Charting App Developers' Journey Through Privacy Regulation Features in Ad Networks

Mohammad Tahaei, Marvin Ramokapane, Tianshi Li, Jason I. Hong, Awais Rashid

    Research output: Chapter in Book/Report/Conference proceedingConference Contribution (Conference Proceeding)

    293 Downloads (Pure)

    Abstract

    Mobile apps enable ad networks to collect and track users. App developers are given “configurations” on these platforms to limit data collection and adhere to privacy regulations; however, the prevalence of apps that violate privacy regulations because of third parties, including ad networks, begs the question of how developers work through these configurations and how easy they are to utilize. We study privacy regulations-related interfaces on three widely used ad networks using two empirical studies, a systematic review and think-aloud sessions with eleven developers, to shed light on how ad networks present privacy regulations and how usable the provided configurations are for developers. We find that information about privacy regulations is scattered in several pages, buried under multiple layers, and uses terms and language developers do not understand. While ad networks put the burden of complying with the regulations on developers, our participants, on the other hand, see ad networks responsible for ensuring compliance with regulations. To assist developers in building privacy regulations-compliant apps, we suggest dedicating a section to privacy, offering easily accessible configurations (both in graphical and code level), building testing systems for privacy regulations, and creating multimedia materials such as videos to promote privacy values in the ad networks’ documentation.

    We find that information about privacy regulations is scattered in several pages, buried under multiple layers, and uses terms and language developers do not understand. While ad networks put the burden of complying with the regulations on developers, our participants, on the other hand, see ad networks responsible for ensuring compliance with regulations. To assist developers in building privacy regulations-compliant apps, we suggest dedicating a section to privacy, offering easily accessible configurations (both in graphical and code level), building testing systems for privacy regulations, and creating multimedia materials such as videos to promote privacy values in the ad networks' documentation.
    Original languageEnglish
    Title of host publicationProceedings on privacy enhancing technologies symposium
    PublisherDe Gruyter Open Ltd.
    Pages33–56
    Number of pages24
    DOIs
    Publication statusPublished - 15 Jul 2022
    EventThe 22nd Privacy Enhancing Technologies Symposium - Sydney, Australia
    Duration: 11 Jul 202215 Jul 2022

    Publication series

    NameProceedings on Privacy Enhancing Technologies
    PublisherDe Gruyter Open
    Number3
    Volume2022
    ISSN (Electronic)2299-0984

    Conference

    ConferenceThe 22nd Privacy Enhancing Technologies Symposium
    Country/TerritoryAustralia
    CitySydney
    Period11/07/2215/07/22

    Keywords

    • usable privacy
    • software developers
    • ad networks
    • privacy regulations
    • CCPA
    • COPPA
    • GDPR

    Fingerprint

    Dive into the research topics of 'Charting App Developers' Journey Through Privacy Regulation Features in Ad Networks'. Together they form a unique fingerprint.

    Cite this