Privacy Settings in Social Networks: Empowering Tool or Deceptive Trap?
Privacy Settings in Social Networking Sites: Is It Fair?
This legal analysis evaluates the fairness of privacy settings in Social Networking Sites (SNS), specifically Facebook, under the EU Data Protection Directive (95/46/EC). It examines how technical complexity and "disclosure by design" default settings undermine user autonomy and transparency.
TL;DR
This paper explores the legal tension between complex SNS privacy settings and the Fairness Principle of EU data protection law. Using Facebook’s 2010 policy changes as a case study, the authors argue that "granular" settings often serve as a smokescreen for "disclosure by design," pushing users toward public exposure. They suggest that Consumer Protection Law might be a more effective weapon than traditional data protection guidelines to enforce digital fairness.
Problem & Motivation: The Illusion of Control
In the offline world, we naturally segregate our social roles—we are different people to our bosses than we are to our friends. SNS platforms promised to replicate this through "privacy settings." However, the authors identify a critical failure:
- Context Collapse: Information intended for one audience (friends) frequently spills over to others (employers/insurers), often with devastating real-world consequences.
- Complexity as an Obstacle: The tools provided are so granular and "mysterious" that most users never touch them, remaining stuck with whatever "public" defaults the provider recommends.
The authors ask a fundamental question: Is it fair for a platform to provide powerful tools that are practically unusable for the average person?
Methodology: The Three Pillars of Fairness
The analysis measures Facebook's architecture against the Fairness Principle (Article 6.1.a of the DPD), which the authors break down into three dimensions:
- Transparency: Data subjects must be able to understand the processing. Facebook’s privacy policy, famously longer than the US Constitution, fails this test.
- Lack of Pressure: Users should not be "tricked" or pressured into supplying data. The "Instant Personalization" feature, enabled by default, exemplifies this pressure.
- Reasonable Expectations: Controllers must respect what a user expects to happen. Changing defaults to "public" after a user has already joined the platform violates this "contextual integrity."
Note: The paper discusses the gap between user expectations of intimacy and the technical reality of data harvesting.
The "Dark Side" of Privacy Improvements
The authors analyze the specific 2010 updates where Facebook claimed to make settings "clearer" while simultaneously:
- Making user data "Public" by default.
- Allowing search engine indexing of profiles.
- Enabling "Instant Personalization" for third parties on an opt-out basis.
These are described as misleading omissions. By hiding the most privacy-invasive settings deep within menus, the platform leverages the "power of defaults" to feed its advertisement-based business model, where member-created data is the primary "lifeblood."
Experimental Insight: Why Recommendations Aren't Enough
The paper argues that the soft-law approach (recommendations and pacts) taken by the Art. 29 Working Party has failed because Facebook’s business incentives are inherently anti-privacy.
| Metric | Observation |
|---|---|
| User Engagement | Only ~20% of users change privacy settings. |
| Default Stickiness | 75% of users never deviate from default settings. |
| Regulatory Impact | Recommendations are non-binding; penalties are rare. |
Note: Revisualizing the delta between high privacy concern and low technical engagement.
Critical Analysis & Conclusion: The Case for Consumer Law
The most provocative insight of the paper is the shift toward Unfair Commercial Practices (Directive 2005/29/EC).
If data protection law focuses on how data is handled, consumer law focuses on deception. The authors argue that since SNS users are often "technology-ignorant or vulnerable" (especially minors), misleading them with complex interfaces is a commercial infringement.
Takeaway
For researchers and product designers, this work is a reminder that Transparency is not just about having a policy; it is about UI/UX. If a user cannot navigate your privacy settings, your system is legally "unfair." The future of privacy regulation likely lies in merging data law with robust consumer protection penalties to ensure that "privacy by default" becomes a technical reality, not just a legal suggestion.
