Privacy protection of China’s top websites: A Multi-layer privacy measurement via network behaviours and privacy policies
Xinjie Lin,Han Liu,Zhen Li,Gang Xiong,Gaopeng Gou
DOI: https://doi.org/10.1016/j.cose.2022.102606
2022-03-01
Abstract:In the booming development of China’s digital economy, the privacy and security issues of personal data in website applications are vital important. Websites need to implement basic personal information protection measures according to China’s existing statutory requirements for privacy protection, such as disclosing personal information protection policies. However, there still is possibility to leak personal information although the sites adopt the self-regulation way. In this study, we first propose the measurement study of popular websites in China combining strategy analysis and web verification, in hope of providing countermeasures for the development of the personal information protection legal system in China. The study is achieved by analysing a collection of 199,060 network behaviours from 663 websites spanning half a year, studying the consistency between behaviour and policy in websites and conducting a systematic analysis of the privacy policies disclosed on all websites. The findings are multi-fold, 67.6% of popular websites in China have publicly disclosed their privacy policies and all compliance requirements have reached more than 60%, while less than 5% of websites have clearly disclosed and strictly followed the policy statement on third-party sharing and cookie retention. Overall, we conclude that the website has a moderate level of transparency under the existing legal conditions, but there is still a lack of functional and usable mechanisms and regulations for users to consent to or deny processing of their personal data on the Internet. To this end, we analyse the measurement results and put forward appropriate recommendations for the website owners, legal institutions and regulatory authorities.
computer science, information systems