. Utz, V . B. Kumar, T. Dhellemmes, A. Ravichander, P. Story, J. Mangat, R. Chen, M. Degelinget al., “A tale of two regulatory regimes: Creation and analysis of a bilingual privacy policy corpus,” inProceedings of the thirteenth language resources and e...
2022
-
[60]
Regulatory compliance with limited enforceability: Evidence from privacy policies,
B. Ganglmair, J. Kr ¨amer, and J. Gambato, “Regulatory compliance with limited enforceability: Evidence from privacy policies,”ZEW-Centre for European Economic Research Discussion Paper, no. 24-012, 2024
2024
-
[61]
Privacy policies in medium-sized european town ad- ministrations: A comparative analysis of english and german-speaking countries,
H. Hosseini, “Privacy policies in medium-sized european town ad- ministrations: A comparative analysis of english and german-speaking countries,” inProceedings of the 11th International Conference on Information Systems Security and Privacy (ICISSP 2025), 2025
2025
-
[62]
A bilingual longitudinal analysis of privacy policies measuring the impacts of the gdpr and the ccpa/cpra,
H. Hosseini, C. Utz, M. Degeling, and T. Hupperich, “A bilingual longitudinal analysis of privacy policies measuring the impacts of the gdpr and the ccpa/cpra,” 2024
2024
-
[63]
Fair balancing? evaluating llm-based privacy policy ethics assessments
V . Freiberger and E. Buchmann, “Fair balancing? evaluating llm-based privacy policy ethics assessments.” inEWAF, 2024
2024
-
[64]
Effective regulation and firm compliance: The case of german privacy policies,
J. Gambato, B. Ganglmair, and J. K. Kr ¨amer, “Effective regulation and firm compliance: The case of german privacy policies,” National Bureau of Economic Research, Tech. Rep., 2024. 15
2024
-
[65]
Evaluating the privacy policy of android apps: a privacy policy compliance study for popular apps in china and europe,
K. Liu, G. Xu, X. Zhang, G. Xu, and Z. Zhao, “Evaluating the privacy policy of android apps: a privacy policy compliance study for popular apps in china and europe,”Scientific Programming, vol. 2022, no. 1, p. 2508690, 2022
2022
-
[66]
Personal information protection and privacy policy compliance of health code apps in china: Scale development and content analysis,
J. Jiang and Z. Zheng, “Personal information protection and privacy policy compliance of health code apps in china: Scale development and content analysis,”JMIR mHealth and uHealth, vol. 11, 2023
2023
-
[67]
An analysis of privacy policies of public covid- 19 apps: Evidence from india,
S. J. De and R. Shukla, “An analysis of privacy policies of public covid- 19 apps: Evidence from india,”Journal of Public Affairs, vol. 22, p. e2801, 2022
2022
-
[68]
A study of south asian websites on privacy compliance,
Y . Javed, K. M. Salehin, and M. Shehab, “A study of south asian websites on privacy compliance,”IEEE Access, vol. 8, 2020
2020
-
[69]
Privacyflash pro: automat- ing privacy policy generation for mobile apps,
S. Zimmeck, R. Goldstein, and D. Baraka, “Privacyflash pro: automat- ing privacy policy generation for mobile apps,” in28th Network and Distributed System Security Symposium (NDSS 2021). NDSS, 2021
2021
-
[70]
A large-scale empirical study of online automated privacy policy generators for mobile apps,
S. Pan, D. Zhang, M. Staples, Z. Xing, J. Chen, X. Xu, and J. Hoang, “A large-scale empirical study of online automated privacy policy generators for mobile apps,”arXiv preprint arXiv:2305.03271, 2023
2023 arXiv
-
[71]
Optimizing a policy authoring framework for security and privacy policies,
M. Johnson, J. Karat, C.-M. Karat, and K. Grueneberg, “Optimizing a policy authoring framework for security and privacy policies,” in Proceedings of the Sixth Symposium on Usable Privacy and Security, 2010, pp. 1–9
2010
-
[72]
Toward automatically generating privacy policy for android apps,
L. Yu, T. Zhang, X. Luo, L. Xue, and H. Chang, “Toward automatically generating privacy policy for android apps,”IEEE Transactions on Information Forensics and Security, vol. 12, no. 4, pp. 865–880, 2016
2016
-
[73]
Matcha: An ide plugin for creating accurate privacy nutrition labels,
T. Li, L. F. Cranor, Y . Agarwal, and J. I. Hong, “Matcha: An ide plugin for creating accurate privacy nutrition labels,”Proceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies, vol. 8, no. 1, pp. 1–38, 2024
2024
-
[74]
Towards fine- grained localization of privacy behaviors,
V . Jain, S. Ghanavati, S. T. Peddinti, and C. McMillan, “Towards fine- grained localization of privacy behaviors,” in2023 IEEE 8th European Symposium on Security and Privacy (EuroS&P). IEEE, 2023, pp. 258–277
2023
-
[75]
Enhancing transparency and accountability of tpls with pbom: A privacy bill of materials,
Y . Xiao, A. Nadkarni, and X. Liao, “Enhancing transparency and accountability of tpls with pbom: A privacy bill of materials,” in Proceedings of the 2024 Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses, 2023, pp. 1–11
