Authors:
Jens Leicht
;
Julien Lukasewycz
and
Maritta Heisel
Affiliation:
Paluno - The Ruhr Institute for Software Technology, University of Duisburg-Essen, Germany
Keyword(s):
General Data Protection Regulation, User Interfaces, Consent Management, Privacy Policy Customization, Policy Languages, Tool Support, Privacy Policy Visualization.
Abstract:
The General Data Protection Regulation (GDPR) demands data controllers to provide transparent information about data processing to data subjects. This information is mostly provided in the form of textual privacy policies. These policies have many disadvantages, such as their inconsistent structure and terminology, their large scope, and their high complexity. For this reason, data subjects are likely to accept the agreement even if they do not fully agree with the data processing contained in it; this phenomenon is known as the privacy paradox. To overcome these disadvantages, we propose a user interface based on the results from a thorough literature review and a group interview. By not relying on a completely textual approach, we reduce the mental effort required from data subjects and increase transparency. We utilize the Prolog - Layered Privacy Language (P-LPL), which allows data subjects to customize privacy policies. Our work extends the compliance checks of P-LPL with compat
ibility checks for customized privacy policies. The proposed interface provides graphical representations for privacy policies, aligning with different mental models of data subjects. We provide a prototype to demonstrate the proposed theoretical concepts.
(More)