REVIEW 3 major objections 6 minor 73 references
"We Need a Standard": Toward an Expert-Informed Privacy Label for Differential Privacy
T0 review · 3 major / 6 minor · reviewed 2026-08-06 · deepseek-v4-flash
Pith's one-line read Twelve DP experts agree: a privacy label must say more than epsilon.
desk verdict Useful expert-elicitation study with a solid prototype, but the 'significant consensus' frame outruns the data for most label categories. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing artifact is the proposed DP label: a table modeled on nutrition labels that lists each expert-endorsed parameter with its value, ordered with privacy parameters at the top. Its design follows a two-layer structure, with a compact primary layer for summaries and a secondary layer, reached through an interactive interface, holding technical detail and plain-language explanations. The label is generated from a qualitative machinery: semi-structured interviews with 12 DP experts, transcribed and coded with a hybrid deductive-inductive thematic analysis, with mention counts indicating consensus strength.
What would settle it
Run the same interview protocol with a larger, preregistered sample that includes regulators, policymakers, legal scholars, and downstream data users in addition to DP researchers and engineers; if the resulting parameter list does not reproduce the nine categories or does not place $\epsilon$, $\delta$, and the unit of privacy at the top, the claimed expert consensus does not generalize beyond the original sample.
Extended reading notes
Core claim
The paper's central claim is that expert consensus already exists on the content of a differential privacy disclosure: reporting $\epsilon$ alone is insufficient and potentially misleading, while a standardized label that includes $\epsilon$, $\delta$, the unit of privacy (what entity or event is protected), and contextual parameters would let technical stakeholders accurately compare and assess deployments. The interview study yields nine parameter categories, with privacy parameters and the unit of privacy receiving the strongest expert support. The authors further report expert guidance on typical ranges (e.g., $\epsilon \le 4$ as an ideal, $\delta$ near $10^{-5}$ to $10^{-6}$), on which parameters suit general versus technical audiences, and on presentation formats. Synthesizing this guidance, they design a two-layer, nutrition-style differential privacy label for technical users, leaving communication to the general public as an open problem.
Load-bearing premise
The load-bearing premise is that the 12 interviewed experts, mostly US-based academics and industry practitioners recruited through the authors' professional networks and a DP mailing list, represent the wider DP community well enough to anchor a standardization effort; if policymakers, regulators, or other stakeholders name a different set of essential parameters, the consensus list and label design lose their grounding.
Editorial extensions
If this is right
- A standard differential privacy disclosure should report $\epsilon$ and $\delta$ together with the unit of privacy; $\epsilon$-only reporting is the transparency failure the paper targets.
- Privacy registries and data-release documentation can adopt the two-layer label format, giving technical readers a full parameter list and non-experts a summary layer.
- Draft normal ranges (e.g., $\epsilon$ ideally at or below 4, $\delta$ around $10^{-5}$ to $10^{-6}$) provide initial benchmarks, though the paper stresses context-dependence.
- How to communicate differential privacy guarantees to the general public remains unsolved; the paper positions that as future work.
- Future evaluation should test the label with technical users first, then iterate with end users through participatory design.
Reading between the lines
- If the label were machine-readable and embedded in data-release metadata, disclosure of the unit of privacy could become an automatic compliance check for deployments claiming differential privacy.
- The contested status of utility information suggests that a single label may not serve all stakeholders; regulators, analysts, and data subjects may each need a tailored view.
- A direct empirical test would be to give the prototype to practitioners comparing two DP releases and see whether it prevents the kind of unit-of-privacy misreadings documented in the paper.
- The expert-suggested ranges (e.g., $\epsilon$ up to 20 for high-dimensional data) could be benchmarked against actual published deployments to see whether industry practice matches expert norms.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper presents a qualitative interview study with 12 DP experts (May–August 2024) conducted to identify which parameters should be included in a standardized 'DP privacy label' and how those parameters should be presented. The authors use semi-structured interviews, hybrid thematic analysis with two independent coders, and report counts of expert mentions for nine parameter categories. Based on these data, they propose a two-layer interactive HTML label targeted at technical users, and they discuss typical ranges, audience relevance, and presentation formats. The paper's central claim is that experts reached significant consensus about what to communicate, specifically epsilon, delta, and the unit of privacy, and that this consensus motivates the proposed label.
