Mind the Gap: Measuring the Disconnect Between Privacy Policies and OSN Controls
A Method for Analysing Traceability between Privacy Policies and Privacy Controls of Online Social Networks
The paper introduces a systematic method to analyze the traceability between natural language privacy policies and the runtime privacy controls of Online Social Networks (OSNs). By utilizing a custom privacy taxonomy and a 3-point qualitative scale, the authors evaluate how accurately OSN settings implement their stated policy promises, revealing significant gaps in SOTA platforms like Google+.
TL;DR
Despite the legal jargon in privacy policies, do the "Privacy Settings" buttons actually do what they say? This paper presents a formal traceability method to find out. By mapping policy statements to runtime controls across Google+ and other OSNs, the authors found that a staggering majority of privacy promises are either ambiguous (Partial) or entirely missing from the UI (Broken).
The "Illusion of Control" in Social Networks
We have all seen it: a 20-page privacy policy that promises "Your data is handled with care," followed by a confusing settings menu with 60+ toggles. The authors argue that this creates a fundamental Traceability Problem. Research shows users find controls difficult to configure, and regulators are increasingly skeptical of whether OSN functionality aligns with legal mandates. The core issue is that policy text is written by lawyers (high abstraction), while controls are built by developers (low-level operations), leaving a massive gap in the middle.
Methodology: The Traceability Framework
The researchers developed a method that treats privacy as a software engineering requirement that must be traced to its implementation.
1. The Action Taxonomy
To solve the "vocabulary gap," they created a taxonomy that classifies policy statements based on Actions (e.g., Collection, Storage, Transfer). This provides a standardized language to compare different OSNs.

2. The Dual-Stream Mapping
The method operates in two parallel tracks:
- The Policy Stream: Decomposing text into categorized statements and identifying the Data (what info?) and Visibility (who sees it?).
- The Control Stream: Auditing the actual site via test accounts (Adult/Minor) to see what settings actually exist.
By matching Terminology, Data items, and Default Visibility, they determine if a "Trace" exists between a promise and a toggle.

Experimental Findings: A Privacy Failure
The authors put Google+, Meet Me, and Zorpia to the test. The results highlight a systemic failure in the OSN industry:
- Google+: While elaborate, 42.9% of its mappings were "Partial." The use of "catch-all" terms like "other profile information" means users never truly know what data is being "combined" across services.
- The "Broken" Reality: In Meet Me and Zorpia, over 60% of policy statements were Broken—meaning the policy discussed data protections or choices that simply did not exist in the user settings.

Critical Insights: Why Is This Happening?
The authors identify three industry-wide deficiencies:
- Information Asymmetry: Terms are intentionally vague to give OSNs legal "wiggle room."
- Default Opt-Ins: OSNs prioritize data velocity over user privacy by defaulting everything to "On" and burying "Off" switches.
- Third-Party Integration: The "trace" often breaks entirely when data moves to third-party apps, where OSNs claim they "are not responsible" for what happens next.
Conclusion and Future Outlook
This work moves privacy audits from subjective opinions to objective measurements. By assigning a "Traceability Degree," we can finally hold OSNs accountable. The authors' future vision includes automated CASE tools that can flag a policy as "untraceable" the moment a developer changes a line of code in the settings menu. Until then, the burden remains on the user to navigate a "privacy jungle" where the map (Policy) rarely matches the terrain (Controls).
