O2.05.1Cross-context tracking disclosuredesignresearch

Cross-application and cross-site tracking needs explicit disclosure

Aliases: cross-application tracking disclosure · cross-site tracking notice · identity-linking notice

What it is

Cross-context tracking disclosure explains when an organization links one person's activity across applications, sites, devices, or offline settings. It identifies the linking actor, data, purpose, and beneficiaries. “Improving your experience” does not disclose tracking: a person needs to know whether current behavior leaves its present context, which other activity it joins, and whether the result supports targeting, attribution, or profiling.

Why it happens

A screen exposes one interaction, while cookies, advertising identifiers, signed-in accounts, embedded SDKs, and server events assemble an identity graph in the background. That mismatch between local interface visibility and cross-context data life encourages people to assume that activity in A remains in A. Concrete disclosure turns hidden links into an anticipatable information flow and gives a subsequent choice a definite object.

Studying it

Researchers can construct tasks containing first-party analytics, an embedded advertising service, and cross-device sign-in. After seeing the disclosure, participants draw where data travels, what it joins, and who may use it. Comparing predicted flows with traffic captures, SDK configuration, and server events measures beneficiary recognition, cross-context understanding, and false confidence. Asking only whether text felt understandable overstates transparency; comprehension needs answers about actual flows.

Where it stops holding

Necessary state continuity inside one service and cross-company advertising profiles do not carry identical risk, so “tracking” should not flatten scope. Security, fraud prevention, and aggregate measurement may warrant different necessity and detail, but a purpose label cannot replace an account of linkage. Exact detection rules may be withheld to avoid assisting attackers without hiding participating roles or the kinds of information flow.

Applying it

  • At the task event that first creates a cross-context link, show a short path from current activity to other context, use, and participants.
  • Distinguish first party, affiliated company, and independent third party with recognizable names and roles rather than only legal entities.
  • Disclose again when source, identifier, linkage scope, or purpose changes materially; do not interrupt for inconsequential copy edits.
  • Ask unprimed newcomers to reconstruct the flow, then compare it with network and backend paths; revise whenever a consequential link is missed.

Related

  • Same group: O2.05.2 Opting out needs to be as easy as opting in · O2.05.3 Tracking scope needs to be queryable
  • Adjacent: O1.08 Contextual integrity · O2.02 Readable explanations of data use · O2.08 Disclosure of third-party data sharing
  • Search terms: cross-context tracking disclosure · identity graph transparency · cross-site tracking notice

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/O2.05.1