Significance. The study addresses a real gap: DP deployments are proliferating but lack standardized transparency documentation. If the findings are interpreted with appropriate scope, the paper makes a useful contribution by (i) providing a systematically coded list of expert-nominated parameters, (ii) documenting expert opinions on ranges and audiences, and (iii) offering a concrete, publicly available label prototype. Strengths include the published codebook (Appendix E), the two-coder process, the explicit discussion of limitations, and the caution about not over-claiming for end-user communication. The main concern is that the 'consensus' framing overstates what the data show; with more careful hedging, the work would be a solid basis for future standardization efforts.
major comments (3)
- [Section 4, Table 1] The abstract and the Section 4 introduction claim 'significant consensus about what to communicate' and that experts agreed that 'epsilon, delta, and the unit of privacy are vital' for a DP label, but Table 1 and Section 4.1 show that this strong consensus tier (8–12 experts) covers only the combined 'Privacy parameters' category and 'Unit of privacy.' 'Utility information,' 'Mechanism used,' and 'Algorithm hyperparameters' fall in the moderate tier (4–7), and 'Deployment model,' 'Empirical privacy metrics,' and 'Privacy interpretation-semantics' fall in the weakest tier (1–3). Section 5.1 then states that 'When expert opinions diverged, we used our best judgment,' which means the label's comprehensive contents are not fully consensus-backed. Because the paper's contribution is explicitly framed as an 'Expert-Informed Privacy Label' and as a basis for standardization, the manuscript should either report consensus levels per parameter throughout, or sharply separate the consensus-backed core (epsilon, unit of privacy, and arguably the other privacy-loss measures) from the authors' design choices for the remaining categories. As written, the 'significant consensus' framing overstates the evidence.
- [Section 4.1.1.2 and Table 3] Delta is the clearest instance of the gap between the consensus claim and the underlying counts. Only three experts are reported as emphasizing delta's role (Section 4.1.1.2), and Table 3 lists only three 'yes' responses for delta for a technical audience, with one expert (P05) explicitly arguing that if delta is set small by consensus there is no need to convey it. Yet delta is placed at the top of the proposed label in Figure 1 and treated as a core parameter throughout. This is not necessarily wrong, but the paper should explicitly acknowledge that delta's inclusion is a design decision informed by theoretical importance rather than by a demonstrated expert consensus, and it should explain the authors' judgment for including it despite the sparse support. Without that, a reader could infer that the label's most prominent parameters are all equally expert-endorsed.
- [Section 4.5 and Appendix B] The two-layer structure is one of the paper's main design outputs, but the supporting evidence is partly an artifact of the interview protocol. The authors proposed the two-layer structure to experts (Appendix B, Focus 3) and disclose that experts did not independently suggest it; they then report that 'Experts unanimously supported our proposed layered structure.' This wording overstates the agreement: two experts (P01, P11) proposed adding a third layer, so the support was not unanimous in the sense of unqualified endorsement. Moreover, the question format may invite socially desirable agreement with the interviewer's proposal. The manuscript should present this result as 'all experts who commented on the proposed two-layer design responded positively, with two suggesting an additional intermediate layer,' and add a sentence noting the possibility of acquiescence bias in this portion of the data.
minor comments (6)
- [Table 3] The counts in Table 3 are incomplete: for example, Epsilon–General Audience reports 8 yes and 2 no, totaling 10 of 12 participants, and Delta–Technical Audience reports only 3 yes, leaving 9 participants unaccounted for. Please state whether the remaining experts declined to answer or were not asked, or report 'n' and missing values explicitly.
- [Section 4.5] The text reports 'Eleven experts praised our idea of a DP label with standardized contents' and 'Ten experts favored the two-layer structure,' but no counts are given for the remaining experts; please specify the number of experts who addressed each question and how non-responses were handled.
- [Section 4.5] The phrase 'Experts unanimously supported our proposed layered structure' is inconsistent with the immediately following statement that two experts (P01, P11) proposed a third layer; consider rephrasing to 'supported the layered concept.'
