{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,26]],"date-time":"2025-03-26T08:26:12Z","timestamp":1742977572932,"version":"3.40.3"},"publisher-location":"Cham","reference-count":37,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030939434"},{"type":"electronic","value":"9783030939441"}],"license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022]]},"DOI":"10.1007\/978-3-030-93944-1_3","type":"book-chapter","created":{"date-parts":[[2022,1,23]],"date-time":"2022-01-23T18:02:53Z","timestamp":1642960973000},"page":"39-54","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Quantitative Rubric for Privacy Policy Analysis"],"prefix":"10.1007","author":[{"given":"Paul","family":"O\u2019Donnell","sequence":"first","affiliation":[]},{"given":"Joe","family":"Harrison","sequence":"additional","affiliation":[]},{"given":"Joshua","family":"Lyons","sequence":"additional","affiliation":[]},{"given":"Lauren","family":"Anderson","sequence":"additional","affiliation":[]},{"given":"Lauren","family":"Maunder","sequence":"additional","affiliation":[]},{"given":"Sarah","family":"Ramboyong","sequence":"additional","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2437-3410","authenticated-orcid":false,"given":"Alan J.","family":"Michaels","sequence":"additional","affiliation":[]}],"member":"297","published-online":{"date-parts":[[2022,1,23]]},"reference":[{"key":"3_CR1","unstructured":"https:\/\/www.github.com\/humeESL\/Use-and-Abuse-PII\/"},{"key":"3_CR2","unstructured":"Platform for privacy preferences (P3P) project. https:\/\/www.w3.org\/P3P\/"},{"key":"3_CR3","unstructured":"U.S. Census Bureau QuickFacts. https:\/\/www.census.gov\/quickfacts\/"},{"key":"3_CR4","unstructured":"Terms of Service; Didn\u2019t Read (2020). https:\/\/tosdr.org\/"},{"issue":"2","key":"3_CR5","doi-asserted-by":"publisher","first-page":"36","DOI":"10.1109\/MSECP.2004.1281243","volume":"2","author":"A Anton","year":"2004","unstructured":"Anton, A., Earp, J., He, Q., Stufflebeam, W., Bolchini, D., Jensen, C.: Financial privacy policies and the need for standardization. IEEE Secur. Priv. 2(2), 36\u201345 (2004). https:\/\/doi.org\/10.1109\/MSECP.2004.1281243","journal-title":"IEEE Secur. Priv."},{"key":"3_CR6","unstructured":"Apple: Privacy policy (2019). https:\/\/www.apple.com\/legal\/privacy\/en-ww\/"},{"key":"3_CR7","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-642-23556-6_1","volume-title":"Secure Data Management","author":"M Banerjee","year":"2011","unstructured":"Banerjee, M., Karimi Adl, R., Wu, L., Barker, K.: Quantifying privacy violations. In: Jonker, W., Petkovi\u0107, M. (eds.) SDM 2011. LNCS, vol. 6933, pp. 1\u201317. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-23556-6_1"},{"key":"3_CR8","unstructured":"BBC: BBC news (2018). https:\/\/www.bbc.com\/news"},{"key":"3_CR9","unstructured":"Bed Bath and Beyond: Privacy policy (2021). https:\/\/www.bedbathandbeyond.com\/store\/static\/PrivacyPolicy"},{"key":"3_CR10","unstructured":"Commonsense.org: It\u2019s not you, privacy policies are difficult to read (2020). https:\/\/www.commonsense.org\/education\/articles\/its-not-you-privacy-policies-are-difficult-to-read"},{"key":"3_CR11","doi-asserted-by":"publisher","unstructured":"Cranor, L.F., Hoke, C., Leon, P., Au, A.: Are they worth reading? An in-depth analysis of online advertising companiess privacy policies. SSRN Electron. J. (2014). https:\/\/doi.org\/10.2139\/ssrn.2418590","DOI":"10.2139\/ssrn.2418590"},{"key":"3_CR12","unstructured":"Discord: Terms of Service (2018). https:\/\/discord.com\/terms"},{"key":"3_CR13","doi-asserted-by":"crossref","unstructured":"Fabian, B., Ermakova, T., Lentz, T.: Large-scale readability analysis of privacy policies. In: Proceedings of the International Conference on Web Intelligence, WI 2017, pp. 18\u201325. ACM (2017)","DOI":"10.1145\/3106426.3106427"},{"key":"3_CR14","unstructured":"Facebook: Facebook data policy. https:\/\/www.facebook.com\/about\/privacy"},{"key":"3_CR15","unstructured":"Harkous, H. et al.: Polisis: automated analysis and presentation of privacy policies using deep learning. In: 27th $$\\{$$USENIX$$\\}$$ Security Symposium, pp. 531\u2013548 (2018)"},{"issue":"5\u20136","key":"3_CR16","first-page":"260","volume":"27","author":"J Kaur","year":"2018","unstructured":"Kaur, J., Dara, R.A., Obimbo, C., Song, F., Menard, K.: A comprehensive keyword analysis of online privacy policies. Inf. Secur. J.: Glob. Perspect. 