A ‘Human-in-the-Loop’ approach for Information Extraction from Privacy Policies under Data Scarcity

Michael Gebauer, Faraz Maschhur, Nicola Leschke, Elias Grünewald, Frank Pallas

Publikation: Beitrag in Buch/Bericht/Konferenzband/GesetzeskommentarKonferenzbeitragPeer-reviewed

Abstract

Machine-readable representations of privacy policies are door openers for a broad variety of novel privacy-enhancing and, in particular, transparency-enhancing technologies (TETs). In order to generate such representations, transparency information needs to be extracted from written privacy policies. However, respective manual annotation and extraction processes are laborious and require expert knowledge. Approaches for fully automated annotation, in turn, have so far not succeeded due to overly high error rates in the specific domain of privacy policies. In the end, a lack of properly annotated privacy policies and respective machine-readable representations persists and enduringly hinders the development and establishment of novel technical approaches fostering policy perception and data subject informedness.In this work, we present a prototype system for a ‘ Human-in-the-Loop’ approach to privacy policy annotation that integrates ML-generated suggestions and ultimately human annotation decisions. We propose an ML-based suggestion system specifically tailored to the constraint of data scarcity prevalent in the domain of privacy policy annotation. On this basis, we provide meaningful predictions to users thereby streamlining the annotation process. Additionally, we also evaluate our approach through a prototypical implementation to show that our ML-based extraction approach provides superior performance over other recently used extraction models for legal documents.
OriginalspracheDeutsch
Titel2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)
Herausgeber (Verlag)IEEE
Seiten76-83
Seitenumfang8
ISBN (Print)979-8-3503-2721-2
DOIs
PublikationsstatusVeröffentlicht - 7 Juli 2023
Veranstaltung2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW) - Delft, Netherlands
Dauer: 3 Juli 20237 Juli 2023

Konferenz

Konferenz2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)
Zeitraum3/07/237/07/23

Schlagwörter

  • Privacy
  • Data privacy
  • Annotations
  • Law

Systematik der Wissenschaftszweige 2012

  • 102 Informatik
  • 505 Rechtswissenschaften

Dieses zitieren