- [Section 5.1] In the 'Two-Layer Design' paragraph, 'plan-language descriptions' should be 'plain-language descriptions.'
- [Appendix A] The eligibility survey asks 'Do you currently reside in the United States?' but Section 3.1 reports one participant from Europe; please clarify whether the residency criterion was waived or whether the question was only a screening preference.
- [Section 4.1] The paragraph on counting notes that mentions are not an attempt to quantify findings, but Table 1 and Table 3 use count-based consensus tiers; clarify the counting unit (e.g., whether an expert mentioning any sub-parameter counts once for the category) to make those tiers interpretable.
Circularity Check
No significant circularity: the expert-informed DP label is grounded in external interview data, and self-citations are background context rather than load-bearing inputs.
full rationale
This paper's derivation chain is empirical rather than formal: the parameter list and label design are outputs of semi-structured interviews with 12 DP experts, not consequences of the authors' prior mathematical definitions. The (epsilon, delta)-DP definition in Section 2.1 is standard background and is not used to derive the label; the label is explicitly presented as 'an initial DP label' synthesized from expert recommendations, with divergences resolved by 'our best judgment' (Section 5.1). Self-citations such as [43] and [44] appear only as context for standard definitions and NIST guidance, and they do not supply the consensus evidence. The one circularity-adjacent feature—the authors proposed a two-layer structure and later report that experts favored it—is disclosed ('experts did not independently suggest a two-layer design,' Section 4.5), and the paper does not claim that the structure was derived from expert consensus alone. Whether the expert sample supports the strength of the consensus claim is an internal-validity and reporting concern, not circularity, because the conclusions are not equivalent to the inputs by construction.
Assumptions & free parameters
assumptions (3)
- standard math Standard definitions of differential privacy and related measures (epsilon, delta, zCDP) are correct and accepted.
- domain assumption Thematic analysis of semi-structured interviews is a valid method for synthesizing expert consensus.
- domain assumption The 12 recruited experts are sufficiently representative of the wider DP expert community for standardization guidance.
Cite this review
Pith. "Pith review of "We Need a Standard": Toward an Expert-Informed Privacy Label for Differential Privacy." pith.science (2026). https://pith.science/paper/GUBH5USP
@misc{pith2026250715997,
author = {Pith},
title = {Pith review of: "We Need a Standard": Toward an Expert-Informed Privacy Label for Differential Privacy},
year = {2026},
howpublished = {\url{https://pith.science/paper/GUBH5USP}},
note = {Machine review of arXiv:2507.15997}
}
read the original abstract
The increasing adoption of differential privacy (DP) leads to public-facing DP deployments by both government agencies and companies. However, real-world DP deployments often do not fully disclose their privacy guarantees, which vary greatly between deployments. Failure to disclose certain DP parameters can lead to misunderstandings about the strength of the privacy guarantee, undermining the trust in DP. In this work, we seek to inform future standards for communicating the privacy guarantees of DP deployments. Based on semi-structured interviews with 12 DP experts, we identify important DP parameters necessary to comprehensively communicate DP guarantees, and describe why and how they should be disclosed. Based on expert recommendations, we design an initial privacy label for DP to comprehensively communicate privacy guarantees in a standardized format.