2024
-
[76]
Autoppg: Towards automatic generation of privacy policy for android applications,
L. Yu, T. Zhang, X. Luo, and L. Xue, “Autoppg: Towards automatic generation of privacy policy for android applications,” inProceedings of the 5th Annual ACM CCS Workshop on Security and Privacy in Smartphones and Mobile Devices, 2015, pp. 39–50
2015
-
[77]
Creating consistent privacy notices by translating code segments into privacy captions,
V . Jain, “Creating consistent privacy notices by translating code segments into privacy captions,” in2022 IEEE 30th International Requirements Engineering Conference (RE), pp. 201–206
-
[78]
Pact: Detecting and classifying privacy behavior of android applica- tions,
V . Jain, S. D. Gupta, S. Ghanavati, S. T. Peddinti, and C. McMillan, “Pact: Detecting and classifying privacy behavior of android applica- tions,” inProceedings of the 15th ACM Conference on Security and Privacy in Wireless and Mobile Networks, 2022, pp. 104–118
2022
-
[79]
Visual configuration of mobile privacy policies,
A. Aydin, D. Piorkowski, O. Tripp, P. Ferrara, and M. Pistoia, “Visual configuration of mobile privacy policies,” inInternational Conference on Fundamental Approaches to Software Engineering. Springer, 2017, pp. 338–355
2017
-
[80]
Toward automatically generating privacy policy for smart home apps,
Y . Li, Y . Zhang, H. Zhu, and S. Du, “Toward automatically generating privacy policy for smart home apps,” inIEEE INFOCOM 2021-IEEE Conference on Computer Communications Workshops (INFOCOM WKSHPS). IEEE, 2021, pp. 1–7
2021
-
[81]
A user requirements-oriented privacy policy self-adaption scheme in cloud computing,
C. Ke, F. Xiao, Z. Huang, and F. Xiao, “A user requirements-oriented privacy policy self-adaption scheme in cloud computing,”Frontiers of Computer Science, vol. 17, no. 2, p. 172203, 2023
2023
-
[82]
Extracting lpl privacy policy purposes from annotated web service source code,
K. Hjerppe, J. Ruohonen, and V . Lepp ¨anen, “Extracting lpl privacy policy purposes from annotated web service source code,”Software and Systems Modeling, vol. 22, no. 1, pp. 331–349, 2023
2023
-
[83]
Pripocog: Empowering end-users’ data protection decisions,
J. Leicht, J. Lukasewycz, and M. Heisel, “Pripocog: Empowering end-users’ data protection decisions,” inProceedings of the 27th International Conference on Enterprise Information Systems - Volume 2: ICEIS, INSTICC. SciTePress, 2025, pp. 668–679
2025
-
[84]
Make privacy policies longer and appoint llm readers,
P. Pałka, F. Lagioia, R. Liepina, M. Lippi, and G. Sartor, “Make privacy policies longer and appoint llm readers,”Artificial Intelligence and Law, pp. 1–33, 2025
2025
-
[85]
Privacy policies on the fediverse: A case study of mastodon instances,
E. Tosch, L. Garcia, C. Li, and C. Martens, “Privacy policies on the fediverse: A case study of mastodon instances,”Proceedings on Privacy Enhancing Technologies, 2024
2024
-
[86]
Privacy bills of materials (pribom): A transparent privacy information inventory for collaborative privacy notice generation in mobile app development,
Z. Tao, S. Pan, Z. Xing, X. Sun, O. Haggag, J. Grundy, J. Li, and L. Zhu, “Privacy bills of materials (pribom): A transparent privacy information inventory for collaborative privacy notice generation in mobile app development,” inThe 25th Privacy Enhancing Technologies Symposi...
2025
-
[87]
Analysis of privacy policies to enhance informed consent,
R. Pardo and D. Le M ´etayer, “Analysis of privacy policies to enhance informed consent,” inIFIP Annual Conference on Data and Applica- tions Security and Privacy. Springer, 2019, pp. 177–198
2019
-
[88]
Privee: An architecture for auto- matically analyzing web privacy policies,
S. Zimmeck and S. M. Bellovin, “Privee: An architecture for auto- matically analyzing web privacy policies,” in23rd USENIX Security Symposium (USENIX Security 14). San Diego, CA: USENIX Asso- ciation, Aug. 2014, pp. 1–16
2014
-
[89]
Challenges in classifying privacy policies by machine learning with word-based features,
K. Fukushima, T. Nakamura, D. Ikeda, and S. Kiyomoto, “Challenges in classifying privacy policies by machine learning with word-based features,” inproceedings of the 2nd international conference on cryp- tography, security and privacy, 2018, pp. 62–66
2018
-
[90]
Privacy policy question answering assistant: A query-guided extractive summarization approach,
M. Keymanesh, M. Elsner, and S. Parthasarathy, “Privacy policy question answering assistant: A query-guided extractive summarization approach,”arXiv preprint arXiv:2109.14638, 2021
2021 arXiv
-
[91]
What about my privacy? helping users understand online privacy poli- cies,
W. Brunotte, L. Chazette, L. Kohler, J. Klunder, and K. Schneider, “What about my privacy? helping users understand online privacy poli- cies,” inProceedings of the International Conference on Software and System Processes and International Conference on Global Software Engine...
