{"id":370473,"date":"2021-11-21T22:48:39","date_gmt":"2021-11-21T19:48:39","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/avoid-a-privacy-nightmare-with-lean-privacy-review\/"},"modified":"2021-11-21T22:48:39","modified_gmt":"2021-11-21T19:48:39","slug":"avoid-a-privacy-nightmare-with-lean-privacy-review","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/avoid-a-privacy-nightmare-with-lean-privacy-review\/","title":{"rendered":"#Avoid a privacy nightmare with &#8216;Lean Privacy Review&#8217;"},"content":{"rendered":"<p>&#8220;<strong>#Avoid a privacy nightmare with &#8216;Lean Privacy Review&#8217;<\/strong>&#8221;<\/p>\n<div>\n<div class=\"article-gallery lightGallery\">\n<div data-thumb=\"https:\/\/scx1.b-cdn.net\/csz\/news\/tmb\/2021\/avoid-a-privacy-nightm.jpg\" data-src=\"https:\/\/scx2.b-cdn.net\/gfx\/news\/2021\/avoid-a-privacy-nightm.jpg\" data-sub-html=\"A privacy storyboard illustrating data practices during the scenario of using a loyalty card in a retail store. Credit: CyLab\">\n<figure class=\"article-img\">\n            <img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/scx1.b-cdn.net\/csz\/news\/800a\/2021\/avoid-a-privacy-nightm.jpg\" alt=\"Avoid a privacy nightmare with 'Lean Privacy Review'\" title=\"A privacy storyboard illustrating data practices during the scenario of using a loyalty card in a retail store. Credit: CyLab\" width=\"800\" height=\"455\"\/><figcaption class=\"text-darken text-low-up text-truncate-js text-truncate mt-3\">\n                A privacy storyboard illustrating data practices during the scenario of using a loyalty card in a retail store. Credit: CyLab<br \/>\n            <\/figcaption><\/figure>\n<\/p><\/div>\n<\/div>\n<p>When Google launched its own attempt at a <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/social-mediaa\/\" data-internallinksmanager029f6b8e52c=\"1\" title=\"Social Media\" target=\"_blank\" rel=\"noopener\">social<\/a> network\u2014Google Buzz\u2014back in 2010, the company initially suffered a PR nightmare. &#8220;WARNING: Google Buzz Has A Huge Privacy Flaw,&#8221; read Business Insider. It turned out, Google was generating user connections by collecting contact info from users&#8217; Gmail accounts. In other words, anyone on the social network could see who anyone else&#8217;s personal contacts were.<\/p>\n<p>                                                                                To try to avoid privacy nightmares like that one, companies sometimes perform privacy reviews on new <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">app<\/a>lications or services to try to catch any potential privacy issues before they&#8217;re released. These reviews typically involve privacy experts and lawyers and tend to cost quite a bit of money and time, making them not very feasible for many companies. They also rarely involve actual user feedback. <\/p>\n<p>But a recent study by Carnegie Mellon University CyLab researchers proposes a new kind of privacy review\u2014one that is cheaper and makes it easy to hear direct user feedback early in the development process. The study, &#8220;Lean Privacy Review: Collecting Users&#8217; Privacy Concerns of Data Practices at a Low Cost,&#8221; was published in the current issue of <i>ACM Transactions on Computer-Human Interaction<\/i>. <\/p>\n<p>&#8220;Lean Privacy Review can help reveal privacy concerns actual people can have at a tiny fraction of the cost and wait-time for a formal review,&#8221; says Haojian Jin, a Ph.D. student in the Human-Computer Interaction Institute (HCII) and the study&#8217;s lead author.<\/p>\n<p>The authors say that a Lean Privacy Review\u2014or LPR for short\u2014isn&#8217;t meant to replace the formal privacy review\u2014privacy experts and lawyers are still necessary\u2014but rather to supplement the formal review to make the whole process easier and smoother. They say that LPR is especially useful in the very early stages of design. <\/p>\n<p>&#8220;If you can find these problems much earlier on, and cheaper, it&#8217;s actually good for everybody,&#8221; says CyLab&#8217;s Jason Hong, a professor in the HCII and a co-author of the study. &#8220;The speed and low cost of LPR increases its flexibility and allows it to be used more often and throughout the entire design process rather than just a one-time formal privacy review.&#8221;<\/p>\n<p>LPR begins when a practitioner wants to understand users&#8217; privacy concerns of using a certain type of data for a specific purpose. They&#8217;ll create a privacy storyboard using the <a rel=\"nofollow noopener\" target=\"_blank\" href=\"http:\/\/www.leanprivacyreview.com\/\">LPR website<\/a> to communicate one or any of the four main actions performed on that data: data collection, sharing, processing, and usage. Using the storyboard, the website will then create a survey for users, in which they describe the data action, and then ask how they feel about the action, and why in plain English. The practitioner may distribute the survey through any number of survey channels, e.g. crowd workers on Amazon Mechanical Turk or Google Marketing Platform. <\/p>\n<p>After the survey has been conducted, a web interface aggregates all of the privacy concerns identified by users into a <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/watch-movies-tv-seriess\/\" data-internallinksmanager029f6b8e52c=\"8\" title=\"Watch Movies &amp; TV Series\" target=\"_blank\" rel=\"noopener\">series<\/a> of graphics. <\/p>\n<p>&#8220;Through these visualizations, practitioners can have both a quantitative and qualitative view of potential privacy concerns, namely, how severely the concerns are and what the concerns are,&#8221; says Jin.