The California Consumer Protection Act (CCPA) gives users the right to opt-out of sale of their personal information, but prior work has found that opt-out mechanisms provided under this law result in very low opt-out rates. Privacy signals offer a solution for users who are aware of their rights and are willing to proactively take steps to enable privacy-enhancing tools, but this work findsthat many users are not aware of their rights under CCPA and that current opt-out rates are very low. We therefore explore an alternative approach to enhancing privacy under CCPA: increasing the visibility of opt-out of sale mechanisms. For this purpose, we design and implement CCPA Opt-out Assistant (COA), a browser extension that automatically detects when websites sell personal information and presents users with a visible, standardized banner that links to the opt-out of sale mechanism for the website. We conduct an online user study with 54 participants that finds that these banners significantly increases the rate at which users opt-out of sale of their personal information. Participants also report less difficulty opting-out and more satisfaction with opt-out mechanisms compared to the native mechanisms currently provided by websites. Our results suggest that effective privacy regulation depends on imposing clear, enforceable visibility standards, and that CCPA's requirements for opt-out of sale mechanisms fall short.
翻译:《加利福尼亚消费者保护法》赋予用户选择不出售个人信息的权利,但先前的工作发现,根据该法提供的选择不出售机制导致选择不出售率非常低。 隐私信号为了解自身权利并愿意主动采取措施提供增强隐私工具的用户提供了一个解决方案,但这项工作发现,许多用户不知道自己根据《加利福尼亚消费者保护法》享有的权利,目前的选择不出售率很低。因此,我们探索了另一种办法,根据《加利福尼亚消费者保护法》加强隐私:提高选择不出售机制的可见度。为此,我们设计和实施了CAPA Opt-out助理(COA),这是一个浏览器扩展,在网站出售个人信息时自动检测,向用户提供与网站选择不出售机制链接的可见的标准化标语。我们与54名参与者进行了在线用户研究,发现这些标语大大提高了用户选择不出售个人信息的速度。与会者还报告说,与目前由网站提供的本地机制相比,选择退出和更加满意的选择机制。我们的结果表明,有效的保密性标准取决于清晰的可执行性标准。