2022
-
[92]
Genaipabench: A benchmark for generative ai-based privacy assis- tants,
A. Hamid, H. R. Samidi, T. Finin, P. Pappachan, and R. Yus, “Genaipabench: A benchmark for generative ai-based privacy assis- tants,”arXiv preprint arXiv:2309.05138, 2023
2023 arXiv
-
[93]
Automated generation of accurate privacy captions from android source code using large language models,
V . Jain, S. Ghanavati, S. T. Peddinti, and C. McMillan, “Automated generation of accurate privacy captions from android source code using large language models,”arXiv preprint arXiv:2601.06276, 2026
2026
-
[94]
Collaborative privacy policy authoring in a social networking context,
R. Wishart, D. Corapi, S. Marinovic, and M. Sloman, “Collaborative privacy policy authoring in a social networking context,” in2010 IEEE International Symposium on Policies for Distributed Systems and Networks. IEEE, 2010, pp. 1–8
2010
-
[95]
Is it a trap? a large-scale empirical study and comprehensive as- sessment of online automated privacy policy generators for mobile apps,
S. Pan, D. Zhang, M. Staples, Z. Xing, J. Chen, X. Xu, and T. Hoang, “Is it a trap? a large-scale empirical study and comprehensive as- sessment of online automated privacy policy generators for mobile apps,” in33rd USENIX Security Symposium (USENIX Security 24). Philadelphia,...
2024
-
[96]
” i don’t use ai for everything
S. Pan, L. Wang, T. Zhang, Z. Xing, Y . Zhao, Q. Lu, and X. Sun, “” i don’t use ai for everything”: Exploring utility, attitude, and responsibility of ai-empowered tools in software development,”arXiv preprint arXiv:2409.13343, 2024
2024 arXiv
-
[97]
Ai in software engineer- ing: Perceived roles and their impact on adoption,
I. Zakharov, E. Koshchenko, and A. Sergeyuk, “Ai in software engineer- ing: Perceived roles and their impact on adoption,” inProceedings of the 33rd ACM International Conference on the Foundations of Software Engineering, 2025, pp. 1305–1309
2025
-
[98]
Purext: Automated extraction of the purpose-aware rule from the natural language privacy policy in iot,
L. Yang, X. Chen, Y . Luo, X. Lan, and L. Chen, “Purext: Automated extraction of the purpose-aware rule from the natural language privacy policy in iot,”Security and Communication Networks, vol. 2021, no. 1, p. 5552501, 2021
2021
-
[99]
Privonto: A semantic framework for the analysis of privacy policies,
A. Oltramari, D. Piraviperumal, F. Schaub, S. Wilson, S. Cherivirala, T. B. Norton, N. C. Russell, P. Story, J. Reidenberg, and N. Sadeh, “Privonto: A semantic framework for the analysis of privacy policies,” Semantic Web, vol. 9, no. 2, pp. 185–203, 2018
2018
-
[100]
Guileak: Tracing privacy policy claims on user input data for android applications,
X. Wang, X. Qin, M. B. Hosseini, R. Slavin, T. D. Breaux, and J. Niu, “Guileak: Tracing privacy policy claims on user input data for android applications,” inProceedings of the 40th International Conference on Software Engineering, 2018, pp. 37–47
2018
-
[101]
Analyzing regulatory rules for privacy and security requirements,
T. Breaux and A. Ant ´on, “Analyzing regulatory rules for privacy and security requirements,”IEEE transactions on software engineering, vol. 34, no. 1, pp. 5–20, 2008
2008
-
[102]
A framework for expressing and enforcing purpose-based privacy policies,
M. Jafari, R. Safavi-Naini, P. W. Fong, and K. Barker, “A framework for expressing and enforcing purpose-based privacy policies,”ACM Transactions on Information and System Security (TISSEC), vol. 17, no. 1, pp. 1–31, 2014
2014
-
[103]
Rsl-il4privacy: A domain-specific language for the rigorous specification of privacy policies,
J. Caramujo, A. Rodrigues da Silva, S. Monfared, A. Ribeiro, P. Calado, and T. Breaux, “Rsl-il4privacy: A domain-specific language for the rigorous specification of privacy policies,”Requirements Engineering, vol. 24, no. 1, pp. 1–26, 2019
2019
-
[104]
Towards privacy policy conceptual modeling,
K. Krasnashchok, M. Mustapha, A. Al Bassit, and S. Skhiri, “Towards privacy policy conceptual modeling,” inInternational Conference on Conceptual Modeling. Springer, 2020, pp. 429–438
2020
-
[105]
Ambiguity and generality in natural language privacy policies,
M. B. Hosseini, J. Heaps, R. Slavin, J. Niu, and T. Breaux, “Ambiguity and generality in natural language privacy policies,” in2021 IEEE 16 29th International Requirements Engineering Conference (RE). IEEE, 2021, pp. 70–81
2021
-
[106]
Consent verifi- cation monitoring,
M. Robol, T. D. Breaux, E. Paja, and P. Giorgini, “Consent verifi- cation monitoring,”ACM Transactions on Software Engineering and Methodology, vol. 32, no. 1, pp. 1–33, 2023
2023
-
[107]
Enhancing the description-to-behavior fidelity in android apps with privacy policy,
L. Yu, X. Luo, C. Qian, S. Wang, and H. K. N. Leung, “Enhancing the description-to-behavior fidelity in android apps with privacy policy,” IEEE Transactions on Software Engineering, 2018
2018
-
[108]
The effect of platform policies on app privacy compliance: A study of child-directed apps,
N. Alomar, J. Reardon, A. Girish, N. Vallina-Rodriguez, and S. Egel- man, “The effect of platform policies on app privacy compliance: A study of child-directed apps,”Proceedings on Privacy Enhancing Technologies, 2025
2025
-
[109]
Unpacking privacy labels: A measurement and developer perspective on google’s data safety section,
R. Khandelwal, A. Nayak, P. Chung, K. Fawaz, A. Bianchi, Z. B. Celik, Y . Yarom, X. S. Shen, Z. Fang, S. Zhanget al., “Unpacking privacy labels: A measurement and developer perspective on google’s data safety section,” in33rd USENIX Security Symposium (USENIX Security 24), 202...