<\/p>\n<p>The researchers evaluated LPR using 12 real-world data practice scenarios\u2014including the Google Buzz scenario\u2014with 240 crowd users and 24 data practitioners. They found that it only takes ~ 14 participants to find the vast majority of the privacy concerns and costs less than four hours of total crowd work for a given scenario. That&#8217;s equivalent to about $80. <\/p>\n<p>&#8220;Our results show that LPR is inexpensive, fast, consistent, and can provide high-quality privacy review results,&#8221; the authors write in the study. <\/p>\n<p>It&#8217;s hard to know for sure what kind of privacy review, if any, Google had performed before launching Google Buzz (the company did address the issues relatively quickly after the public uproar), but it&#8217;s possible they could have dodged their privacy nightmare if they&#8217;d had LPR. <\/p>\n<p>For those interested, <a rel=\"nofollow noopener\" target=\"_blank\" href=\"http:\/\/www.leanprivacyreview.com\/\">LPR has a website<\/a> where one can explore the method and create storyboards.\n                                                                                                                        <\/p>\n<hr\/>\n<div class=\"article-main__explore my-4 d-print-none\">\n<p>                                            Zoom to settle US privacy lawsuit for $85 mn\n                                        <\/p><\/div>\n<hr class=\"mb-4\"\/>\n<div class=\"article-main__more p-4\">\n                                                                                                <strong>More information:<\/strong><br \/>\n                                                Haojian Jin et al, Lean Privacy Review: Collecting Users&#8217; Privacy Concerns of Data Practices at a Low Cost, <i>ACM Transactions on Computer-Human Interaction<\/i> (2021).  <a rel=\"nofollow noopener\" target=\"_blank\" data-doi=\"1\" href=\"http:\/\/dx.doi.org\/10.1145\/3463910\">DOI: 10.1145\/3463910<\/a><\/p><\/div>\n<div class=\"d-inline-block text-medium my-4\">\n                                                Provided by<br \/>\n                                                                                                    Carnegie Mellon University<br \/>\n                                                                                                        <a rel=\"nofollow noopener\" target=\"_blank\" class=\"icon_open\" href=\"http:\/\/www.cmu.edu\/index.shtml\"><br \/>\n                                                        <svg>\n                                                            <use href=\"https:\/\/techx.b-cdn.net\/tmpl\/v2\/img\/svg\/sprite.svg#icon_open\" x=\"0\" y=\"0\"\/>\n                                                        <\/svg><br \/>\n                                                    <\/a><\/p><\/div>\n<p>                                        <!-- print only --><\/p>\n<div class=\"d-none d-print-block\">\n<p>                                                 <strong>Citation<\/strong>:<br \/>\n                                                 Avoid a privacy nightmare with &#8216;Lean Privacy Review&#8217; (2021, November 21)<br \/>\n                                                 retrieved 21 November 2021<br \/>\n                                                 from https:\/\/techxplore.com\/<a href=\"https:\/\/buradabiliyorum.com\/en\/category\/news\/\" data-internallinksmanager029f6b8e52c=\"2\" title=\"News\" target=\"_blank\" rel=\"noopener\">news<\/a>\/2021-11-privacy-nightmare.html<\/p>\n<p>                                            This document is subject to copyright. Apart from any fair dealing for the purpose of private study or research, no<br \/>\n                                            part may be reproduced without the written permission. The content is provided for information purposes only.<\/p><\/div>\n<\/p><\/div>\n<p><script id=\"facebook-jssdk\" async=\"\" src=\"https:\/\/connect.facebook.net\/en_US\/sdk.js\"><\/script><\/p>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong>\n<\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more Like this articles, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/science\/\" target=\"_blank\" rel=\"noopener\">Science category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/techxplore.com\/news\/2021-11-privacy-nightmare.html\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;#Avoid a privacy nightmare with &#8216;Lean Privacy Review&#8217;&#8221; A privacy storyboard illustrating data practices during the scenario of using a loyalty card in a retail store. Credit: CyLab When Google launched its own attempt at a social network\u2014Google Buzz\u2014back in 2010, the company initially suffered a PR nightmare. &#8220;WARNING: Google Buzz Has A Huge Privacy&#8230;<\/p>\n","protected":false},"author":1,"featured_media":370474,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/scx2.b-cdn.net\/gfx\/news\/2021\/avoid-a-privacy-nightm.jpg","fifu_image_alt":"","footnotes":""},"categories":[16],"tags":[],"class_list":["post-370473","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sciencee"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/370473","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=370473"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/370473\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/370474"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=370473"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=370473"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=370473"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}