Automated Approach to Improve IoT Privacy Policies

10/06/2019
by   Parvaneh Shayegh, et al.
0

The massive growth of the Internet of Things (IoT) as a network of interconnected entities [18], brings up new challenges in terms of privacy and security requirements to the traditional software engineering domain [4]. To protect the individuals' privacy, the FTC's Fair Information Practice Principles (FIPPs) [6] proposes to companies to give notice to the consumer about their data practices, provide them with choices and give them means to have control over their own data.. Using privacy policy is the most common way for this type of notices. However, privacy policies are not generally effective due to two main reasons: first, privacy policies are long and full of legal jargon which are not understandable by a normal user; second, it is not guaranteed that an IoT device behave as it is explained in its privacy policy. In this technical report, we propose and discuss our methodologies to analyze privacy policies. By the help of this analysis, we reduce the length of a privacy policy and make it organized based on privacy practices to improve understanding level for the user. We also come up with a method to find the inconsistencies between IoT devices and their privacy policies.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
11/08/2021

Automated Detection of GDPR Disclosure Requirements in Privacy Policies using Deep Active Learning

Since GDPR came into force in May 2018, companies have worked on their d...
research
06/24/2020

Interactive Privacy Preferences Management for Shared Spaces in Internet of Things

The balance between protecting users' privacy while providing cost-effec...
research
09/28/2021

Fighting the Fog: Evaluating the Clarity of Privacy Disclosures in the Age of CCPA

Vagueness and ambiguity in privacy policies threaten the ability of cons...
research
08/19/2019

Three Dimensions of Privacy Policies

Privacy policies are the main way to obtain information related to perso...
research
03/10/2020

IoT Expunge: Implementing Verifiable Retention of IoT Data

The growing deployment of Internet of Things (IoT) systems aims to ease ...
research
02/07/2018

Polisis: Automated Analysis and Presentation of Privacy Policies Using Deep Learning

Privacy policies are the primary channel through which companies inform ...
research
08/11/2023

PrivacyLens: A Framework to Collect and Analyze the Landscape of Past, Present, and Future Smart Device Privacy Policies

As the adoption of smart devices continues to permeate all aspects of ou...

Please sign up or login with your details

Forgot password? Click here to reset