The Clash of Service Provider and Service User Expectations
摘要
Data Protection regulation seeks to support data subjects to control their personal data. A lack of such control poses a significant risk to their privacy and may undermine the data subject’s trust in the provider. To achieve this, it imposes certain obligations on those providing services to data subjects which requires the processing of their personal data. Compliance with regulation, including security standards, would demonstrate provider trustworthiness, it is assumed. In so doing, this would encourage users to engage. But how are those users supposed to know the provider is compliant? Further, how will the provider manage their data? The assumption is that a provider’s privacy notice is a suitable communication vehicle for this purpose. In this study, we challenge this view. Using causal models to visualise both service provider and service user decision making around interaction, we maintain there to be a mismatch between the expectations of the two: a tussle which cannot be resolved through regulatory compliance, but a better understanding of service user privacy attitudes.