Figures
Reference graph
Works this paper leans on
-
[1]
The 2020 census disclosure avoidance system top- down algorithm
John M Abowd, Robert Ashmead, Ryan Cumings-Menon, Simson Garfinkel, Micah Heineck, Christine Heiss, Robert Johns, Daniel Kifer, Philip Leclerc, Ash- win Machanavajjhala, et al. The 2020 census disclosure avoidance system top- down algorithm. Harvard Data Science Review , 2, 2022
work page 2020
-
[2]
Apple: Differential Privacy Overview, 2023
Apple. Apple: Differential Privacy Overview, 2023. https://www.apple.com/ privacy/docs/Differential_Privacy_Overview.pdf
work page 2023
-
[3]
Learning with privacy at scale
D Apple. Learning with privacy at scale. Apple Machine Learning Journal, 1(8):71, 2017
work page 2017
-
[4]
Casual users and rational choices within differential privacy
Narges Ashena, Oana Inel, Badrie L Persaud, and Abraham Bernstein. Casual users and rational choices within differential privacy. InIEEE Symposium on Secu- rity and Privacy. Proceedings, pages 87–87. Institute of Electrical and Electronics Engineers, 2024
work page 2024
-
[5]
Hierarchical organization of urban mobility and its connection with city livability
Aleix Bassolas, Hugo Barbosa-Filho, Brian Dickinson, Xerxes Dotiwalla, Paul Eastham, Riccardo Gallotti, Gourab Ghoshal, Bryant Gipson, Surendra A Hazarie, Henry Kautz, et al. Hierarchical organization of urban mobility and its connection with city livability. Nature communications, 10(1):4817, 2019
work page 2019
-
[6]
Aleix Bassolas, Hugo Barbosa-Filho, Brian Dickinson, Xerxes Dotiwalla, Paul Eastham, Riccardo Gallotti, Gourab Ghoshal, Bryant Gipson, Surendra A Haz- arie, Henry Kautz, et al. Reply to: On the difficulty of achieving differential privacy in practice: user-level guarantees in aggregate location data. Nature Communications, 13(1):30, 2022
work page 2022
-
[7]
Using thematic analysis in psychology
Virginia Braun and Victoria Clarke. Using thematic analysis in psychology. Qualitative research in psychology, 3(2):77–101, 2006
work page 2006
-
[8]
Brooke Bullek, Stephanie Garboski, Darakhshan J Mir, and Evan M Peck. Towards understanding differential privacy: When do people trust randomized response technique? In Proceedings of the 2017 CHI Conference on Human Factors in Computing Systems, pages 3833–3837, 2017
work page 2017
Show all 73 references
-
[9]
Concentrated differential privacy: Simplifications, extensions, and lower bounds
Mark Bun and Thomas Steinke. Concentrated differential privacy: Simplifications, extensions, and lower bounds. In Theory of cryptography conference , pages 635–
-
[10]
Membership inference attacks from first principles
Nicholas Carlini, Steve Chien, Milad Nasr, Shuang Song, Andreas Terzis, and Florian Tramer. Membership inference attacks from first principles. In 2022 IEEE symposium on security and privacy (SP) , pages 1897–1914. IEEE, 2022
2022
-
[11]
Mobile-app privacy nutrition labels missing key ingredients for success
Lorrie Faith Cranor. Mobile-app privacy nutrition labels missing key ingredients for success. Communications of the ACM, 65(11):26–28, 2022
2022
-
[12]
Attax- onomy: Unpacking differential privacy guarantees against practical adversaries
Rachel Cummings, Shlomi Hod, Jayshree Sarathy, and Marika Swanberg. Attax- onomy: Unpacking differential privacy guarantees against practical adversaries. arXiv preprint arXiv:2405.01716, 2024
2024 arXiv
-
[13]
i need a better description
Rachel Cummings, Gabriel Kaptchuk, and Elissa M Redmiles. " i need a better description": An investigation into user expectations for differential privacy. In Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security, pages 3037–3052, 2021
2021
-
[14]
Centering policy and practice: Research gaps around usable differential privacy
Rachel Cummings and Jayshree Sarathy. Centering policy and practice: Research gaps around usable differential privacy. In 2023 5th IEEE International Conference on Trust, Privacy and Security in Intelligent Systems and Applications (TPS-ISA) , pages 122–135. IEEE, 2023
