Gamifying Privacy: Using Crowdsourcing to Break the Privacy Paradox

A Rewarding Framework for Crowdsourcing to Increase Privacy Awareness

2021-01-01
Ioannis Chrysakis, Giorgos Flouris, Maria Makridaki, Theodore Patkos, Yannis Roussakis, Georgios Samaritakis, Nikoleta Tsampanaki, Elias Tzortzakakis, Elisjana Ymeralli, Tom Seymoens, Anastasia Dimou, Ruben Verborgh
Summary
Problem
Method
Results
Takeaways
Abstract

The paper introduces a Rewarding Framework (RF) integrated into the CAP-A crowdsourcing portal, aimed at increasing digital privacy awareness. By combining intrinsic and extrinsic rewards (points, badges, leaderboards) based on the REWARD ontology, it motivates users to perform complex privacy tasks such as annotating Privacy Policy (PrP) documents.

TL;DR

Privacy Policies (PrPs) are the "unread manifestos" of the digital age. This paper presents the Rewarding Framework (RF) within the CAP-A portal, a system that uses gamification, tiers, and the REWARD ontology to turn the tedious task of reading privacy policies into a rewarding community activity. The result? A massive 286% average increase in privacy awareness among users.

The "Privacy Paradox" and the Engagement Wall

We all claim to care about our data, yet we click "I Accept" in milliseconds. This is the Privacy Paradox. The primary barrier isn't just apathy; it's the sheer complexity and length of PrP documents. While crowdsourcing (having many users annotate parts of a policy) is a logical solution, most people find it incredibly boring.

Previous works relied on paid crowdsourcing (like Amazon Mechanical Turk), which is expensive and often lacks high-quality "intrinsic" motivation. The authors of this paper argue that to truly raise awareness, we need a framework that balances Intrinsic Motivation (learning, social recognition) with Extrinsic Rewards (points, badges, leaderboards).

Methodology: The Engineering of Motivation

The core of this research is a four-tiered task system designed to match a user's expertise with the difficulty of the task.

1. The REWARD Ontology

Instead of a hard-coded point system, the authors used an ontology-based approach. This allows the system to be agile. For instance, if a specific pilot project needs more users to annotate a specific app category, they can apply a "Boost Parameter" to increase points for those tasks without rewriting the code.

2. Tiered Task Management

To ensure quality, the RF locks "sophisticated" tasks behind experience walls:

  • Level 1: Basic tasks (e.g., completing a profile).
  • Level 2: Social tasks (e.g., voting on credibility).
  • Level 3 & 4: High-level annotation and GDPR concept identification—reserved for "Expert" or "Guru" tiers.

Overall Architecture of the RF Framework Figure 1: The Rewarding Framework integrated into the CAP-A Portal architecture.

Experiments: Does it Actually Work?

The validation involved six pilots (e.g., Saferinternet4Kids, Devstaff) and a dedicated empirical evaluation.

Engagement Results

The engagement metrics were impressive. Users were asked to complete 10 tasks; on average, they completed 41. This suggests that the gamification Loop (Tasks -> Points -> Tiers -> Feedback) effectively keeps users "in the loop."

Awareness Impact

The study used the Privacy Awareness Index (PAI) to measure knowledge before and after using the portal. The results were striking:

  • Pragmatists: +286% increase in awareness.
  • Unconcerned Users: +288% increase in awareness.
  • Fundamentalists (Already aware): +151% increase.

Privacy Awareness Index Comparison Figure 2: Significant PAI growth across different user classes (Fundamentalists, Pragmatists, Unconcerned).

Critical Insight: Why This Matters

The breakthrough here isn't just "giving points for tasks." It is the Task Leveling strategy. By preventing "Baby" users from attempting complex legal annotations (Level 4), individual users don't feel overwhelmed, and the community data remains high-quality.

Limitations & Future Work

The authors noted that Annotation (Level 3/4) is still perceived as difficult compared to simpler tasks like "expressing expectations." Future work will likely focus on "UX Nudging"—finding even more attractive ways to present legal text, perhaps through better annotator interfaces or team-based rewards.

Conclusion

The CAP-A Rewarding Framework proves that privacy awareness doesn't have to be a chore. By treating privacy policy analysis as a collective intelligence task supported by a solid gamification ontology, we can move from "blindly accepting" to "knowingly engaging" with the digital ecosystem.

Find Similar Papers

Try Our Examples

  • Examine recent SOTA crowdsourcing frameworks that utilize hybrid intrinsic and extrinsic rewards specifically for legal or policy-related text annotation.
  • What is the theoretical origin of the "Privacy Paradox" across digital platforms, and how have subsequent studies utilized gamification to mitigate user cognitive load?
  • Investigate how the REWARD ontology has been extended or applied in other citizen science or collective intelligence domains beyond digital privacy.
Contents
Gamifying Privacy: Using Crowdsourcing to Break the Privacy Paradox
1. TL;DR
2. The "Privacy Paradox" and the Engagement Wall
3. Methodology: The Engineering of Motivation
3.1. 1. The REWARD Ontology
3.2. 2. Tiered Task Management
4. Experiments: Does it Actually Work?
4.1. Engagement Results
4.2. Awareness Impact
5. Critical Insight: Why This Matters
5.1. Limitations & Future Work
6. Conclusion