TL;DR
This study analyzes the impact of GDPR on online privacy policies, revealing extensive textual changes, improved compliance, and increased transparency, but also highlighting ongoing gaps and transitional challenges in policy adherence.
Contribution
It provides the first large-scale longitudinal assessment of privacy policies before and after GDPR, introducing a new automated workflow for compliance evaluation.
Findings
Privacy policies became longer and more comprehensive post-GDPR.
User perception of privacy policies improved for EU websites.
Policies show increased compliance and specificity, but gaps remain.
Abstract
The EU General Data Protection Regulation (GDPR) is one of the most demanding and comprehensive privacy regulations of all time. A year after it went into effect, we study its impact on the landscape of privacy policies online. We conduct the first longitudinal, in-depth, and at-scale assessment of privacy policies before and after the GDPR. We gauge the complete consumption cycle of these policies, from the first user impressions until the compliance assessment. We create a diverse corpus of two sets of 6,278 unique English-language privacy policies from inside and outside the EU, covering their pre-GDPR and the post-GDPR versions. The results of our tests and analyses suggest that the GDPR has been a catalyst for a major overhaul of the privacy policies inside and outside the EU. This overhaul of the policies, manifesting in extensive textual changes, especially for the EU-based…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