2023
-
[15]
A list of real-world uses of differential privacy
Damien Desfontaines. A list of real-world uses of differential privacy. https: //desfontain.es/blog/real-world-differential-privacy.html, 2021. Originally pub- lished: 2021-10-01, Last updated: 2024-09-13, Accessed: 2024-09-17
2021
-
[16]
Differential privacy in practice: Expose your epsilons! Journal of Privacy and Confidentiality , 9(2), 2019
Cynthia Dwork, Nitin Kohli, and Deirdre Mulligan. Differential privacy in practice: Expose your epsilons! Journal of Privacy and Confidentiality , 9(2), 2019
2019
-
[17]
Calibrating noise to sensitivity in private data analysis
Cynthia Dwork, Frank McSherry, Kobbi Nissim, and Adam Smith. Calibrating noise to sensitivity in private data analysis. In Theory of Cryptography: Third Theory of Cryptography Conference, TCC 2006, New York, NY, USA, March 4-7,
2006
-
[18]
The algorithmic foundations of differential privacy
Cynthia Dwork, Aaron Roth, et al. The algorithmic foundations of differential privacy. Foundations and Trends® in Theoretical Computer Science, 9(3–4):211–407, 2014
2014
-
[19]
Ask the experts: What should be on an iot privacy and security label? In 2020 IEEE Symposium on Security and Privacy (SP) , pages 447–464
Pardis Emami-Naeini, Yuvraj Agarwal, Lorrie Faith Cranor, and Hanan Hibshi. Ask the experts: What should be on an iot privacy and security label? In 2020 IEEE Symposium on Security and Privacy (SP) , pages 447–464. IEEE, 2020
2020
-
[20]
nutrition
Pardis Emami-Naeini, Janarth Dheenadhayalan, Yuvraj Agarwal, and Lorrie Faith Cranor. An informative security and privacy “nutrition” label for internet of things devices. IEEE Security & Privacy , 20(2):31–39, 2021
2021
-
[21]
Statistically valid inferences from privacy-protected data
Georgina Evans, Gary King, Margaret Schwenzfeier, and Abhradeep Thakurta. Statistically valid inferences from privacy-protected data. American Political Science Review, 117(4):1275–1290, 2023
2023
-
[22]
Building a rappor with the unknown: Privacy-preserving learning of associations and data dictionaries
Giulia Fanti, Vasyl Pihur, and Úlfar Erlingsson. Building a rappor with the unknown: Privacy-preserving learning of associations and data dictionaries. arXiv preprint arXiv:1503.01214, 2015
2015 arXiv
-
[23]
Demonstrating rigor using the- matic analysis: A hybrid approach of inductive and deductive coding and theme development
Jennifer Fereday and Eimear Muir-Cochrane. Demonstrating rigor using the- matic analysis: A hybrid approach of inductive and deductive coding and theme development. International journal of qualitative methods , 5(1):80–92, 2006
2006
-
[24]
Pageviews differential privacy — current
Wikimedia Foundation. Pageviews differential privacy — current. https://analytics.wikimedia.org/published/datasets/country_project_page/00_ README.html, 2024. Accessed: 2024-09-17
2024
-
[25]
Am i private and if so, how many? communicating privacy guarantees of differential privacy with risk communication formats
Daniel Franzen, Saskia Nuñez von Voigt, Peter Sörries, Florian Tschorsch, and Claudia Müller-Birn. Am i private and if so, how many? communicating privacy guarantees of differential privacy with risk communication formats. In Pro- ceedings of the 2022 ACM SIGSAC Conference on ...
2022
-
[26]
Google: Differentially private heatmaps, 2023
Google. Google: Differentially private heatmaps, 2023. https://blog.research. google/2023/04/differentially-private-heatmaps.html
2023
-
[27]
Differentially private release of israel’s national registry of live births
Shlomi Hod and Ran Canetti. Differentially private release of israel’s national registry of live births. arXiv preprint arXiv:2405.00267, 2024
2024 arXiv
-
[28]
The dataset nutrition label
Sarah Holland, Ahmed Hosny, Sarah Newman, Joshua Joseph, and Kasia Chmielinski. The dataset nutrition label. Data Protection and Privacy , 12(12):1, 2020
2020
-
[29]
