A Multiphase Mixed Methods Analysis of UK E-Commerce Privacy Policies
Total Page:16
File Type:pdf, Size:1020Kb
A Multiphase Mixed Methods Analysis of UK E-Commerce Privacy Policies By David Johnson A Doctoral Thesis Submitted in Partial Fulfilment of the Requirements for the Award of Doctor of Philosophy of Loughborough University 2019 © David Johnson 2019 Acknowledgements I would like to thank my supervisors Professor Adrienne Muir, Professor Louise Cooke and Dr Steve Probets for supporting and guiding me through this research. Without your expertise, your encouragement and your patience this work would not have been possible. I have enjoyed working with you all and I am very grateful for the opportunities that you have provided me while I have been studying at Loughborough University. I would also like to thank my parents, Trevor and Lorraine, for supporting me for many years whilst this research took place. Your support has been immensely helpful and has played a significant role in enabling me to carry out this research. Thank you for taking the time to listen to my thoughts about this research. In addition, I would like to thank those that gave up their time to participate in this research. Your honesty and input were much appreciated at each stage of this research. Finally, I would like to thank those faculty members and PhD students that I have had the privilege to work with and meet along the way. My thanks go to Professor Graham Matthews, Professor Anne Goulding and Ian Murray for providing insightful and constructive comments about this research. Each instance of being able to discuss this research with others helped to provoke thought and in doing so provided the opportunity to reflect on the broader context of research. i Abstract Database technology and advanced statistical processes have rendered it possible to process unprecedented volumes of personal data. However, tension exists between the rights of those that are the subject of personal data processing and the interests of commercial organisations and governments. Privacy policies are supposed to describe how and why personal data is processed. The aim of this research was to explore how these statements could be improved in the context of UK e-commerce. A novel, mixed method phased approach was adopted to address the research aim. In phase one a content analysis of UK e-commerce privacy policies was carried out. Findings showed UK e-commerce privacy policies do not consistently follow good practice guidelines. Moreover, results revealed several information gaps that need to be addressed considering the transparency obligations outlined in the General Data Protection Regulation. Phase two explored user attitudes towards UK e-commerce privacy policies. Barriers to readership and heuristics are outlined along with perceived positive and negative characteristics of UK e-commerce privacy policies. Phase three examined user attitudes towards a layered prototype privacy policy revealing preferences for summary and full layered notices. Phase four demonstrated perceived ease of use and perceived efficiency differences in support of the prototype layered privacy policy compared to a typical privacy. In addition, findings highlighted user support for privacy policy standardisation. Findings from phases one to four are synthesised and evidence-based recommendations are made that are aimed at improving UK e-commerce privacy policies in the short and long term. ii Table of Contents Acknowledgements .................................................................................................... i Abstract .................................................................................................................... ii Table of Contents .................................................................................................... iii Table of Figures ........................................................................................................ x Table of Tables ....................................................................................................... xii Chapter 1 - Introduction .............................................................................. 1 1.1 Research Context .............................................................................................. 1 1.2 Research Topic .................................................................................................. 1 1.3 Research Aim and Questions ............................................................................ 2 1.4 Research Justification ........................................................................................ 2 1.5 Research Contributions ..................................................................................... 3 1.6 Research Scope ................................................................................................ 4 1.7 Thesis Structure ................................................................................................. 4 1.8 Summary ........................................................................................................... 5 Chapter 2 - Literature Review ..................................................................... 6 2.1 Introduction ........................................................................................................ 6 2.2 Understanding Privacy: An Overview ................................................................. 6 2.3 Personal Data Processing: Practice, Concern and Consequence .................... 10 2.3.1 Practice: First Party and Third-Party Data .................................................. 11 2.3.2 Concern: Creepy Marketing ....................................................................... 17 2.3.3 Consequence: Impact on Stated Behaviour ............................................... 18 2.4 Privacy Policies: An Introduction ...................................................................... 19 2.5 Transparency: Theory and Requirements ........................................................ 22 2.5.1 Information Disclosure ................................................................................ 23 2.5.2 Clarity ......................................................................................................... 29 2.5.3 Accuracy .................................................................................................... 30 2.6 Transparency: Problems in Practice ................................................................ 30 2.6.1 Problem One: Not all Websites Publish a Privacy Policy ............................ 30 2.6.2 Problem Two: The Publication of Relevant Information Is Not Consistent .. 31 2.6.3 Problem Three: There Are Mismatches Between Published Information and User Beliefs and Expectations ............................................................................ 33 2.6.4 Problem Four: Privacy policies are Difficult to Understand ......................... 33 iii 2.6.5 Problem Five: Privacy Policy Language Can Obscure the Truth ................ 35 2.6.6 Problem Six: There Are Mismatches Between Policy Meaning and User Understanding..................................................................................................... 36 2.6.7 Problem Seven: Privacy Policies Take Too Long to Read .......................... 37 2.6.8 Problem Eight: Privacy Policies Are Not Displayed In a Friendly Format .... 37 2.6.9 Problem Nine: Privacy Policies Are Not Always Truthful Accounts of Personal Data Processing .................................................................................................. 38 2.7 Addressing the Problems: What Has Been Done So Far? ............................... 39 2.7.1 Platform for Privacy Preferences ................................................................ 39 2.7.2 Financial Privacy Notices ........................................................................... 39 2.7.3 Privacy Label ............................................................................................. 43 2.7.4 Privacy Icons .............................................................................................. 45 2.7.5 Standardisation .......................................................................................... 46 2.7.6 Privacy by Design: User Centricity and Layered Notices ............................ 47 2.7.7 Natural Language Processing .................................................................... 48 2.8 Summary ......................................................................................................... 48 Chapter 3 - Research Methodology .......................................................... 50 3.1 The Nature of Research ................................................................................... 50 3.2 Strategy of Inquiry ............................................................................................ 53 3.3 Multiphase Mixed Methods Design .................................................................. 54 3.4 Phase One: Good Practice .............................................................................. 58 3.4.1 Choosing a Method: Content Analysis ........................................................ 58 3.4.1.1 Operationalisation................................................................................. 59 3.4.1.2 Unitising ............................................................................................... 60 3.4.1.3 Sampling .............................................................................................. 60 3.4.1.4 Piloting the Coding Scheme ................................................................