Feb 1, 2022 | Privacy & Security

Privacy and Currency: Give a little, take a little.

Maria Arango Kure

On this fourth post of the series I discuss the issues data collection presents in terms of user privacy, consent, and surveillance. Highlighting the main concerns of web users, governments, and advocacy groups regarding these practices, along with existing regulations, such as the European GDPR and the California privacy law.

The consequence of the data economy, with its growing need for personal data for profit, is a significant loss of personal information privacy, defined as the rights of individuals to control the circulation of information related to them (Slattery & Krawitz, 2014). Informational privacy has long been recognized as a fundamental human right, with personally identifiable information as the legal threshold condition for the loss of anonymity or privacy (Schwartz & Solove, 2011).

The primary trade-off for the user is relinquishing control over their personal information, in exchange for access to information, services, efficiency and a personalization of experiences. The information is then used by website owners as a means to generate revenue from advertisement as a way to offset the costs of providing this access (Evans, 2009).

Advertisers and website owners justify this exchange by emphasizing the benefits to the end user of giving up this data, such as relevant advertisement rather than randomized content of little interest. In the words of Evans (2009), given that a website is going to display an advertisement, consumers might prefer that the advertisement be more relevant than not.

At first glance, the exchange might not seem very different to the one seen on traditional radio or television advertisement. However, digital media has radically changed the flows of personal information (Nissenbaum, 2011) with mediated disruptions of an unprecedented scale and variety.

The mechanisms of data collection, as explained on part two of this paper, paired with the increasing value of this data and the lack of understanding on the part of consumers of the intricacies of which information exactly they are disclosing about themselves, raises serious concerns about the fairness and legally and ethics behind these data collection practices (Warner & Sloan, 2012).

Current data collection technologies have been recent source of concern by policymakers, public-interest advocates, and the media who have raised awareness of the pervasive, manipulative and surreptitious data collection practices of the current media landscape and their consequences on individuals and society as a whole (Nissenbaum, 2011), such as with the widely publicized case of Facebook and Cambridge Analytica.

Due in part to these alarms being raised in the eye of public opinion, data collection and behavioral advertisement have attracted lawsuits and legislative inquiries (Evans, 2009) escalating to the passing of legislation such as the GDPR in Europe (Strycharz et al., 2021), state legislation in the USA and Australian legislation (Slattery & Krawitz, 2014).

Unfortunately, as it was made plainly visible by the recent congressional hearings where social media owners were questioned about their online practices and closely scrutinized, the rapid advances in data processing technologies, paired with the slow pace of the legislative process and the lack of technological understanding by policymakers, has rendered current legislation inadequate to handle the rapid pace of the industry.

While the existence of legislation such as GDPR has been seen as a move towards establishing the user as the default owner of their personal data, confusion about implementation and scope (Degeling et al., 2019), and the inevitable loopholes have allowed for websites to be apparently compliant with current regulation while, in reality, deceiving and manipulating users into parting with their personal data.

The literature in the field of online privacy and security has identified a growing concern amongst internet users about their privacy, personal data and how it is used in the data market. A strong desire for control over personal data is identified, but also a lack of action to secure this control, named the privacy paradox by Barth and de Jong (2017), which responds to failures in risk benefit analysis aided by common cognitive biases and heuristic.


Note: The content of this blog post was written as part of the process of writing my thesis’ theoretical background, as a way to organize my ideas and clean them up in writing. The posts were temporarily taken down to prioritize the academic work’s originality, and have been reinstated after the publication of the thesis in the Swedish registry.