On the difficulty of achieving differential privacy in practice: user-level guarantees in aggregate location data
Florimond Houssiau, Luc Rocher, and Yves-Alexandre de Montjoye. On the difficulty of achieving differential privacy in practice: user-level guarantees in aggregate location data. Nature communications, 13(1):29, 2022
2022
-
[30]
Auditing differentially private machine learning: How private is private sgd? Advances in Neural Information Processing Systems, 33:22205–22216, 2020
Matthew Jagielski, Jonathan Ullman, and Alina Oprea. Auditing differentially private machine learning: How private is private sgd? Advances in Neural Information Processing Systems, 33:22205–22216, 2020
2020
-
[31]
Exploring {User-Suitable} metaphors for differentially private data analyses
Farzaneh Karegar, Ala Sarah Alaqra, and Simone Fischer-Hübner. Exploring {User-Suitable} metaphors for differentially private data analyses. In Eighteenth Symposium on Usable Privacy and Security (SOUPS 2022) , pages 175–193, 2022
2022
-
[32]
nutrition label
Patrick Gage Kelley, Joanna Bresee, Lorrie Faith Cranor, and Robert W Reeder. A" nutrition label" for privacy. In Proceedings of the 5th Symposium on Usable Privacy and Security, pages 1–12, 2009
2009
-
[33]
Stan- dardizing privacy notices: an online study of the nutrition label approach
Patrick Gage Kelley, Lucian Cesca, Joanna Bresee, and Lorrie Faith Cranor. Stan- dardizing privacy notices: an online study of the nutrition label approach. In Proceedings of the SIGCHI Conference on Human factors in Computing Systems , pages 1573–1582, 2010
2010
-
[34]
Pripearl: A framework for privacy- preserving analytics and reporting at linkedin
Krishnaram Kenthapadi and Thanh TL Tran. Pripearl: A framework for privacy- preserving analytics and reporting at linkedin. In Proceedings of the 27th ACM International Conference on Information and Knowledge Management, pages 2183– 2191, 2018
2018
-
[35]
Goodbye tracking? impact of ios app tracking transparency and privacy labels
Konrad Kollnig, Anastasia Shuba, Max Van Kleek, Reuben Binns, and Nigel Shadbolt. Goodbye tracking? impact of ios app tracking transparency and privacy labels. In Proceedings of the 2022 ACM Conference on Fairness, Accountability, and Transparency, pages 508–520, 2022
2022
-
[36]
Replication: the effect of differential privacy communication on german users’ comprehension and data sharing attitudes
Patrick Kühtreiber, Viktoriya Pak, and Delphine Reinhardt. Replication: the effect of differential privacy communication on german users’ comprehension and data sharing attitudes. In Eighteenth Symposium on Usable Privacy and Security (SOUPS 2022), pages 117–134, 2022
2022
-
[37]
How much is enough? choosing 𝜀 for differential privacy
Jaewoo Lee and Chris Clifton. How much is enough? choosing 𝜀 for differential privacy. In Information Security: 14th International Conference, ISC 2011, Xi’an, China, October 26-29, 2011. Proceedings 14 , pages 325–340. Springer, 2011
2011
-
[38]
Microsoft AI: Differential Privacy, 2023
Microsoft. Microsoft AI: Differential Privacy, 2023. https://www.microsoft.com/ en-us/ai/ai-lab-differential-privacy
2023
-
[39]
Rényi differential privacy
Ilya Mironov. Rényi differential privacy. In 2017 IEEE 30th computer security foundations symposium (CSF), pages 263–275. IEEE, 2017
2017
-
[40]
Visualizing privacy-utility trade-offs in differentially private data releases
Priyanka Nanayakkara, Johes Bater, Xi He, Jessica Hullman, and Jennie Rogers. Visualizing privacy-utility trade-offs in differentially private data releases. arXiv preprint arXiv:2201.05964, 2022
2022 arXiv
-
[41]
What are the chances? explaining the epsilon parameter 13 Onyinye Dibia, Mengyi Lu, Prianka Bhattacharjee, Joseph P
Priyanka Nanayakkara, Mary Anne Smart, Rachel Cummings, Gabriel Kaptchuk, and Elissa M Redmiles. What are the chances? explaining the epsilon parameter 13 Onyinye Dibia, Mengyi Lu, Prianka Bhattacharjee, Joseph P. Near, and Yuanyuan Feng in differential privacy. In 32nd USENIX...
