发表机构
University of Michigan; University of North Florida(密歇根大学; 北佛罗里达大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究提出一个基于大型语言模型的可扩展框架,将10,000个网站隐私政策转化为结构化数据,并引入四个维度的定量指标,以评估用户保护与商业利益之间的张力。
AI 中文摘要
尽管隐私政策是组织披露其如何收集、处理和共享个人数据的主要机制,但由于其冗长和密集的法律语言,普通用户很难解读这些政策,这或许是有意为之。重要的是,目前缺乏超越监管要求的、能够表征隐私政策关键质量的标准化指标。大型语言模型(LLM)的最新进展使得大规模自动结构化并分析这些文档成为可能。在本研究中,我们开发并评估了一个端到端的、基于LLM的系统,该系统将原始隐私政策转换为细粒度的结构化表示和一组定量度量。我们的流程应用一个详细的分类法来提取特定的数据元素和管理实践,捕获将每项实践与其引用的数据元素连接起来的关系链接。我们将该框架应用于包含10,000个网站隐私政策的多样化语料库,据我们所知,生成了迄今为止同类中最全面的数据集。基于我们的结构化表示,我们引入了首个标准化且可重复的定量指标,用于从四个维度评估隐私政策:完整性、透明度、对用户保护的承诺以及对业务驱动数据实践的重视。这使我们能够比较行业内和跨行业的政策,并评估用户保护与商业利益之间的张力。
英文摘要
Even though privacy policies are the primary mechanism organizations use to disclose how they collect, process, and share personal data, they are difficult for average users to interpret, perhaps by design, due to their verbosity and dense legal language. Importantly, there is a lack of standardized metrics that characterize key qualities of a privacy policy beyond regulatory requirements. Recent advances in large language models (LLMs) make it feasible to automatically structure and analyze these documents at scale. In this study, we develop and evaluate an end-to-end, LLM-enabled system that converts raw privacy policies into fine-grained structured representations and a set of quantitative measures. Our pipeline applies a detailed taxonomy to extract specific data elements and governing practices, capturing relational links that connect each practice to the data elements it references. We apply our framework to a diverse corpus of 10,000 website privacy policies, yielding, to the best of our knowledge, the most comprehensive dataset of its kind to date. Building on our structured representations, we introduce the first standardized and repeatable quantitative metrics for evaluating privacy policies along four dimensions: completeness, transparency, commitment to user protection, and emphasis on business-driven data practices. This allows us to compare policies within and across industry sectors, and to assess the tension between user protection and business interests.