Professor Shvartzshnaider gave a talk on "" titled: "Doing Away with Privacy Preferences: Towards Privacy Inserts" at at the annual Privacy Enhancing Technologies Symposium (PETS) in Calgary
Talk Abstract:
The predominant privacy-preserving policy approaches rely on users expressing their preferences and having control over their information. These mechanisms are part of the "informed consent" policy model, which assumes an average user is able to discern the complex network of information flows generated by vastly interconnected services. Countless studies have shown this to be false. The informed-consent model simply does not scale. Yet, as a community we still insist that users read privacy policies and understand the information handling practices in making an informed decision.
I would like to discuss an alternative approach that largely does away with asking users about their privacy preferences instead of ensuring services are designed to support established contextual privacy norms that align with contextual ends, values, and functions. This would put the onus on companies to provide the relevant, detailed information about their services for intermediate domain experts to detect any potential breaches. Users should have peace of mind knowing the service they use is liable to support the values and purposes of the social domain they are deployed in.
This approach would resemble the “learned intermediary rule” used in the highly regulated prescription pharmaceutical industry. The rule mandates the drug manufacturers to inform prescribing physicians about any potential risks and harms a drug may cause. To comply, the manufacturers include “package inserts” (PI) for each drug with detailed unbiased information about the risk and benefits associated with it. Medical professionals such as physicians and pharmacists, not patients act as "learned-intermediaries," that are tasked with interpreting the dangers of a particular drug for a given patient based on the information provided by pharmaceutical companies.
Following the pharmaceutical industry, we could introduce a learned intermediary rule for digital services. The rule would force each service provider to include a service privacy insert. A privacy insert would include an exhaustive list of information handling practices for a domain expert to investigate and determine the benefits and harms. The goal is to provide the necessary information for empirical analysis that researchers, lawyers, and policymakers need to perform privacy assessments using the framework of Contextual Integrity. This could include descriptions of information flows resulting from third-party integration, lists of supply-chain business associate services, and automatic AI-driven components along with scenarios of potential "side effects."
