Cargando…

Privacy Policies of IoT Devices: Collection and Analysis

Currently, personal data collection and processing are widely used while providing digital services within mobile sensing networks for their operation, personalization, and improvement. Personal data are any data that identifiably describe a person. Legislative and regulatory documents adopted in re...

Descripción completa

Detalles Bibliográficos
Autores principales: Kuznetsov, Mikhail, Novikova, Evgenia, Kotenko, Igor, Doynikova, Elena
Formato: Online Artículo Texto
Lenguaje:English
Publicado: MDPI 2022
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC8914639/
https://www.ncbi.nlm.nih.gov/pubmed/35270993
http://dx.doi.org/10.3390/s22051838
_version_ 1784667767844110336
author Kuznetsov, Mikhail
Novikova, Evgenia
Kotenko, Igor
Doynikova, Elena
author_facet Kuznetsov, Mikhail
Novikova, Evgenia
Kotenko, Igor
Doynikova, Elena
author_sort Kuznetsov, Mikhail
collection PubMed
description Currently, personal data collection and processing are widely used while providing digital services within mobile sensing networks for their operation, personalization, and improvement. Personal data are any data that identifiably describe a person. Legislative and regulatory documents adopted in recent years define the key requirements for the processing of personal data. They are based on the principles of lawfulness, fairness, and transparency of personal data processing. Privacy policies are the only legitimate way to provide information on how the personal data of service and device users is collected, processed, and stored. Therefore, the problem of making privacy policies clear and transparent is extremely important as its solution would allow end users to comprehend the risks associated with personal data processing. Currently, a number of approaches for analyzing privacy policies written in natural language have been proposed. Most of them require a large training dataset of privacy policies. In the paper, we examine the existing corpora of privacy policies available for training, discuss their features and conclude on the need for a new dataset of privacy policies for devices and services of the Internet of Things as a part of mobile sensing networks. The authors develop a new technique for collecting and cleaning such privacy policies. The proposed technique differs from existing ones by the usage of e-commerce platforms as a starting point for document search and enables more targeted collection of the URLs to the IoT device manufacturers’ privacy policies. The software tool implementing this technique was used to collect a new corpus of documents in English containing 592 unique privacy policies. The collected corpus contains mainly privacy policies that are developed for the Internet of Things and reflect the latest legislative requirements. The paper also presents the results of the statistical and semantic analysis of the collected privacy policies. These results could be further used by the researchers when elaborating techniques for analysis of the privacy policies written in natural language targeted to enhance their transparency for the end user.
format Online
Article
Text
id pubmed-8914639
institution National Center for Biotechnology Information
language English
publishDate 2022
publisher MDPI
record_format MEDLINE/PubMed
spelling pubmed-89146392022-03-12 Privacy Policies of IoT Devices: Collection and Analysis Kuznetsov, Mikhail Novikova, Evgenia Kotenko, Igor Doynikova, Elena Sensors (Basel) Article Currently, personal data collection and processing are widely used while providing digital services within mobile sensing networks for their operation, personalization, and improvement. Personal data are any data that identifiably describe a person. Legislative and regulatory documents adopted in recent years define the key requirements for the processing of personal data. They are based on the principles of lawfulness, fairness, and transparency of personal data processing. Privacy policies are the only legitimate way to provide information on how the personal data of service and device users is collected, processed, and stored. Therefore, the problem of making privacy policies clear and transparent is extremely important as its solution would allow end users to comprehend the risks associated with personal data processing. Currently, a number of approaches for analyzing privacy policies written in natural language have been proposed. Most of them require a large training dataset of privacy policies. In the paper, we examine the existing corpora of privacy policies available for training, discuss their features and conclude on the need for a new dataset of privacy policies for devices and services of the Internet of Things as a part of mobile sensing networks. The authors develop a new technique for collecting and cleaning such privacy policies. The proposed technique differs from existing ones by the usage of e-commerce platforms as a starting point for document search and enables more targeted collection of the URLs to the IoT device manufacturers’ privacy policies. The software tool implementing this technique was used to collect a new corpus of documents in English containing 592 unique privacy policies. The collected corpus contains mainly privacy policies that are developed for the Internet of Things and reflect the latest legislative requirements. The paper also presents the results of the statistical and semantic analysis of the collected privacy policies. These results could be further used by the researchers when elaborating techniques for analysis of the privacy policies written in natural language targeted to enhance their transparency for the end user. MDPI 2022-02-25 /pmc/articles/PMC8914639/ /pubmed/35270993 http://dx.doi.org/10.3390/s22051838 Text en © 2022 by the authors. https://creativecommons.org/licenses/by/4.0/Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/).
spellingShingle Article
Kuznetsov, Mikhail
Novikova, Evgenia
Kotenko, Igor
Doynikova, Elena
Privacy Policies of IoT Devices: Collection and Analysis
title Privacy Policies of IoT Devices: Collection and Analysis
title_full Privacy Policies of IoT Devices: Collection and Analysis
title_fullStr Privacy Policies of IoT Devices: Collection and Analysis
title_full_unstemmed Privacy Policies of IoT Devices: Collection and Analysis
title_short Privacy Policies of IoT Devices: Collection and Analysis
title_sort privacy policies of iot devices: collection and analysis
topic Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC8914639/
https://www.ncbi.nlm.nih.gov/pubmed/35270993
http://dx.doi.org/10.3390/s22051838
work_keys_str_mv AT kuznetsovmikhail privacypoliciesofiotdevicescollectionandanalysis
AT novikovaevgenia privacypoliciesofiotdevicescollectionandanalysis
AT kotenkoigor privacypoliciesofiotdevicescollectionandanalysis
AT doynikovaelena privacypoliciesofiotdevicescollectionandanalysis