Notice must match the situation; dense terms do not work
Aliases: just-in-time notice · notice fatigue · contextual privacy notice
What it is
Notice that works is in-situ, comprehensible, and relevant right now: a line of text on the device, a sign at the entrance to the space, one sentence when capture first happens. A screen of dense legal clauses or a "see our privacy policy" link amounts to no notice at all in domestic settings — not because users disregard privacy, but because the form physically never reaches the moment and place where judgement happens.
What this entry opposes is the illusion that "duty to notify = a notification document exists". The standard of fulfilment is not document existence but whether the affected person can obtain processable information at the moment they need it. A document without a situation is notice in the compliance sense and a blank in the cognitive sense.
Why it happens
Why situatedness is a necessity rather than a nicety:
- Near-zero policy reading is the rational outcome. At installation or checkout the user's goal is to finish the task; stopping to read ten thousand words of terms carries a high opportunity cost, and even having read them yields nothing memorable or negotiable. Not reading is not laziness — it is the optimal strategy under that situation's structure. "They clicked agree" is cognitively empty as evidence of informedness.
- Knowledge is processed only when a situation activates it. "Does this camera see the sofa?" becomes a real question only when a person stands in the living room looking at the device; inside step 7 of a setup wizard it is abstract noise. Situations supply retrieval cues and motivation; information divorced from them never enters usable memory.
- Granularity decides usability. Global policy ("we may collect device data to improve services") supports no concrete judgement; what converts into judgement are device-level, event-level facts — "this device has a microphone; recordings are kept 7 days on the vendor cloud". The natural unit of notice information is the device and the situation, not the vendor and the policy.
Studying it
- Reading-rate studies: the classic findings on privacy-policy behaviour — reading rates and durations near zero, and insensitive to changes in clause content — directly undermine "policy provided = notice done".
- Ubiquitous-consent research: Luger and Rodden's interviews on consent in context-aware collection show that the prevailing mechanism (long terms plus one-time confirmation) fails systematically for ubiquitous collection; users need information forms closer to the point of capture.
- Format-contrast experiments: present identical facts either as just-in-time situated prompts (on entering the space, at first trigger) or as setup-time policy text, then compare recall of key facts, comprehension accuracy, and configuration behaviour (whether settings were adjusted to match stated preferences).
One methodological caution: measure recall in delayed, context-uncued tests. Reciting on the spot measures working memory; still being able to say a week later "that living-room device records audio" is informedness.
Where it stops holding
- Simplification does not reduce the obligation. Saying only "we collect data to improve your experience" is worse than long clauses: unread and uninformative. The compliance layer (purposes, retention, third-party sharing, redress paths) is legally required; the situated layer is cognitively required — both layers, not either.
- Situated prompts carry an interruption cost. Prompting on every entry trains people to ignore it; prompts belong at low-frequency, high-relevance touchpoints (first time, on change), with everyday presence carried by standing discoverability (device marking, indicators).
- Multilingual, multigenerational households: situated-layer information should be in the languages the household actually uses; bilingual signs beat a single default language — the people needing notice at home are not all the buyer's generation.
Applying it
- Layered notice: one line of core fact on the device or at the entrance ("this device records video and audio, kept for 7 days"), complete in itself; details (where stored, who can view, how to disable) one level deeper via QR code or long-press.
- Occupy three touchpoints: the device itself (standing), the space entrance (visible on entry), and the first moment of capture (one-time explanation plus a confirmation entry). These cover installer, cohabitants, and guests.
- Write the situated layer in plain language: sentence patterns like "what it can hear, what it sees, how long it keeps, how to turn it off" — no "data controller" or "legitimate interest".
- Re-occupy the touchpoints on change: notices about capability changes reappear in the situation, not only as a push notification.
- How to check: interview household members and guests just after they enter the space — "what does this device collect?" The hit rate on core facts is the situated layer's direct grade; comparing answers against the second-layer document measures the reachability of deeper notice.
Related
- Same group: Z6.06.1 Passive collection differs from active query, and usually goes unnoticed · Z6.06.2 After-the-fact notice cannot replace a prior opportunity to know · Z6.06.4 Short-term guests and long-term residents need different depths of notice
- Nearby: Z6.08 Physical indicators of collection · Z6.04 The presence of non-users
- Search terms:
situated notice·just-in-time notice·privacy policy reading·privacy labelling