The Great Privacy Disconnect: Why You Can’t Control What Social Networks Claim You Can
Do the Privacy Policies Reflect the Privacy Controls on Social Networks?
This paper examines the alignment between textual privacy policies and functional privacy controls on major social networks (Facebook, Twitter, MySpace, and PerfSpot). Using a qualitative mapping scale (Complete, Partial, Broken), the authors demonstrate a significant systemic disconnect where stated data practices lack corresponding user-manageable controls.
TL;DR
Even if you spend hours reading a social network’s privacy policy, you probably can't actually control the data collection it describes. Researchers at Lancaster University analyzed prominent social networks and found a massive "disconnect" between legal promises and functional buttons. Most critically, while you can control who sees your posts, you have almost zero control over how the platform itself collects your metadata or shares it with subsidiaries.
Background: A Personal Data Ecosystem in Chaos
Social Networking Sites (SNS) have become the primary repositories of our digital lives. However, high-profile leaks—like Facebook's token leakage to third parties—have shattered user trust. To defend themselves, platforms have released "plethora of controls" (Facebook once had 61 settings across 7 pages). But does more settings mean more control? This paper argues the opposite: the complexity masks a fundamental lack of mapping between policy text and technical reality.
The "Broken" Mapping Problem
The authors suggest that a privacy policy should be an operational manual for the user. If the policy mentions a data practice, there should be a corresponding button to manage it.
They categorize the relationship between Policy and Control into three states:
- Complete: Labels match, and the setting is easy to find.
- Partial: Vague language (e.g., "we use some information") makes it unclear which button to press.
- Broken: The policy describes a practice (like collecting your IP address), but there is literally no way for the user to opt-out or manage it.
Methodology: Mapping Data to Visibility
The researchers used a grounded theory approach to bridge the gap between "Actions" (what the site does) and "Operations" (what the user can do).
Fig 1: The framework used to cross-reference policy sentences with UI operations.
Experimental Results: The Illusion of Choice
The findings were stark. The researchers evaluated Facebook, MySpace, Twitter, and PerfSpot.
1. The Feedback Loop Void
For "Indirect Collection"—the silent gathering of browser types, IP addresses, and navigational data—the mapping was Broken for every single site. Users are told it happens, but they are given zero agency over it.
2. Sharing vs. Broadcast
Social networks are great at letting you control "Sharing by a member" (e.g., making a post 'Friends Only'). However, "Sharing by the SNS provider" (where the site sells or gives your data to partners) is a black box. No controls exist for these backend transactions.
Table 1: The visualization of "Complete" (black circles) vs "Broken" (white circles) mappings across categories.
Critical Insight: Transparency is Not Control
The most profound takeaway is that transparency ≠control. A site can be perfectly "transparent" by admitting they sell your data in a 50-page document, but if there is no "Operation" to stop it, the privacy control architecture is fundamentally failed.
The authors conclude that privacy controls should be a causal reflection of the policy. If it's in the text, it must be in the UI. Anything less is a "Privacy Jungle" designed to minimize user awareness while maximizing data extraction.
Conclusion & Future Outlook
This exploratory study serves as an early warning for the modern UI/UX era. As we move toward more complex "personal data ecosystems," the need for automated runtime traceability tools—software that can automatically verify if a site's code matches its legal promises—is more urgent than ever.
