Show simple item record

dc.contributor.advisorDavid D. Clark.en_US
dc.contributor.authorSowell, Jesse H., II (Jesse Horton)en_US
dc.contributor.otherMassachusetts Institute of Technology. Technology and Policy Program.en_US
dc.date.accessioned2011-04-04T17:44:45Z
dc.date.available2011-04-04T17:44:45Z
dc.date.copyright2010en_US
dc.date.issued2010en_US
dc.identifier.urihttp://hdl.handle.net/1721.1/62110
dc.descriptionThesis (S.M. in Technology and Policy)--Massachusetts Institute of Technology, Engineering Systems Division, Technology and Policy Program, 2010.en_US
dc.descriptionCataloged from PDF version of thesis.en_US
dc.descriptionIncludes bibliographical references (p. 111-121).en_US
dc.description.abstractOnline service providers (OSPs) such as Google, Yahoo!, and Amazon provide customized features that do not behave as conventional experience goods. Absent familiar metaphors, unraveling the full. scope and implications of attendant privacy hazards requires technical knowledge, creating information asymmetries for casual users. While a number of information asymmetries are proximately rooted in the substantive content of OSP privacy policies, the lack of countervailing standards guidelines can be traced to systemic failures on the part of privacy regulating institutions. In particular, the EU Data Protection Directive (EU-DPD) and the US Safe Harbor Agreement (US-SHA) are based on comprehensive norms, but do not provide pragmatic guidelines for addressing emerging privacy hazards in a timely manner. The dearth of substantive privacy standards for behavioral advertising and emerging location-based services highlight these gaps. To explore this problem, the privacy policies of ten large OSPs were evaluated in terms of strategies for complying with the EU-DPD and US-SHA and in terms of their role as tools for enabling informed decision-making. Analysis of these policies shows that OSPs do little more than comply with the black letter of the EU-DPD and USSHA. Tacit data collection is an illustrative instance. OSP privacy policies satisfice by acknowledging the nominal mechanisms behind tacit data collection supporting services that "enhance and customize the user experience," but these metaphors do not sufficiently elaborate the privacy implications necessary for the user to make informed choices. In contrast, privacy advocates prefer "privacy and surveillance" metaphors that draw users attention away from the immediate gratification of customized services. Although OSPs do bear some responsibility, neither the EU-DPD nor the US-SHA provide the guidance or incentives necessary to develop more substantive privacy standards. In light of these deficiencies, this work identifies an alternative, collaborative approach to the design of privacy standards. OSPs often obscure emerging privacy hazards in favor of promoting innovative services. Privacy advocates err on the other side, giving primacy to "surveillance" metaphors and obscuring the utility of information based services. Rather than forcing users to unravel the conflicting metaphors, collaborative approaches focus on surfacing shared concerns. The collaborative approach presented here attempts to create a forum in which OSPs, advertisers, regulators, and civil society organizations contribute to a strategic menu of technical and policy options that highlight mutually beneficial paths to second best solutions. Particular solutions are developed through a process of issue (re)framing focused on identifying common metaphors that highlight shared concerns, reduce overall information asymmetries, and surface the requirements for governance and privacy tools that address emerging risks. To illustrate this reframing process, common deficiencies identified in the set of privacy policies are presented along with strategic options and examples of potential reframings.en_US
dc.description.statementofresponsibilityby Jesse H. Sowell, II.en_US
dc.format.extent121 p.en_US
dc.language.isoengen_US
dc.publisherMassachusetts Institute of Technologyen_US
dc.rightsM.I.T. theses are protected by copyright. They may be viewed from this source for any purpose, but reproduction or distribution in any format is prohibited without written permission. See provided URL for inquiries about permission.en_US
dc.rights.urihttp://dspace.mit.edu/handle/1721.1/7582en_US
dc.subjectEngineering Systems Division.en_US
dc.subjectTechnology and Policy Program.en_US
dc.titleDeficiencies in online privacy policies : factors and policy recommendationsen_US
dc.typeThesisen_US
dc.description.degreeS.M.in Technology and Policyen_US
dc.contributor.departmentMassachusetts Institute of Technology. Engineering Systems Division
dc.contributor.departmentTechnology and Policy Program
dc.identifier.oclc708362081en_US


Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record