|
ABSTRACT
As electronic commerce environments become more and more interactive, privacy is a matter of increasing concern. Many surveys have investigated households' privacy attitudes and concerns, revealing a general desire among Internet users to protect their privacy. To complement these questionnaire-based studies, we conducted an experiment in which we compared self-reported privacy preferences of 171 participants with their actual disclosing behavior during an online shopping episode. Our results suggest that current approaches to protect online users' privacy, such as EU data protection regulation or P3P, may face difficulties to do so effectively. This is due to their underlying assumption that people are not only privacy conscious, but will also act accordingly. In our study, most individuals stated that privacy was important to them, with concern centering on the disclosure of different aspects of personal information. However, regardless of their specific privacy concerns, most participants did not live up to their self-reported privacy preferences. As participants were drawn into the sales dialogue with an anthropomorphic 3-D shopping bot, they answered a majority of questions, even if these were highly personal. Moreover, different privacy statements had no effect on the amount of information disclosed; in fact, the mentioning of EU regulation seemed to cause a feeling of 'false security'. The results suggest that people appreciate highly communicative EC environments and forget privacy concerns once they are 'inside the Web'.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
 |
1
|
Mark S. Ackerman , Lorrie Faith Cranor , Joseph Reagle, Privacy in e-commerce: examining user scenarios and privacy preferences, Proceedings of the 1st ACM conference on Electronic commerce, p.1-8, November 03-05, 1999, Denver, Colorado, United States
[doi> 10.1145/336992.336995]
|
| |
2
|
Annacker, D., Spiekermann, S., Strobel, M., "E-privacy: A new search cost dimension in online environments", 14th Bled Conference of Electronic Commerce, June 2001, download: http://www.wiwi.hu-berlin. de/~sspiek/phdresearch.html
|
| |
3
|
Ansari A., Essegaier, S., Kohli, R., "Internet Recommender Systems", in: Journal of Marketing Research", Vol. 37, August 2000, pp. 363-375.
|
| |
4
|
Berendt, B. (2000). "Web usage mining, site semantics, and the support of navigation". In: Workshop 'Web Mining for E-Commerce Challenges and Opportunities." KDD 2000, August 2000. Boston, MA. pp. 83-93.
|
| |
5
|
B~umler, H., "Datenschutz im Internet", in: E-Privacy, ed. by Helmut B~umler, Wiesbaden, 2000, pp. 1-8
|
| |
6
|
|
| |
7
|
Borking, J., "Erwartungen an die Datenschutz-beauftragten im Internet", in: E-Privacy, ed. by Helmut B~umler, Wiesbaden, 2000, pp. 280-290.
|
| |
8
|
|
 |
9
|
|
| |
10
|
Chang, A., Kannan, P., Whinston, A., "The Economics of Freebies in Exchange for Consumer Information on the Internet: An Exploratory Study", in: Int. Journal of Electronic Commerce, Vol. 4, No. 1, Fall 1999, pp. 85-101.
|
| |
11
|
Clau~, S., K~hntopp, M., "Identity Management and Its Support of Multilateral Systems", accepted for publication in the Special Issue on 'Electronic Business Systems' of Computer Networks; until publication available directly from marit@koehntopp.de.
|
| |
12
|
Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data: http://europa.eu.int/comm/internal_market/en/media/dataprot /law/index.htm.
|
| |
13
|
Hagel, J., Rayport, J., "The Coming Battle for Customer Information", in: Harvard Business Review, January-February 1997, pp.53-65.
|
| |
14
|
H~uble, G., Trifts,V., "Consumer Decision Making in Online Shopping Environments: The Effects of Interactive Decision Aids", in: Marketing Science, April 2000.
|
| |
15
|
K~hntopp, M., "Wie war noch gleich Ihr Name? - Schritte zu einem umfassenden Identit~tsmanagement", accepted at the conference VIS - Verl~ssliche IT-Systeme, Kiel, Germany, September 2001.
|
| |
16
|
K~hntopp, M., Pfitzmann, A., "Datenschutz Next Generation"", in: E-Privacy, ed. by Helmut B~umler, Wiesbaden, 2000, pp. 316-322.
|
| |
17
|
Moon, Y.: The Interface Project: http://www.people.hbs.edu/ymoon/Interface/home.html
|
| |
18
|
Moon, Y., Intimate Exchanges: Using Computers to Elicit Self-Disclosure from Consumers, in: Journal of Consumer Research, Vol.27, No.4, March 2000.