2024
-
[110]
An empirical analysis of data deletion and{Opt-Out}choices on 150 websites,
H. Habib, Y . Zou, A. Jannu, N. Sridhar, C. Swoopes, A. Acquisti, L. F. Cranor, N. Sadeh, and F. Schaub, “An empirical analysis of data deletion and{Opt-Out}choices on 150 websites,” inFifteenth Symposium on Usable Privacy and Security (SOUPS 2019), 2019
2019
-
[111]
Re- viewing the data security and privacy policies of mobile apps for depression,
K. O’Loughlin, M. Neary, E. C. Adkins, and S. M. Schueller, “Re- viewing the data security and privacy policies of mobile apps for depression,”Internet interventions, vol. 15, pp. 110–115, 2019
2019
-
[112]
Lessons in vcr repair: compliance of android app developers with the california consumer privacy act (ccpa),
N. Samarin, S. Kothari, Z. Siyed, O. Bjorkman, R. Yuan, P. Wijesekera, N. Alomar, J. Fischer, C. Hoofnagle, and S. Egelman, “Lessons in vcr repair: compliance of android app developers with the california consumer privacy act (ccpa),”arXiv preprint arXiv:2304.00944, 2023
2023 arXiv
-
[113]
Smart home privacy policies demystified: A study of availability, content, and coverage,
S. Manandhar, K. Kafle, B. Andow, K. Singh, and A. Nadkarni, “Smart home privacy policies demystified: A study of availability, content, and coverage,” in31st USENIX Security Symposium (USENIX Security 22), 2022, pp. 3521–3538
2022
-
[114]
Feasibility of structured, machine- readable privacy notices,
V . Jesus, A. Patel, and D. Kumar, “Feasibility of structured, machine- readable privacy notices,” in2023 10th International Conference on Behavioural and Social Computing (BESC). IEEE, 2023, pp. 1–8
2023
-
[115]
Domain specialization as the key to make large language models disruptive: A comprehensive survey,
C. Ling, X. Zhao, J. Lu, C. Deng, C. Zheng, J. Wang, T. Chowdhury, Y . Li, H. Cui, X. Zhanget al., “Domain specialization as the key to make large language models disruptive: A comprehensive survey,” ACM Computing Surveys, vol. 58, no. 3, pp. 1–39, 2025
2025
-
[116]
Evaluating llms towards automated assessment of privacy policy understandability,
K. Mori, D. Ito, T. Fukunaga, T. Watanabe, Y . Takata, M. Kamizono, and T. Mori, “Evaluating llms towards automated assessment of privacy policy understandability,” inProceedings of the 2025 Symposium on Usable Security and Privacy, 2025
2025
-
[117]
A survey on hallucination in large language models: Principles, taxonomy, challenges, and open questions,
L. Huang, W. Yu, W. Ma, W. Zhong, Z. Feng, H. Wang, Q. Chen, W. Peng, X. Feng, B. Qinet al., “A survey on hallucination in large language models: Principles, taxonomy, challenges, and open questions,”ACM Transactions on Information Systems, vol. 43, no. 2, pp. 1–55, 2025
2025
-
[118]
Au- tomated extraction of semantic legal metadata using natural language processing,
A. Sleimi, N. Sannier, M. Sabetzadeh, L. Briand, and J. Dann, “Au- tomated extraction of semantic legal metadata using natural language processing,” in2018 IEEE 26th International Requirements Engineer- ing Conference (RE). IEEE, 2018, pp. 124–135
2018
-
[119]
Measuring compliance implications of third-party libraries’ privacy label disclosure guidelines,
Y . Xiao, C. Zhang, Y . Qin, F. F. S. Alharbi, L. Xing, and X. Liao, “Measuring compliance implications of third-party libraries’ privacy label disclosure guidelines,” inProceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security, 2024
2024
-
[120]
Advancing gdpr adherence: Leveraging generative ai for in-depth privacy policy analysis in android apps,
T. Duc, T. Nghiem, H. Khanh, T. Khoa, M. Triet, L. Bang, N. Ngan, and N. Trong, “Advancing gdpr adherence: Leveraging generative ai for in-depth privacy policy analysis in android apps,” inInternational Conference on Artificial Intelligence and Soft Computing. Springer, 2024, ...