2023
-
[42]
Machine learning with mem- bership privacy using adversarial regularization
Milad Nasr, Reza Shokri, and Amir Houmansadr. Machine learning with mem- bership privacy using adversarial regularization. In Proceedings of the 2018 ACM SIGSAC conference on computer and communications security , pages 634–646, 2018
2018
-
[43]
Programming differential privacy
Joseph P Near and Chiké Abuah. Programming differential privacy. URL: https://uvm, 2021
2021
-
[44]
Guidelines for evaluating differential privacy guarantees
Joseph P Near, David Darais, Naomi Lefkovitz, Gary Howarth, et al. Guidelines for evaluating differential privacy guarantees. National Institute of Standards and Technology, Tech. Rep, 2023
2023
-
[45]
Privacy as contextual integrity
Helen Nissenbaum. Privacy as contextual integrity. Wash. L. Rev., 79:119, 2004
2004
-
[46]
Privacy in context: Technology, policy, and the integrity of social life
Helen Nissenbaum. Privacy in context: Technology, policy, and the integrity of social life. In Privacy in context. Stanford University Press, 2009
2009
-
[47]
The biggest lie on the internet: Ignoring the privacy policies and terms of service policies of social networking services
Jonathan A Obar and Anne Oeldorf-Hirsch. The biggest lie on the internet: Ignoring the privacy policies and terms of service policies of social networking services. Information, Communication & Society , 23(1):128–147, 2020
2020
-
[48]
The privacy deployments registry
Oblivious. The privacy deployments registry. https://registry.oblivious.com/,
-
[49]
Inductive/deductive hybrid thematic analysis in mixed methods research
Kevin Proudfoot. Inductive/deductive hybrid thematic analysis in mixed methods research. Journal of mixed methods research , 17(3):308–326, 2023
2023
-
[50]
Models matter: Setting accurate privacy expectations for local and central differential privacy
Mary Anne Smart, Priyanka Nanayakkara, Rachel Cummings, Gabriel Kaptchuk, and Elissa Redmiles. Models matter: Setting accurate privacy expectations for local and central differential privacy. arXiv preprint arXiv:2408.08475, 2024
2024
-
[51]
The methodology of participatory design
Clay Spinuzzi. The methodology of participatory design. Technical communica- tion, 52(2):163–174, 2005
2005
-
[52]
Census Bureau
U.S. Census Bureau. Why the Census Bureau Chose Differential Privacy, 2023. https://www.census.gov/library/publications/2023/decennial/c2020br-03.html
2023
-
[53]
The influence of explanation designs on user understanding differential privacy and making data-sharing decision
Zikai Alex Wen, Jingyu Jia, Hongyang Yan, Yaxing Yao, Zheli Liu, and Changyu Dong. The influence of explanation designs on user understanding differential privacy and making data-sharing decision. Information Sciences, 642:118799, 2023
2023
-
[54]
Differential privacy: A primer for a non-technical audience
Alexandra Wood, Micah Altman, Aaron Bembenek, Mark Bun, Marco Gaboardi, James Honaker, Kobbi Nissim, David R O’Brien, Thomas Steinke, and Salil Vadhan. Differential privacy: A primer for a non-technical audience. Vand. J. Ent. & Tech. L., 21:209, 2018
2018
-
[55]
Effect of facts box on users’ comprehension of differential privacy: A preliminary study
Aiping Xiong. Effect of facts box on users’ comprehension of differential privacy: A preliminary study. In Proceedings of the Human Factors and Ergonomics Society 2020 Annual Meeting, 2020
2020
-
[56]
Towards effective differential privacy communication for users’ data sharing decision and compre- hension
Aiping Xiong, Tianhao Wang, Ninghui Li, and Somesh Jha. Towards effective differential privacy communication for users’ data sharing decision and compre- hension. In 2020 IEEE Symposium on Security and Privacy (SP) , pages 392–410. IEEE, 2020
2020
-
[57]
Using illustrations to communicate differential privacy trust models: an investigation of users’ comprehension, perception, and data sharing decision
Aiping Xiong, Chuhao Wu, Tianhao Wang, Robert W Proctor, Jeremiah Blocki, Ninghui Li, and Somesh Jha. Using illustrations to communicate differential privacy trust models: an investigation of users’ comprehension, perception, and data sharing decision. arXiv preprint arXiv:220...
2022 arXiv
-
[58]
Exploring use of explanative illustrations to com- municate differential privacy models
Aiping Xiong, Chuhao Wu, Tianhao Wang, Robert W Proctor, Jeremiah Blocki, Ninghui Li, and Somesh Jha. Exploring use of explanative illustrations to com- municate differential privacy models. In Proceedings of the Human Factors and Ergonomics Society Annual Meeting, volume 67, ...
