Automated analysis of privacy policies has proved a fruitful research direction, with developments such as automated policy summarization, question answering systems, and compliance detection. Prior research has been limited to analysis of privacy policies from a single point in time or from short spans of time, as researchers did not have access to a large-scale, longitudinal, curated dataset. To address this gap, we developed a crawler that discovers, downloads, and extracts archived privacy policies from the Internet Archive's Wayback Machine. Using the crawler and following a series of validation and quality control steps, we curated a dataset of 1,071,488 English language privacy policies, spanning over two decades and over 130,000 distinct websites. Our analyses of the data paint a troubling picture of the transparency and accessibility of privacy policies. By comparing the occurrence of tracking-related terminology in our dataset to prior web privacy measurements, we find that privacy policies have consistently failed to disclose the presence of common tracking technologies and third parties. We also find that over the last twenty years privacy policies have become even more difficult to read, doubling in length and increasing a full grade in the median reading level. Our data indicate that self-regulation for first-party websites has stagnated, while self-regulation for third parties has increased but is dominated by online advertising trade associations. Finally, we contribute to the literature on privacy regulation by demonstrating the historic impact of the GDPR on privacy policies.
翻译:对隐私政策进行自动化分析已证明是一个富有成果的研究方向,其发展动态包括自动化政策总结、问答系统和合规检测等。先前的研究仅限于从一个时间点或短时间段分析隐私政策,因为研究人员无法获得大规模、纵向和经整理的数据集。为弥补这一差距,我们开发了一个爬行器,从因特网档案的“回路机器”中发现、下载和提取存档隐私政策。利用爬行器和一系列验证和质量控制步骤,我们整理了一套1,071,488个英语隐私政策,涵盖20多年和130多个不同网站。我们的数据分析描绘了隐私政策透明度和可获取性方面令人不安的图景。通过将我们数据集中与跟踪有关的术语的出现与先前的网络隐私测量进行比较,我们发现隐私政策一直未能披露共同跟踪技术和第三方的存在。我们还发现,在过去二十年中层隐私政策变得更加难以阅读,其长度翻了一番,并在中位读文献中位增加了整整1,300多个不同网站。我们的数据分析描绘了隐私政策的透明度和可获取性图象。最后,通过在线监管,我们数据库的自我监管增加了在线监管,从而展示了公司内部监管,从而提高了自我监管。