2024
-
[121]
Privacychat: Utilizing large language model for fine-grained information extraction over privacy policies,
R. C. Salvi, C. Blake, and M. Bahir, “Privacychat: Utilizing large language model for fine-grained information extraction over privacy policies,” inInternational Conference on Information. Springer, 2024, pp. 223–231
2024
-
[122]
Analyzing corporate privacy policies using ai chatbots,
Z. Huang, J. Tang, M. Karir, M. Liu, and A. Sarabi, “Analyzing corporate privacy policies using ai chatbots,” inProceedings of the 2024 ACM on Internet Measurement Conference, 2024
2024
-
[123]
Honesty is the best policy: On the accuracy of apple privacy labels compared to apps’ privacy policies,
M. M. Ali, D. G. Balash, M. Kodwani, C. Kanich, and A. J. Aviv, “Honesty is the best policy: On the accuracy of apple privacy labels compared to apps’ privacy policies,”arXiv preprint arXiv:2306.17063, 2023
2023 arXiv
-
[124]
The creation and analysis of a website privacy policy corpus,
S. Wilson, F. Schaub, A. A. Dara, F. Liu, S. Cherivirala, P. G. Leon, M. S. Andersen, S. Zimmecket al., “The creation and analysis of a website privacy policy corpus,” inProceedings of the 54th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Pap...
2016
-
[125]
Automated extraction and presentation of data practices in privacy policies,
D. Bui, K. G. Shin, J.-M. Choi, and J. Shin, “Automated extraction and presentation of data practices in privacy policies,”Proceedings on Privacy Enhancing Technologies, 2021
2021
-
[126]
Democratizing gdpr compliance: Ai-driven privacy policy interpretation,
S. Mittal, S. Gupta, K. Bansal, and G. Aggarwal, “Democratizing gdpr compliance: Ai-driven privacy policy interpretation,” inProceedings of the 2024 Sixteenth International Conference on Contemporary Computing, 2024, pp. 735–743
2024
-
[127]
Factors related to gdpr compliance promises in privacy policies: A machine learning and nlp approach,
A.-J. Aberkane, S. vanden Broucke, and G. Poels, “Factors related to gdpr compliance promises in privacy policies: A machine learning and nlp approach,”International Journal of Information Systems and Project Management, vol. 13, no. 2, p. 3, 2025
2025
-
[128]
Policygpt: Automated analysis of privacy policies with large language models,
C. Tang, Z. Liu, C. Ma, Z. Wu, Y . Li, W. Liu, D. Zhu, Q. Li, X. Li, T. Liuet al., “Policygpt: Automated analysis of privacy policies with large language models,”arXiv preprint arXiv:2309.10238, 2023
2023 arXiv
-
[129]
Unilaw-r1: A large language model for legal reasoning with reinforcement learning and iterative inference,
H. Cai, S. Zhao, L. Zhang, X. Shen, Q. Xu, W. Shen, Z. Wen, and T. Ban, “Unilaw-r1: A large language model for legal reasoning with reinforcement learning and iterative inference,” inProceedings of the 2025 Conference on Empirical Methods in Natural Language Processing, 2025, ...
2025
-
[130]
Privacy at scale: Intro- ducing the privaseer corpus of web privacy policies,
M. Srinath, S. Wilson, and C. L. Giles, “Privacy at scale: Intro- ducing the privaseer corpus of web privacy policies,”arXiv preprint arXiv:2004.11131, 2020
2004 arXiv
-
[131]
Maps: Scaling privacy compliance analysis to a million apps,
S. Zimmeck, P. Story, D. Smullen, A. Ravichander, Z. Wang, J. Reiden- berg, N. C. Russell, and N. Sadeh, “Maps: Scaling privacy compliance analysis to a million apps,”Proceedings on Privacy Enhancing Tech- nologies, vol. 2019, no. 3, pp. 66–86, 2019
2019
-
[132]
Privacy policies in social media: Providing translated privacy notice,
B. Ur, M. Sleeper, and L. F. Cranor, “Privacy policies in social media: Providing translated privacy notice,” inProceedings of the 1st Workshop on Privacy and Security in Online Social Media, 2012
2012
-
[133]
Lalaine: Measuring and characterizing non-compliance of apple privacy labels,
Y . Xiao, Z. Li, Y . Qin, X. Bai, J. Guan, X. Liao, and L. Xing, “Lalaine: Measuring and characterizing non-compliance of apple privacy labels,” in32nd USENIX Security Symposium (USENIX Security 23), 2023, pp. 1091–1108
2023
-
[134]
Longitudinal compliance analysis of android applications with pri- vacy policies,