|
| |
19
|
Pew Internet & American Life Project, Trust and Privacy Online: Why Americans Want to Rewrite the Rules, 2000-8- 20, http://pewinternet.org/reports/toc.asp?Report=19.
|
| |
20
|
Andreas Pfitzmann , Marit Köhntopp, Anonymity, unobservability, and pseudeonymity — a proposal for terminology, International workshop on Designing privacy enhancing technologies: design issues in anonymity and unobservability, p.1-9, January 2001, Berkeley, California, United States
|
| |
21
|
Schaar, P., "Die Moglichkeiten der Datenschutzaufsichtsbeh~rden", in: E-Privacy, ed. by Helmut B~ umler, Wiesbaden, 2000, pp. 69-76.
|
 |
22
|
J. Ben Schafer , Joseph Konstan , John Riedi, Recommender systems in e-commerce, Proceedings of the 1st ACM conference on Electronic commerce, p.158-166, November 03-05, 1999, Denver, Colorado, United States
[doi> 10.1145/336992.337035]
|
| |
23
|
Spiekermann, S., Corina, P., "Motivating Human-Agent Interaction : Transferring Insights from Behavioral Marketing to Agent Design", in: Proc. of the 3 rd International Conference on Telecommunications and Electronic Commerce, ICTEC3, 2000, pp. 387-402.
|
 |
24
|
|
| |
25
|
Urban, G., F. Sultan and W. Qualls, "Design and Evaluation of a Trust Based Advisor on the Internet", MIT, December 1999.
|
 |
26
|
|
| |
27
|
West P., D.Ariely, S.Bellman, E.Bradlow, J.Huber, E.Johnson, B.Kahn, J.Little and D.Schkade, "Agents to the Rescue?", HEC Invitational Choice Symposium, February 1999.
|
| |
28
|
Westin, A., "Harris-Equifax Consumer Privacy Survey", Atlanta, GA: Equifax Inc. (1996).
|
| |
29
|
Vulcan, N., "Economic Implications of Agent Technology and E-Commerce", in: The Economic Journal, February 1999, pp. 67-90.
|
CITED BY 42
|
|
|
|
|
Claus Boyens , Oliver Günther , Maximilian Teltzrow, Privacy conflicts in CRM services for online shops: a case study, Proceedings of the IEEE international conference on Privacy, security and data mining, p.27-35, December 01, 2002, Maebashi City, Japan
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Quentin Jones , Sukeshini A. Grandhi , Steve Whittaker , Keerti Chivakula , Loren Terveen, Putting systems into place: a qualitative study of design requirements for location-aware community systems, Proceedings of the 2004 ACM conference on Computer supported cooperative work, November 06-10, 2004, Chicago, Illinois, USA
|
|
|
|
|
|
Nathaniel Good , Rachna Dhamija , Jens Grossklags , David Thaw , Steven Aronowitz , Deirdre Mulligan , Joseph Konstan, Stopping spyware at the gate: a user study of privacy, notice and spyware, Proceedings of the 2005 symposium on Usable privacy and security, p.43-52, July 06-08, 2005, Pittsburgh, Pennsylvania
|
|
|
|
|
|
Rogério de Paula , Xianghua Ding , Paul Dourish , Kari Nies , Ben Pillet , David F. Redmiles , Jie Ren , Jennifer A. Rode , Roberto Silva Filho, In the eye of the beholder: a visualization-based approach to information system security, International Journal of Human-Computer Studies, v.63 n.1-2, p.5-24, July 2005
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Julia Gideon , Lorrie Cranor , Serge Egelman , Alessandro Acquisti, Power strips, prophylactics, and privacy, oh my!, Proceedings of the second symposium on Usable privacy and security, July 12-14, 2006, Pittsburgh, Pennsylvania
|
|
|
Nathaniel S. Good , Jens Grossklags , Deirdre K. Mulligan , Joseph A. Konstan, Noticing notice: a large-scale experiment on the timing of software license agreements, Proceedings of the SIGCHI conference on Human factors in computing systems, April 28-May 03, 2007, San Jose, California, USA
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Jens Grossklags , Nicolas Christin , John Chuang, Predicted and observed user behavior in the weakest-link security game, Proceedings of the 1st Conference on Usability, Psychology, and Security, p.1-6, April 14-14, 2008, San Francisco, California
|
|
|
|
|
|
|
|
|
|
|
|
Ian K. Reay , Patricia Beatty , Scott Dick , James Miller, A Survey and Analysis of the P3P Protocol's Agents, Adoption, Maintenance, and Future, IEEE Transactions on Dependable and Secure Computing, v.4 n.2, p.151-164, April 2007
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|