Employees are often required to use Enterprise Security Software ("ESS") on corporate and personal devices. ESS products collect users' activity data including users' location, applications used, and websites visited - operating from employees' device to the cloud. To the best of our knowledge, the privacy implications of this data collection have yet to be explored. We conduct an online survey (n=258) and a semi-structured interview (n=22) with ESS users to understand their privacy perceptions, the challenges they face when using ESS, and the ways they try to overcome those challenges. We found that while many participants reported receiving no information about what data their ESS collected, those who received some information often underestimated what was collected. Employees reported lack of communication about various data collection aspects including: the entities with access to the data and the scope of the data collected. We use the interviews to uncover several sources of misconceptions among the participants. Our findings show that while employees understand the need for data collection for security, the lack of communication and ambiguous data collection practices result in the erosion of employees' trust on the ESS and employers. We obtain suggestions from participants on how to mitigate these misconceptions and collect feedback on our design mockups of a privacy notice and privacy indicators for ESS. Our work will benefit researchers, employers, and ESS developers to protect users' privacy in the growing ESS market.
翻译:我们发现,虽然许多参与者报告说,他们没有收到关于所收集的数据的信息,但收到一些信息的人往往低估了所收集的信息。 雇员报告说,没有就各种数据收集方面进行沟通,包括:能够查阅数据的实体和所收集数据的范围。我们利用访谈找出参与者中的一些误解来源。我们的调查结果表明,虽然雇员理解需要收集安全数据、缺乏沟通和数据收集方法模糊不清,从而削弱了雇员对斯洛文尼亚就业服务局和雇主的信任。 我们从参与者那里获得关于如何减少这些误解的建议,并收集我们设计投资者的隐私指标。