S. S. Hashmi, N. Waheed, G. Tangari, M. Ikram, and S. Smith, “Longitudinal compliance analysis of android applications with pri- vacy policies,” inInternational Conference on Mobile and Ubiquitous Systems: Computing, Networking, and Services. Springer, 2021
2021
-
[135]
“trust me over my privacy policy
A. Ragab, M. Mannan, and A. Youssef, ““trust me over my privacy policy”: Privacy discrepancies in romantic ai chatbot apps,” in2024 IEEE European Symposium on Security and Privacy Workshops (Eu- roS&PW). IEEE, 2024, pp. 484–495
2024
-
[136]
Consistency analysis of data-usage purposes in mobile apps,
D. Bui, Y . Yao, K. G. Shin, J.-M. Choi, and J. Shin, “Consistency analysis of data-usage purposes in mobile apps,” inProceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security, 2021, pp. 2824–2843
2021
-
[137]
An automated approach to auditing disclosure of third-party data collection in website privacy policies,
T. Libert, “An automated approach to auditing disclosure of third-party data collection in website privacy policies,” inProceedings of the 2018 World Wide Web Conference, 2018, pp. 207–216
2018
-
[138]
{OVRseen}: Auditing network traffic and privacy policies in oculus {VR},
R. Trimananda, H. Le, H. Cui, J. T. Ho, A. Shuba, and A. Markopoulou, “{OVRseen}: Auditing network traffic and privacy policies in oculus {VR},” in31st USENIX security symposium (USENIX security 22), 2022, pp. 3789–3806
2022
-
[139]
Minis- cope: Automated ui exploration and privacy inconsistency detection of miniapps via two-phase iterative hybrid analysis,
S. Wang, Y . Li, K. Wang, Y . Liu, H. Li, Y . Liu, and H. Wang, “Minis- cope: Automated ui exploration and privacy inconsistency detection of miniapps via two-phase iterative hybrid analysis,”ACM Transactions on Software Engineering and Methodology, vol. 34, no. 6, pp. 1–29, 2025
2025
-
[140]
Investigating documented privacy changes in android os,
C. Yan, M. H. Meng, F. Xie, and G. Bai, “Investigating documented privacy changes in android os,”Proceedings of the ACM on Software Engineering, vol. 1, no. FSE, pp. 2701–2724, 2024
2024
-
[141]
Ptpdroid: Detecting violated user privacy disclosures to third-parties of android apps,
Z. Tan and W. Song, “Ptpdroid: Detecting violated user privacy disclosures to third-parties of android apps,” in2023 IEEE/ACM 45th International Conference on Software Engineering (ICSE). IEEE, 2023, pp. 473–485
2023
-
[142]
A privacy and security analysis of early-deployed covid-19 contact tracing android apps,
M. Hatamian, S. Wairimu, N. Momen, and L. Fritsch, “A privacy and security analysis of early-deployed covid-19 contact tracing android apps,”Empirical software engineering, vol. 26, no. 3, p. 36, 2021
2021
-
[143]
Analysis of privacy compliance by classifying policies before and after the japanese law revision,
K. Mori, T. Nagai, Y . Takata, M. Kamizono, and T. Mori, “Analysis of privacy compliance by classifying policies before and after the japanese law revision,”Journal of information processing, vol. 31, 2023. 17
2023
-
[144]
Act on the protection of personal information (act no. 57 of 2003),
Japanese Government / Ministry of Justice, “Act on the protection of personal information (act no. 57 of 2003),” https://www.japaneselawtranslation.go.jp/en/laws/view/4241/en, Japanese Law Translation Database System, 2003, last version: Act No. 37 of 2021
2003
-
[145]
Classifying potentially non- compliant portuguese language sentences concerning privacy policies,
M. Tocchini, I. M. Rocha, R. M. de Barros, J. O. e Silva, A. F. Garcia, F. Zular, J. Maranh˜ao, and J. S. Sichman, “Classifying potentially non- compliant portuguese language sentences concerning privacy policies,” inBrazilian Conference on Intelligent Systems. Springer, 2024
2024
-
[146]
Lei geral de protec ¸˜ao de dados (lgpd) / general data protec- tion law (law no. 13,709 of august 14, 2018),
Ag ˆencia Nacional de Protec ¸˜ao de Dados (ANPD), Federative Republic of Brazil, “Lei geral de protec ¸˜ao de dados (lgpd) / general data protec- tion law (law no. 13,709 of august 14, 2018),” National Data Protection Authority (ANPD), Brazil, 2018, english version accessed J...
