Reference. Exploring Consequences of Privacy Policies with Narrative Generation via Answer Set Programming
Informed consent has become increasingly salient for data privacy and its regulation. Entities from governments to for-profit companies have addressed concerns about data privacy with policies that enumerate the conditions for personal data storage and transfer. However, increased enumeration of and transparency in data privacy policies has not improved end-users’ comprehension of how their data might be used: not only are privacy policies written in legal language that users may struggle to understand, but elements of these policies may compose in such a way that the consequences of the policy are not immediately apparent. We present a framework that uses Answer Set Programming (ASP) – a type of logic programming – to formalize privacy policies. Privacy policies thus become constraints on a narrative planning space, allowing end-users to forward-simulate possible consequences of the policy in terms of actors having roles and taking actions in a domain. We demonstrate through the example of the Health Insurance Portability and Accountability Act (HIPAA) how to use the system in various ways, including asking questions about possibilities and identifying which clauses of the law are broken by a given sequence of events.
Cite
Cited by (2)
Finite-Choice Logic Programming martens-2025-finite
Logic programming, as exemplified by datalog, defines the meaning of a program as its unique smallest model: the deductive closure of its inference rules. However, many problems call for an enumeration of models that vary along some set of choices while maintaining structural and logical constraints—there is no single canonical model. The notion of stable models for logic programs with negation has successfully captured programmer intuition about the set of valid solutions for such problems, giving rise to a family of programming languages and associated solvers known as answer set programming. Unfortunately, the definition of a stable model is frustratingly indirect, especially in the presence of rules containing free variables. We propose a new formalism, finite-choice logic programming, that uses choice, not negation, to admit multiple solutions. Finite-choice logic programming contains all the expressive power of the stable model semantics, gives meaning to a new and useful class of programs, and enjoys a least-fixed-point interpretation over a novel domain. We present an algorithm for exploring the solution space and prove it correct with respect to our semantics. Our implementation, the Dusa logic programming language, has performance that compares favorably with state-of-the-art answer set solvers and exhibits more predictable scaling with problem size.
Privacy Policies on the Fediverse: A Case Study of Mastodon Instances tosch-2024-privacy
Free and open source social platform software has dramatically lowered the barrier to entry for anyone to set up and administer their own social network. This new population of social network administrators thus assume data management responsibilities for sociotechnical systems. Administrators have the power to customize this software, including data collection and data retention, potentially leading to radically different privacy policies. To better understand the characteristics — e.g., the variability, prohibitions, and permissions — of privacy policies on these new social networking platforms, we have conducted a case study of Mastodon. We performed a text analysis of 351 privacy policies and a survey of 104 Mastodon administrators. While most administrators used the default policy that ships with the Mastodon software, we observed that approximately ten percent of our sample tailored their privacy policies to their instances and that some administrators conflated codes of conduct with privacy policies. Our findings suggest the existing market-based individualistic frameworks for thinking about privacy policies do not adequately address this emerging community.
Cites 21 works (0 here)
External (21)
- Generating Explorable Narrative Spaces with Answer Set Programming (2020)
- Privacy promises that can be kept: a policy analysis method with application to the HIPAA privacy rule (2013)
- Expectation and purpose: understanding users' mental models of mobile app privacy through crowdsourcing (2012)
- Declarative privacy policy: finite models and attribute-based encryption (2012)
- Experiences in the logical specification of the HIPAA and GLBA privacy laws (2010)
- A Formalization of HIPAA for a Medical Messaging System (2009)
- A "nutrition label" for privacy (2009)
- A defeasible logic for modelling policy-based intentions and motivational attitudes (2009)
- Examining Usability of Web Privacy Policies (2008)
- What Can Behavioral Economics Teach Us about Privacy (2008)
- A user’s guide to gringo, clasp, clingo, and iclingo (2008)
- Addressing Legal Requirements in Requirements Engineering (2007)
- Privacy and Utility in Business Processes (2007)
- User interfaces for privacy agents (2006)
- Privacy and contextual integrity: framework and applications (2006)
- Privacy as contextual integrity (2004)
- P3P: Making Privacy Policies More Useful (2003)
- On the Modeling and Analysis of Regulations (1999)
- ON-LINE: an architecture for modelling legal information (1995)
- The Stable Model Semantics for Logic Programming (1988)
- Logic programming for large scale applications in law: A formalisation of supplementary benefit legislation (1987)