AI 中文总结
研究美国各州隐私法下移动增强现实隐私政策披露差距,构建数据集,得出分类法并建立自动化流程进行审计,发现广泛差距,四项要求违规率超90%,还发布相关资源支持未来研究。
AI 中文摘要
移动增强现实(MAR)应用可收集和处理空间地图与生物特征等高度敏感数据,但其隐私政策研究不足。以往对应用隐私政策的审计多聚焦单一法律框架,如《通用数据保护条例》。美国20个州已有全面隐私法,构成分散且快速演变的隐私政策义务体系。本文首次对美国各州隐私法下的MAR隐私政策进行大规模审计。构建涵盖MAR生态系统的数据集,得出可审计披露分类法及经过验证的四阶段自动化流程以产生可追溯、有证据支持的披露判断。审计发现广泛的披露差距,44.62%的审计政策存在严重披露遗漏,四项隐私政策要求违规率超90%。研究结果表明MAR隐私披露未跟上美国各州隐私法规日益增长的复杂性。我们发布数据集、分类法和审计流程以支持未来可扩展隐私合规审计研究。
英文摘要
Mobile Augmented Reality (MAR) apps can collect and process highly sensitive data such as spatial maps and biometrics, yet their privacy policies remain largely understudied. Prior audits of app privacy policies have typically focused on a single legal framework, such as the GDPR. Meanwhile, 20 U.S. states have comprehensive privacy laws in effect, creating a fragmented and rapidly evolving set of privacy policy obligations. To date, no study has systematically audited privacy policies against this emerging body of state-level legislation. In this paper, we present the first large-scale audit of MAR privacy policies under U.S. state privacy laws. We construct a dataset covering the MAR ecosystem, including 8,013 Google Play MAR app metadata records worldwide, and a U.S.-based subset with 6,620 APKs and 6,426 privacy policy files. We further derive an auditable disclosure taxonomy with 5 baseline requirements, 10 triggered requirements, and 4 logic chains, and build a validated four-stage automated pipeline that produces traceable, evidence-grounded disclosure judgments. Our audit reveals widespread disclosure gaps: 44.62\% of audited policies exhibit severe disclosure omissions, with each missing more than eight requirements, and four privacy-policy requirements have violation rates above 90\%. These findings suggest that MAR privacy disclosures are not keeping pace with the growing complexity of U.S. state privacy regulation. We release our dataset, taxonomy, and auditing pipeline to support future research on scalable privacy compliance auditing.