2018
-
[147]
Creation and analysis of an international corpus of privacy laws,
S. Gupta, E. Poplavska, N. O’Toole, S. Arora, T. Norton, N. Sadeh, and S. Wilson, “Creation and analysis of an international corpus of privacy laws,”arXiv preprint arXiv:2206.14169, 2022
2022 arXiv
-
[148]
Accessed: 2026-04-21
(2025) Iso/iec 27701:2025, information security, cybersecurity and privacy protection — privacy information management systems — requirements and guidance. Accessed: 2026-04-21. [Online]. Available: https://www.iso.org/standard/27701
2025
-
[149]
Accessed: 2026-04-21
(2025) The national institute of standards and technology privacy framework. Accessed: 2026-04-21. [Online]. Available: https://www. nist.gov/privacy-framework
2025
-
[150]
Android Developers, Google Play Console Help Center,
“Android Developers, Google Play Console Help Center,” android- developer/answer, Accessed: 2022-04-30
2022
-
[151]
Guttman,An introduction to computer security: the NIST handbook
B. Guttman,An introduction to computer security: the NIST handbook. US Department of Commerce, Technology Administration, National Institute of . . . , 1995, vol. 800, no. 12
1995
-
[152]
Engineering privacy,
S. Spiekermann and L. F. Cranor, “Engineering privacy,”IEEE Trans- actions on software engineering, vol. 35, no. 1, pp. 67–82, 2008
2008
-
[153]
On the privacy of mental health apps: An empirical investigation and its implications for app development,
L. H. Iwaya, M. A. Babar, A. Rashid, and C. Wijayarathna, “On the privacy of mental health apps: An empirical investigation and its implications for app development,”Empirical Software Engineering, vol. 28, no. 1, p. 2, 2023
2023
-
[154]
Temporal mode- checking for runtime monitoring of privacy policies,
O. Chowdhury, L. Jia, D. Garg, and A. Datta, “Temporal mode- checking for runtime monitoring of privacy policies,” inInternational Conference on Computer Aided Verification. Springer, 2014
2014
-
[155]
Atlas: Automatically detecting discrepancies between privacy policies and privacy labels,
A. Jain, D. Rodriguez, J. M. Del Alamo, and N. Sadeh, “Atlas: Automatically detecting discrepancies between privacy policies and privacy labels,” in2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW). IEEE, 2023, pp. 94–107
2023
-
[156]
Mobile-app privacy nutrition labels missing key ingre- dients for success,
L. F. Cranor, “Mobile-app privacy nutrition labels missing key ingre- dients for success,”Communications of the ACM, vol. 65, no. 11, pp. 26–28, 2022
2022
-
[157]
Data safety vs. app privacy: Comparing the usability of android and ios privacy labels,
Y . Lin, J. Juneja, E. Birrell, and L. Cranor, “Data safety vs. app privacy: Comparing the usability of android and ios privacy labels,” arXiv preprint arXiv:2312.03918, 2023
2023 arXiv
-
[158]
Accessed: 2022-10-10
Understand app privacy and security practices with google play’s data safety section. Accessed: 2022-10-10. [Online]. Available: https://support.google.com/googleplay/answer/11416267
2022
-
[159]
App privacy details on the app store,
“App privacy details on the app store,” https://developer.apple.com/ app-store/app-privacy-details/, Accessed: 2022-04-30
2022
-
[160]
A First Look at Privacy Risks of Android Task-executable V oice Assistant Applications ,
S. Pan, Y . Ge, and X. Sun, “ A First Look at Privacy Risks of Android Task-executable V oice Assistant Applications ,” in2025 32nd Asia-Pacific Software Engineering Conference (APSEC). Los Alamitos, CA, USA: IEEE Computer Society, Dec. 2025, pp. 347–358. [Online]. Available: ...
2025
-
[161]
Derivation of new readability formulas (automated readability index, fog count and flesch reading ease formula) for navy enlisted personnel,
J. P. Kincaid, R. P. Fishburne Jr, R. L. Rogers, and B. S. Chissom, “Derivation of new readability formulas (automated readability index, fog count and flesch reading ease formula) for navy enlisted personnel,” Naval Technical Training Command Millington TN Research Branch, Te...
1975
-
[162]
Privacy at scale: Introducing the privaseer corpus of web privacy policies,
M. Srinath, S. Wilson, and C. L. Giles, “Privacy at scale: Introducing the privaseer corpus of web privacy policies,” inProceedings of the 59th Annual Meeting of the Association for Computational Linguistics and the 11th International Joint Conference on Natural Language Proce...
2021
-
[163]
How short is too short? implications of length and framing on the effectiveness of privacy notices,
J. Gluck, F. Schaub, A. Friedman, H. Habib, N. Sadeh, L. F. Cranor, and Y . Agarwal, “How short is too short? implications of length and framing on the effectiveness of privacy notices,” inTwelfth symposium on usable privacy and security (SOUPS 2016), 2016, pp. 321–340
2016
-
[164]
Impact of app privacy label disclosure on demand: An empirical analysis,
R. Garg and R. Telang, “Impact of app privacy label disclosure on demand: An empirical analysis,”Available at SSRN 4588747, 2022
2022
-
[165]
How usable are ios app privacy labels?
S. Zhang, Y . Feng, Y . Yao, L. F. Cranor, and N. Sadeh, “How usable are ios app privacy labels?”Proceedings on Privacy Enhancing Technologies, 2022
2022
-
[166]
Understanding ios privacy nutrition labels: An exploratory large-scale analysis of app store data,
Y . Li, D. Chen, T. Li, Y . Agarwal, L. F. Cranor, and J. I. Hong, “Understanding ios privacy nutrition labels: An exploratory large-scale analysis of app store data,” inCHI Conference on Human Factors in Computing Systems Extended Abstracts, 2022, pp. 1–7
2022
-
[167]
Exploring{Expandable-Grid}designs to make{iOS}app privacy labels more usable,
S. Zhang, L. Klucinec, K. Norton, N. Sadeh, and L. F. Cranor, “Exploring{Expandable-Grid}designs to make{iOS}app privacy labels more usable,” inTwentieth Symposium on Usable Privacy and Security (SOUPS 2024), 2024, pp. 139–157
2024
-
[168]
Unifying privacy policy detection,
H. Hosseini, M. Degeling, C. Utz, and T. Hupperich, “Unifying privacy policy detection,”Proceedings on Privacy Enhancing Technologies, 2021
2021
-
[169]
Less is not more: Improving findability and action- ability of privacy controls for online behavioral advertising,
J. Im, R. Wang, W. Lyu, N. Cook, H. Habib, L. F. Cranor, N. Banovic, and F. Schaub, “Less is not more: Improving findability and action- ability of privacy controls for online behavioral advertising,” inPro- ceedings of the 2023 CHI Conference on Human Factors in Computing Sys...