27(5\u20136), 260\u2013275 (2018)","journal-title":"Inf. Secur. J.: Glob. Perspect."},{"key":"3_CR17","doi-asserted-by":"publisher","unstructured":"Kelley, P.G., Cesca, L., Bresee, J., Cranor, L.F.: Standardizing privacy notices: An online study of the nutrition label approach. In: Proceedings of the SIGCHI Conference on Human Factors in Computing Systems, CHI 2010, pp. 1573\u20131582. Association for Computing Machinery, New York (2010). https:\/\/doi.org\/10.1145\/1753326.1753561","DOI":"10.1145\/1753326.1753561"},{"key":"3_CR18","unstructured":"Kincaid, J.P., Fishburne Jr, R.P., Rogers, R.L., Chissom, B.S.: Derivation of new readability formulas for Navy enlisted personnel. Technical report (1975)"},{"key":"3_CR19","first-page":"71","volume":"84","author":"BA Lee","year":"2011","unstructured":"Lee, B.A.: Making sense of moral rights in intellectual property. Temp. L. Rev. 84, 71 (2011)","journal-title":"Temp. L. Rev."},{"key":"3_CR20","unstructured":"Litmannavarro, K.: We read 150 privacy policies. They were an incomprehensible disaster (2006). https:\/\/www.nytimes.com\/interactive\/2019\/06\/12\/opinion\/facebook-google-privacy-policies.html. Accessed June 2019"},{"key":"3_CR21","doi-asserted-by":"crossref","unstructured":"Massey, A.K., Eisenstein, J., Anton, A.I., Swire, P.P.: Automated text mining for requirements analysis of policy documents. In: 2013 21st IEEE International Requirements Engineering Conference (2013)","DOI":"10.1109\/RE.2013.6636700"},{"key":"3_CR22","first-page":"543","volume":"4","author":"AM McDonald","year":"2008","unstructured":"McDonald, A.M., Cranor, L.F.: The cost of reading privacy policies. Isjlp 4, 543 (2008)","journal-title":"Isjlp"},{"key":"3_CR23","first-page":"639","volume":"12","author":"G Mclaughlin","year":"1969","unstructured":"Mclaughlin, G.: Smog grading - a new readability formula. J. Read. 12, 639\u2013646 (1969)","journal-title":"J. Read."},{"key":"3_CR24","unstructured":"Michaels, A., George, K.: Use & abuse of personal information. Blackhat, USA (2021)"},{"issue":"2","key":"3_CR25","doi-asserted-by":"publisher","first-page":"238","DOI":"10.1509\/jppm.25.2.238","volume":"25","author":"GR Milne","year":"2006","unstructured":"Milne, G.R., Culnan, M.J., Greene, H.: A longitudinal assessment of online privacy notice readability. J. Public Policy Mark. 25(2), 238\u2013249 (2006)","journal-title":"J. Public Policy Mark."},{"issue":"1","key":"3_CR26","doi-asserted-by":"publisher","first-page":"128","DOI":"10.1080\/1369118X.2018.1486870","volume":"23","author":"JA Obar","year":"2020","unstructured":"Obar, J.A., Oeldorf-Hirsch, A.: The biggest lie on the internet: ignoring the privacy policies and terms of service policies of social networking services. Inf. Commun. Soc. 23(1), 128\u2013147 (2020)","journal-title":"Inf. Commun. Soc."},{"key":"3_CR27","unstructured":"OF\u0301laherty, K.: Facebook data breach: here\u2019s what to do now (2021)"},{"issue":"2","key":"3_CR28","doi-asserted-by":"publisher","first-page":"185","DOI":"10.3233\/SW-170283","volume":"9","author":"A Oltramari","year":"2018","unstructured":"Oltramari, A., et al.: PrivOnto: a semantic framework for the analysis of privacy policies. Semant. Web 9(2), 185\u2013203 (2018)","journal-title":"Semant. Web"},{"issue":"9","key":"3_CR29","doi-asserted-by":"publisher","first-page":"103","DOI":"10.1145\/1284621.1284627","volume":"50","author":"I Pollach","year":"2007","unstructured":"Pollach, I.: What\u2019s wrong with online privacy policies? Commun. ACM 50(9), 103\u2013108 (2007)","journal-title":"Commun. ACM"},{"key":"3_CR30","doi-asserted-by":"publisher","first-page":"307","DOI":"10.1080\/10447310801937999","volume":"24","author":"R Proctor","year":"2008","unstructured":"Proctor, R., Ali, A., Vu, K.P.: Examining usability of web privacy policies. Int. J. Hum. Comput. Interact. 