2023
-
[59]
We Need a Standard
Shikun Zhang, Yuanyuan Feng, Yaxing Yao, Lorrie Faith Cranor, and Norman Sadeh. How usable are ios app privacy labels? Proceedings on Privacy Enhancing Technologies, 2022. 14 “We Need a Standard”: Toward an Expert–Informed Privacy Label for Differential Privacy Appendix Append...
2022
-
[62]
We Need a Standard
Why not Include None No valid reason exists not to disclose these parameters; they are essential for clarity and transparency. Privacy The- atre Parameters that mislead stakeholders by ap- pearing to provide strong (robust) privacy protection but fail to provide meaningful pri...
-
[63]
These ranges are inherently context-specific and in- fluenced by the underlying scenario
Normal Range Data/Problem or Algorithm Dependent The appropriate range for parameters varies depending on the dataset, the problem be- ing addressed, or the algorithm used. These ranges are inherently context-specific and in- fluenced by the underlying scenario. Risk Tolerance...
-
[64]
Consensus A range commonly accepted or standardized within the field, facilitating comparisons and usability across implementations
Why the Range Theoretical Justification The range is supported by established theo- retical frameworks or formal definitions, en- suring mathematical soundness. Consensus A range commonly accepted or standardized within the field, facilitating comparisons and usability across ...
-
[65]
Utility If adhering to the normal range significantly reduces data usability, the range becomes im- practical for the intended purpose
Circumstances the normal range is not applicable Composition / Complexity In scenarios involving complex models or multiple composed queries, the normal range may not apply due to added layers of diffi- culty in maintaining consistency. Utility If adhering to the normal range ...
-
[66]
Important for General Public Very Impor- tant Indicates that the parameter is crucial for the general public to understand, as it signifi- cantly impacts their trust, informed decisions (data-sharing decisions) about data privacy and its implications, or perception of privacy ...
-
[67]
Important for Technical Users Very Impor- tant Indicates that the parameter is essential for technical users to implement, evaluate, or op- timize DP systems effectively. Somewhat Im- portant Suggests that the parameter is moderately rel- evant for technical users, aiding thei...
-
[68]
Thoughts about layered structure Support Reflects agreement or approval that a layered structure is effective for presenting param- eters to audiences with different expertise levels, ensuring accessibility for all stakehold- ers. Add Third Layer Suggests enhancing the layered...
-
[69]
Secondary A deeper layer intended for more detailed or technical explanations, tailored for users with advanced knowledge (technical users) or specific needs
Layer to Present Parameters Primary The top layer designed to present the most critical parameters, offering high-level, acces- sible information for a broad audience. Secondary A deeper layer intended for more detailed or technical explanations, tailored for users with advanc...
-
[70]
How to Present Parameters Full Technical Info Present the complete and detailed informa- tion about the parameter, including numer- ical values, descriptions, and links to sup- porting documentation or research papers for technical users. Color-coded The use of a color scheme ...
-
[71]
In the App Embedding the DP label within the applica- tion or tool that interacts with the data, en- suring it’s accessible during use
Where to Place the Label With the Data Release Attaching the DP label directly to the dataset being shared to ensure immediate access by users evaluating the data. In the App Embedding the DP label within the applica- tion or tool that interacts with the data, en- suring it’s ...
-
[72]
Consistency and Standard- ization The DP label follows a uniform design and structure to improve usability and avoid con- fusion across datasets or tools
Thoughts on design and layout Color-coding The use of a color scheme to visually differen- tiate between parameter categories, levels of risk, or importance for quick comprehension (e.g., green for safe, yellow for caution, red for high-risk). Consistency and Standard- ization...
-
[73]
We Need a Standard
Recommendations Educational Resources These are supplementary materials, such as tutorials or guides, to help users understand the parameters and their implications. Mirror Exist- ing Labels Adopting design elements or structures from established labels (e.g., nutrition labels...
-
[2006]
Springer, 2006
Proceedings 3, pages 265–284. Springer, 2006
2006
-
[2024]
Accessed: 2024-09-17
2024
Reviewed August 6, 2026 · model on record in the stance chip above.
Discussion (0). Sign in to comment.