Is It a Trap? A Large-scale Empirical Study And Comprehensive Assessment of Online Automated Privacy Policy Generators for Mobile Apps
Shidong Pan, Dawen Zhang, Mark Staples, Zhenchang Xing, Jieshan Chen,, Xiwei Xu, and James Hoang

TL;DR
This study evaluates the quality, compliance, and market penetration of online automated privacy policy generators for mobile apps through large-scale empirical analysis.
Contribution
It provides the first comprehensive large-scale assessment of APPGs, analyzing their characteristics, market reach, and compliance with privacy regulations.
Findings
Nearly 20.1% of app privacy policies could be generated by existing APPGs.
Generated policies often do not fully comply with GDPR, CCPA, or LGPD.
The study highlights the importance of careful selection of APPGs by developers.
Abstract
Privacy regulations protect and promote the privacy of individuals by requiring mobile apps to provide a privacy policy that explains what personal information is collected and how these apps process this information. However, developers often do not have sufficient legal knowledge to create such privacy policies. Online Automated Privacy Policy Generators (APPGs) can create privacy policies, but their quality and other characteristics can vary. In this paper, we conduct the first large-scale empirical study and comprehensive assessment of APPGs for mobile apps. Specifically, we scrutinize 10 APPGs on multiple dimensions. We further perform the market penetration analysis by collecting 46,472 Android app privacy policies from Google Play, discovering that nearly 20.1% of privacy policies could be generated by existing APPGs. Lastly, we point out that generated policies in our study do…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsPrivacy, Security, and Data Protection · Green IT and Sustainability · Advanced Malware Detection Techniques
