Collective Sovereignty: Collaborative Privacy Policy Authoring in Social Networks

Collaborative Privacy Policy Authoring in a Social Networking Context

2010-01-01
Ryan Wishart, Domenico Corapi, Srdjan Marinovic, Morris Sloman
Summary
Problem
Method
Results
Takeaways
Abstract

The paper introduces a collaborative privacy policy authoring framework for social networks, implemented as a prototype called PRiMMA-Viewer. It enables content owners to share policy-making power with "co-owners" (e.g., people tagged in a photo) to ensure that data disclosure respects the privacy needs of all affected parties.

TL;DR

In the social media era, a single photo can impact the lives of everyone in the frame, yet privacy settings are typically controlled by a single uploader. This paper introduces a collaborative authoring framework that allows multiple stakeholders (co-owners) to co-create privacy policies. By distinguishing between Strong Conditions (vetoes) and Weak Conditions (preferences), the system balances individual safety with social sharing.

Background Positioning

This work sits at the intersection of Access Control and Social Computing. While prior works like XACML or P3P focused on enterprise or single-user data, this paper addresses the specific "privacy entanglement" found in social networks. It is a pioneering effort in moving from monolithic ownership to a distributed, stakeholder-based model.

Problem & Motivation: The Single-Owner Fallacy

The authors highlight a critical flaw in current Social Networking Services (SNS) like Facebook: Content ownership is tied to the uploader.

  • The Conflict: If Alice uploads a photo of Bob at a party, Bob might lose his job if the photo is public, but Alice owns the "rights" to set the visibility.
  • The Limitation: Existing "Collective Privacy" solutions often rely on simple voting or merging, which doesn't allow for negotiation or "hard nos."
  • The Insight: Privacy is not binary. Users need a way to express "I’d rather people didn't see this (Weak)" versus "My family must NEVER see this (Strong)."

Methodology: Logic-Based Collaboration

The core of the proposal is a policy language defined by Datalog semantics. The unique contribution is the structural split of conditions:

  1. Strong Conditions (): Non-negotiable rules. If a co-owner adds a strong condition (e.g., not group('Bob', Y, 'Family')), it cannot be deleted by others.
  2. Weak Conditions (): Negotiable preferences that can be modified or removed by other owners, facilitating social flexibility.

System Architecture

The authors implemented PRiMMA-Viewer, a prototype that sits atop Facebook but stores data externally to ensure policy integrity.

Overall Architecture Fig 1. The PRiMMA-Viewer architecture using a Policy Decision Point (PDP) and Policy Enforcement Point (PEP) external to Facebook.

The PDP uses the IRIS Reasoner to evaluate requests against the social graph. When Alice uploads an album, she nominates Bob as a co-owner. Bob can then layer his own conditions onto Alice's original policy.

Experiments & Results: Real-World Policy Logic

The paper illustrates the approach through a scenario where users define context-aware rules. The system successfully processes complex logic like:

  • Proximity Rules: Deny access if the requester is physically at "Bob's House."
  • Interaction Rules: Allow access only to "friends in touch" (those who have exchanged messages).

Policy Authoring UI Fig 2. The PRiMMA-Viewer interface where users can hand-code Datalog-style policy rules.

By using Stratified Datalog, the authors ensure that even with negation and complex relations, the system remains tractable and decidable, which is a prerequisite for any real-time social media platform.

Critical Analysis & Conclusion

Takeaway

The shift from "Uploader-Rights" to "Stakeholder-Rights" is a necessary evolution for digital privacy. By formalizing the difference between preferences and mandates (Weak vs. Strong), this framework provides a practical middle ground for social negotiation.

Limitations

  1. Incentive Gap: The system currently relies on the uploader's "goodwill" to invite co-owners. Without a mechanism for users to claim ownership (perhaps via facial recognition), malicious uploaders can still bypass the system.
  2. Usability: Coding logic rules (Datalog) is beyond the average user. A simplified GUI or Natural Language Interface is essential for mass adoption.

Future Work

The authors foresee using automated conflict detection to alert owners when their rules contradict and exploring incentivized voting schemes to encourage fair collaboration. This work lays the foundation for a more democratic and privacy-respecting social web.

Find Similar Papers

Try Our Examples

  • Search for recent papers that extend multi-party privacy conflict resolution in social networks using machine learning or game theory.
  • What are the foundational papers on "Multiparty Access Control" (MPAC) in online social networks, and how does this paper's weak/strong condition distinction build upon them?
  • Explore how facial recognition technologies have been integrated into collaborative privacy frameworks to automate the identification of co-owners in digital media.
Contents
Collective Sovereignty: Collaborative Privacy Policy Authoring in Social Networks
1. TL;DR
2. Background Positioning
3. Problem & Motivation: The Single-Owner Fallacy
4. Methodology: Logic-Based Collaboration
4.1. System Architecture
5. Experiments & Results: Real-World Policy Logic
6. Critical Analysis & Conclusion
6.1. Takeaway
6.2. Limitations
6.3. Future Work