Florian Wittner and his co-authors write about the difficulties arising from the multitude of actors involved with regard to transparency in data protection consent on websites and in apps. The article shows possibilities for the user-friendly design of legally binding notices. It will be presented at the European Conference on Information Systems 2020 (ECIS).
You can download the article here
Abstract
Digital services have undergone a shift to multi-actor constellations characterised by the utilisation of personal data. By involving external actors, service capability and variety increase but so does the number of actors that gain access to personal data. Here, privacy policies are legal documents that serve two primary functions: specifying the purpose and details of data processing in a binding manner and informing users about it. Privacy policies therefore have special importance in which the processing is based on user consent. In a case study of the platform eBay, we identified 18 problems that point out difficulties in achieving consent in a meaningful way in today’s large-scale and massively interconnected digital service ecosystems. Based on these problems, the design goals are determined which help to find meaningful consent in digital service ecosystems. These goals include notifications for changed purposes of data processing in ecosystems or the reasonability of time needed for consent in relation to the usage time of the service. Thus far, no legal limits govern the reasonability of efforts for consent to privacy policies. This requires a fundamental rethinking of the concept of consent or far-reaching automation of privacy-related legal acts.
Kurtz, C.; Wittner, F.; Vogel, P.; Semmann, M.; Böhmann, T. (2020): Design Goals for Consent at Scale in Digital Service Ecosystems. ECIS 2020 Research Papers. 69. https://aisel.aisnet.org/ecis2020_rp/69