2023
-
[170]
The privacy policy landscape after the gdpr,
T. Linden, R. Khandelwal, H. Harkous, and K. Fawaz, “The privacy policy landscape after the gdpr,”arXiv preprint arXiv:1809.08396, 2018
2018 arXiv
-
[171]
A large-scale investigation of semantically incompatible apis behind compatibility issues in android apps,
S. Pan, T. Guo, L. Zhang, P. Liu, Z. Xing, and X. Sun, “A large-scale investigation of semantically incompatible apis behind compatibility issues in android apps,”arXiv preprint arXiv:2406.17431, 2024
2024 arXiv
-
[172]
A” nutrition label
P. G. Kelley, J. Bresee, L. F. Cranor, and R. W. Reeder, “A” nutrition label” for privacy,” inProceedings of the 5th Symposium on Usable Privacy and Security, 2009, pp. 1–12
2009
-
[173]
Standardizing privacy notices: an online study of the nutrition label approach,
P. G. Kelley, L. Cesca, J. Bresee, and L. F. Cranor, “Standardizing privacy notices: an online study of the nutrition label approach,” in Proceedings of the SIGCHI Conference on Human factors in Comput- ing Systems, 2010, pp. 1573–1582
2010
-
[174]
Privacy as part of the app decision-making process,
P. G. Kelley, L. F. Cranor, and N. Sadeh, “Privacy as part of the app decision-making process,” inProceedings of the SIGCHI conference on human factors in computing systems, 2013, pp. 3393–3402
2013
-
[175]
Ask the experts: What should be on an iot privacy and security label?
P. Emami-Naeini, Y . Agarwal, L. F. Cranor, and H. Hibshi, “Ask the experts: What should be on an iot privacy and security label?” in2020 IEEE Symposium on Security and Privacy (SP), 2020
2020
-
[176]
App Privacy Details App Store,
“App Privacy Details App Store,” developer.apple/app-store/, Accessed: 2023-02-20
2023
-
[177]
Cranor,Web privacy with P3P
L. Cranor,Web privacy with P3P. ” O’Reilly Media, Inc.”, 2002
2002
-
[178]
Platform for privacy preferences (p3p) project,
Lorrie Cranor and Rigo Wenning, “Platform for privacy preferences (p3p) project,” 2025, https://www.w3.org/P3P/ Accessed: 2025-11-03
2025
-
[179]
A survey of privacy policy languages,
P. Kumaraguru, L. Cranor, J. Lobo, and S. Calo, “A survey of privacy policy languages,” inWorkshop on Usable IT Security Management (USM 07): Proceedings of the 3rd Symposium on Usable Privacy and Security, ACM, 2007
2007
-
[180]
Contextual privacy policies for mobile appli- cations and an approach toward automated generation,
Z. Tao and S. Pan, “Contextual privacy policies for mobile appli- cations and an approach toward automated generation,” inSE2026. Gesellschaft f ¨ur Informatik, Bonn, 2026, pp. 10–18 420
2026
-
[181]
Clear: Towards con- textual llm-empowered privacy policy analysis and risk generation for large language model applications,
C. Chen, D. Zhou, Y . Ye, T. J.-j. Li, and Y . Yao, “Clear: Towards con- textual llm-empowered privacy policy analysis and risk generation for large language model applications,”arXiv preprint arXiv:2410.13387, 2024
2024 arXiv
-
[182]
Informing the design of a personalized privacy assistant for the internet of things,
J. Colnago, Y . Feng, T. Palanivel, S. Pearman, M. Ung, A. Acquisti, L. F. Cranor, and N. Sadeh, “Informing the design of a personalized privacy assistant for the internet of things,” inProceedings of the 2020 CHI Conference on Human Factors in Computing Systems, 2020
2020
-
[183]
From procedures to peril: Towards risk transparency in information privacy for users,
N. Ebert, S. Fischer-H ¨ubner, S. Human, A. Kitkowska, K. Kollnig, J. Mitrovi´c, S. Pan, T. Schaltegger, F. Schaub, D. Smullenet al., “From procedures to peril: Towards risk transparency in information privacy for users,”Telecommunications Policy, vol. 50, no. 5, p. 103195, 2026
2026
-
[184]
Accessed: 2026-04-21
(2026) The usable privacy policy project. Accessed: 2026-04-21. [Online]. Available: https://usableprivacy.org/data
2026
-
[185]
Honeysuckle: Annotation-guided code generation of in-app privacy notices,
T. Li, E. B. Neundorfer, Y . Agarwal, and J. I. Hong, “Honeysuckle: Annotation-guided code generation of in-app privacy notices,”Pro- ceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies, vol. 5, no. 3, pp. 1–27, 2021. 18
2021
Reviewed August 16, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.