The Bulletproof Glass Effect: Unintended Consequences of Privacy Notices
journals.sagepub.com
journals.sagepub.com
To use their metaphor of bulletproof glass, suppose a company pointed a sheet of cardboard as a safety measure. Strictly speaking, a bullet will be moving slower after going through the cardboard, so it is t detrimental on its own. However, if a company lists it as a safety measure without listing anything else, I'd be more worried. Where before there was uncertainty about whether their practices were sufficient, after there was certainty that they are insufficient.
In the same way, any privacy policy that includes "We only share your data with our trusted business partners." decreases my overall trust. Because that is already an admission of data changing hands, being used for further aggregation. Saying that you'll only share data about me when provided money in a business relationship is strictly better that sharing it publicly at all times, but isn't sufficient to give me any comfort.
And on the analogy of the bullet-proof glass. The bullet-proof glass is never there to protect you the customer. it is only there to protect the company.
1. Be short enough that I can read it quickly (at most a couple minutes)
2. Be easily understandable
3. Actually have meaningful protections for my privacy
Most privacy policies are none of those.
https://littlegreenviper.com/welcome-to-little-green-viper/p...
First sentence is unnecessary.
It would be better if it disallowed taking data for a legit reason and then using it for another less scrupulous reason. Point 5 may mitigate this concern substantially however.
Yeah, I think I agree.
> A privacy notice, by placing legally enforceable limits on a firm's data practices, communicating safeguards, and signaling transparency, might be expected to promote confidence that personal data will not be misused. Indeed, most managers expected a privacy notice to make customers feel more secure (Study 1). Yet, consistent with the analogy that bulletproof glass can increase feelings of vulnerability despite the protection offered, formal privacy notices undermined consumer trust and decreased purchase interest even when they emphasized objective protection (Studies 2, 3, and 5) or omitted any mention of potentially concerning data practices (Study 6).
https://www.hbs.edu/ris/Publication%20Files/The%20Bulletproo...
I see long winded policies as cover-your-ass for the business.
The language and format isn’t any different from EULAs and lends zero confidence because I have no way of verifying misbehavior, short of doing things like one-off email accounts.
Not dissimilar to business whistle-blower “protection” and HR’s mandatory “ethics” and other legal courses.
The C.A.R.E.S. Act had nothing to do with caring. "Lifetime warranty" has a very specific meaning. "Organic" isn't what you think it means. Love. (Feel free to add your own interpretation on this one ;) )
Having gone through several GDPR implementation process in Europe, it’s what the citizens of USA need, but not what American companies or government agencies want. So from my perspective, American citizens will never fully be protected. Sadly.