The Impact of Visibility on the Right to Opt-out of Sale under CCPA

06/21/2022
by   Aden Siebel, et al.
0

The California Consumer Protection Act (CCPA) gives users the right to opt-out of sale of their personal information, but prior work has found that opt-out mechanisms provided under this law result in very low opt-out rates. Privacy signals offer a solution for users who are aware of their rights and are willing to proactively take steps to enable privacy-enhancing tools, but this work findsthat many users are not aware of their rights under CCPA and that current opt-out rates are very low. We therefore explore an alternative approach to enhancing privacy under CCPA: increasing the visibility of opt-out of sale mechanisms. For this purpose, we design and implement CCPA Opt-out Assistant (COA), a browser extension that automatically detects when websites sell personal information and presents users with a visible, standardized banner that links to the opt-out of sale mechanism for the website. We conduct an online user study with 54 participants that finds that these banners significantly increases the rate at which users opt-out of sale of their personal information. Participants also report less difficulty opting-out and more satisfaction with opt-out mechanisms compared to the native mechanisms currently provided by websites. Our results suggest that effective privacy regulation depends on imposing clear, enforceable visibility standards, and that CCPA's requirements for opt-out of sale mechanisms fall short.

READ FULL TEXT

page 3

page 4

page 5

page 6

research
09/02/2023

Are Current CCPA Compliant Banners Conveying User's Desired Opt-Out Decisions? An Empirical Study of Cookie Consent Banners

The California Consumer Privacy Act (CCPA) secures the right to Opt-Out ...
research
09/16/2020

(Un)clear and (In)conspicuous: The right to opt-out of sale under CCPA

The California Consumer Privacy Act (CCPA)—which began enforcement on Ju...
research
08/26/2020

"My Friend Wanted to Talk About It and I Didn't": Understanding Perceptions of Deletion Privacy in Social Platforms

There is a growing concern and awareness about the right-to-be-forgotten...
research
04/08/2022

CookieEnforcer: Automated Cookie Notice Analysis and Enforcement

Online websites use cookie notices to elicit consent from the users, as ...
research
11/22/2022

Twitter has a Binary Privacy Setting, are Users Aware of How It Works?

Twitter accounts are public by default, but Twitter gives the option to ...
research
02/02/2022

Opted Out, Yet Tracked: Are Regulations Enough to Protect Your Privacy?

Data protection regulations, such as GDPR and CCPA, require websites and...
research
09/05/2019

(Un)informed Consent: Studying GDPR Consent Notices in the Field

Since the adoption of the General Data Protection Regulation (GDPR) in M...

Please sign up or login with your details

Forgot password? Click here to reset