24, 307\u2013328 (2008). https:\/\/doi.org\/10.1080\/10447310801937999","journal-title":"Int. J. Hum. Comput. Interact."},{"key":"3_CR31","unstructured":"Reddit: Reddit user agreement (2021). https:\/\/www.redditinc.com\/policies\/user-agreement"},{"key":"3_CR32","unstructured":"Sathyendra, K., et al.: Identifying the provision of choices in privacy policy text. In: Proceedings of the 2017 Conference on Empirical Methods in NLP (2017)"},{"key":"3_CR33","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"225","DOI":"10.1007\/978-3-030-00305-0_17","volume-title":"Data Privacy Management, Cryptocurrencies and Blockchain Technology","author":"I Wagner","year":"2018","unstructured":"Wagner, I., Boiten, E.: Privacy risk assessment: from art to science, by metrics. In: Garcia-Alfaro, J., Herrera-Joancomart\u00ed, J., Livraga, G., Rios, R. (eds.) DPM\/CBT -2018. LNCS, vol. 11025, pp. 225\u2013241. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-030-00305-0_17"},{"issue":"3","key":"3_CR34","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3168389","volume":"51","author":"I Wagner","year":"2018","unstructured":"Wagner, I., Eckhoff, D.: Technical privacy metrics. ACM Comput. Surv. 51(3), 1\u201338 (2018). https:\/\/doi.org\/10.1145\/3168389","journal-title":"ACM Comput. Surv."},{"key":"3_CR35","doi-asserted-by":"crossref","unstructured":"Wilson, S. et al.: The creation and analysis of a website privacy policy corpus. In: Proceedings of the 54th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers), pp. 1330\u20131340 (2016)","DOI":"10.18653\/v1\/P16-1126"},{"key":"3_CR36","unstructured":"Winder, D.: Microsoft security shocker as 250 million customer records exposed online (2020)"},{"issue":"3","key":"3_CR37","first-page":"66","volume":"2019","author":"S Zimmeck","year":"2019","unstructured":"Zimmeck, S., et al.: MAPS: scaling privacy compliance analysis to a million apps. Proc. Priv. Enhanc. Technol. 2019(3), 66\u201386 (2019)","journal-title":"Proc. Priv. Enhanc. Technol."}],"container-title":["Lecture Notes in Computer Science","Data Privacy Management, Cryptocurrencies and Blockchain Technology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-93944-1_3","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,4,28]],"date-time":"2022-04-28T21:22:44Z","timestamp":1651180964000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-93944-1_3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"ISBN":["9783030939434","9783030939441"],"references-count":37,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-93944-1_3","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2022]]},"assertion":[{"value":"23 January 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"DPM","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Workshop on Data Privacy Management","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Darmstadt","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Germany","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2021","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"8 October 2021","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"8 October 2021","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"dpm2021","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/deic-web.uab.cat\/conferences\/dpm\/dpm2021\/main.html","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"26","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"7","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"27% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"The conference took place virtually due to the COVID-19 pandemic.","order":10,"name":"additional_info_on_review_process","label":"Additional Info on Review Process","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}