Hindustan Times (Ranchi)

Notice, consent, privacy: Why we need to do better

Users can barely access, or comprehend, privacy policies. Consent has to be made more meaningful

- SMRITI PARSHEERA Smriti Parsheera is a fellow at the National Institute of Public Finance and Policy. This is based on a NIPFP Working Paper titled ‘Disclosure­s in privacy policies: Does ‘notice and consent’ work?’ The views expressed are personal

EVEN IF A ‘MODEL CONSUMER’ WERE TO ABSORB EVERY TERM, IT WOULD NOT CHANGE THE FACT THAT THE USER STILL LACKS ANY REAL BARGAINING POWER VIS-ÀVIS THE PROVIDER. THE OPTIONS ARE TO EITHER ACCEPT THE TERMS OR NOT USE THE SERVICE

Most people do not read privacy policies. Those who have tried would testify that these documents can be pretty hard to understand. Running into several pages that are filled with legal jargon and unexplaine­d phrases, the main purpose seems to be to protect the company from legal liability rather than genuinely informing the consumer. We discuss this in a recent paper co-authored with Rishab Bailey, Faiza Rahman and Renuka Sane at the National Institute of Public Finance and Policy.

We conducted a quiz to test how well urban, English-speaking, college students understand the policies of five popular tech companies — Flipkart, Google, Paytm, Uber and WhatsApp. The short answer? Not very well. The students scored an average of 5.3 out of 10, faring the worst in areas where the policy terms were unclear or required the reader to make their own inferences.

The right to informatio­nal privacy implies that, at the very least, every individual should be able to determine who can use her personal informatio­n and for what purpose. Moreover, these interactio­ns must take place in an ecosystem that recognises the power and informatio­n asymmetry between the parties, and has sufficient safeguards to protect the individual’s interests.

One way in which most data protection frameworks, including the one currently under considerat­ion in India, try to achieve this is by resorting to the “notice and consent” regime. This framework regards individual­s as pragmatic actors, who are capable of weighing the pros and cons of the options available to them and pursuing their best interests. Entities that seek to collect and use personal data are therefore tasked with the duty to provide adequate and meaningful “notice” to users. Armed with this informatio­n, users can then choose to grant their “informed consent”, which becomes the basis for processing of their data.

Each time a person clicks the “I agree” button, she has presumably conducted a reasoned trade-off between her desired level of privacy and the value being derived from the service in question. This would assume that each Uber user understand­s that the policy is worded broadly enough to allow the

company to track her location at all times. Similarly, all Gmail users are comfortabl­e with their emails being scanned for producing targeted advertisem­ents.

In reality, however, a user’s interactio­n with privacy policies faces many stumbling blocks. The first, and most basic, is the barrier of accessibil­ity. Almost none of the privacy policies are available in languages other than English. Of the companies we studied, only Google provided its privacy policy in multiple Indian languages. This is clearly not optimum in a country where only a fraction of the population is able to read and understand English.

Second, the constructi­on of sentences and phrases in most policies is of a level that requires advanced comprehens­ion skills. Using the Flesch-Kincaid readabilit­y score, we found that all of the selected policies had scores ranging from 16 to 41, which correspond with graduate-level reading skills. To put this in perspectiv­e, only about 8.2% of India’s above 15 population has an education level of graduate and above.

The third concern arises from the sheer volume of the transactio­ns that take place in the digital economy and the big data analytics emerging from that. As per App Annie’s State of the Mobile Report, an average Indian smartphone user has about 70 apps on her phone. Spending even half an hour reading each policy would translate to about 35 hours of reading time. Add to this all the other daily interactio­ns involving the processing of one’s personal data, and the impractica­lity of expecting a user to go through all the policies becomes evident.

Finally, even if a “model consumer” were to read and absorb every term, it would not change the fact that the user still lacks any real bargaining power vis-à-vis the provider. In markets with a handful of dominant players, the only options are to either accept the terms set out by the provider or not use the service at all.

The culminatio­n of these factors has led many to argue that “consent” can no longer serve as a legitimate basis for the processing of personal data. Yet, for many others, the idea of consent is so deeply rooted in individual autonomy and liberty that doing away with it would require a fundamenta­l rethink of how we understand the right to privacy. The middle-path perhaps lies in building a robust set of data protection principles and accountabi­lity mechanisms, which would apply irrespecti­ve of whether the user’s consent has been obtained. To some extent, the draft Personal Data Protection Bill also tries to achieve this, even though it retains a central role for consent.

At the same time, we need privacy policies to be better drafted and designed, keeping in mind the differenti­al needs of different categories of Indian users.

Consent in the digital world will never be perfect but we cannot stop trying to make it as meaningful as possible.

 ??  ??

Newspapers in English

Newspapers from India