The Facebook Privacy Gap: Why Users Are Safer Than They Think
9606_Claimed vs observed information disclosure on social networking sites.
This study investigates the "Privacy Paradox" on Facebook by comparing claimed information disclosure (via questionnaires) against observed public profile data. The research categorizes personal data into identifiable, sensitive, and stigmatizing information to measure the discrepancy between user intent and actual behavior.
TL;DR
Contrary to the popular belief that social media users are increasingly transparent and reckless with their data, this study reveals a surprising trend: users actually disclose significantly less information on their public profiles than they claim to in surveys. By comparing self-reported data against real-world observations, the researchers found massive discrepancies in sensitive areas like birthdays and email addresses, suggesting a "Reverse Privacy Paradox."
The Evolution of the Privacy Paradox
For years, the "Privacy Paradox" has been a staple of digital sociology: the idea that people say they care about privacy but do nothing to protect it. However, most studies rely on "Privacy Concern" vs. "General Behavior."
This study narrows the lens, looking specifically at Claimed Disclosure vs. Observed Disclosure. It asks: If a user says they share their hometown, is it actually visible to the public? The motivation stems from the need to understand if users are becoming more adept at using privacy settings or if they simply lose track of what they've "checked" in their profile settings.
Methodology: The Three Pillars of Data
The researchers categorized Facebook profile components into three threat levels:
- Personal Identifiable Information (PII): Hometown, Gender, Birthday, Email.
- Sensitive Personal Information: Employer, Education, Friends List, Mobile Number.
- Potentially Stigmatizing Information: Religious/Political views, Interests, Dating preferences.
By combining a questionnaire with direct profile audits, they were able to quantify the "Gap" for 29 distinct variables.

Key Findings: The Secure User
The most striking takeaway is the magnitude of the gap in the "Individual PII" category.
- The Birthday Gap: 90% of participants claimed they share their birthday, but only 19% had it visible to the public.
- The Contact Gap: 74% claimed to share an email address, yet only 5% actually did. 60% claimed to share a mobile number, while only 7% were observed doing so.
The only category where "Observed" disclosure exceeded "Claimed" disclosure was the Friends List (-16% gap), suggesting that users may not realize their friends list is public by default or they underestimate its visibility.

Analysis: Why the Discrepancy?
Why do users claim to be more "open" than they actually are? The authors suggest several technical and psychological drivers:
- Platform Defaults: Facebook’s privacy settings may have become more granular since the users last updated their profiles.
- Recall Bias: Users might remember social interactions (sharing a birthday in a post) rather than the static profile setting (the birthday field).
- Security Literacy: The results indicate an "Inductive Bias" toward protection; as users become more aware of identity theft, they naturally withdraw PII from public view, even if they don't consciously update their survey-style self-perception.
Conclusion & Future Outlook
This study provides a refreshing counter-narrative to the "death of privacy." It demonstrates that when it comes to hard data (PII), users are acting with a level of caution that exceeds their own self-description.
Takeaway for Researchers: Self-reported data in privacy studies is highly unreliable. To get the truth, we must look at the "Observed Disclosure."
Limitations: The study’s sample size (N=100-131) is relatively small and focused on a specific demographic. Future research should explore if these "secure gaps" persist across different age groups (e.g., Gen Z vs. Boomers) and across platforms with different privacy architectures like LinkedIn or X (formerly Twitter).
