Z6.06.4Guest versus resident notice needsdesignresearch

Short-term guests and long-term residents need different depths of notice

Aliases: bystander privacy · guest notice · resident notice

What it is

For the same passive collection in the same space, the depth and form of the notice owed differ by length of stay: long-term residents need standing, queryable notice plus a channel into configuration; short-term guests need conspicuous notice at the moment of entry and a zero-dependency path to understanding. One uniform scheme (a single household consent, one shared policy) fits neither — too deep for guests (they will never read settings) and too shallow for residents (they need participation, not notification).

The layering is not by identity label (family / guest) but by two continuous variables: exposure dose (how much data accumulates) and control leverage (how many means exist to change the situation).

Why it happens

The two groups' divergence follows a mismatch of dose and leverage:

  • Doses differ by orders of magnitude. Residents are collected continuously; their data spans sleep-wake rhythm, habits, health signals — harmless per day, a complete profile in aggregate. Guests are collected for hours and leave fragments. The dose gap sets the risk gap and the content gap: residents need to know "how a longitudinal profile forms and flows", guests only "what this visit will capture".
  • Leverage is entirely different. Residents can join household negotiation, reach the configuration, and speak when devices change — their notice must connect to participation rights. Guests have no account, no configuration surface, no seat at the table; their only levers are "ask the host" or "leave". Guest notice must therefore be zero-dependency — obtainable without installing an app, registering, or asking (a sign at the entrance, a label on the device, one sentence from the host) — and its executable outcome is behavioural choice (where in the home to be, what to say).

Making the guest layer a simplified copy of the resident layer ("show them the same policy") fails by construction: the form depends on things they do not have — accounts, patience, a negotiating relationship with the host.

Studying it

  • Role-stratified interviews: smart-home research (e.g. the SOUPS 2017 interviews by Zeng, Mare and Roesner) already reports secondary users — guests, nannies, cleaners — whose privacy is decided by the buyer, with notice channels designed for no one. Stratified interviews (owner / resident / visitor) on notice needs versus actual knowledge measure both the necessity of layering and the present gap.
  • Bystander privacy research: the literature on third-party privacy discusses the notice-and-control predicament of non-users facing other people's devices, and can frame the guest side.
  • Notice-reachability audits: let a new guest enter the space naturally, then afterwards measure what they knew about "what collects here" and from where; compare with residents' knowledge paths to quantify the reachability gap.

One methodological caution: do not measure guest awareness with the host present — accompaniment itself triggers explanation; probe retrospectively after natural visits.

Where it stops holding

  • The layering is not a dichotomy. Flatmates, a grandparent who visits weekly, a cleaner present three hours a week sit between the poles — assess on "dose × leverage": the more frequent and longer the stay, the closer to the resident configuration (query channels, a seat in decisions).
  • In private homes guest notice is weakly enforceable. No statute obliges notice in a private residence; it rests on the host's diligence and product defaults (devices carrying their own marking). Commercial lodging (hotels, short-term rentals) does carry statutory notice duties — that side belongs to public-space monitoring notice, a different rule set.
  • "Notified therefore permitted" does not follow. Guest notice delivers knowing, not agreeing — a guest told about the camera still faces the weak choice of accept-or-leave; restraint on the host's side (turning it off, masking it) remains a necessary complement, not replaceable by notice.

Applying it

  • Guest layer, zero-dependency notice: one visible line at the entrance ("cameras and audio recording indoors, kept 7 days") plus identifiable devices; requiring no action from anyone. Pair it with a default script for the host — a prompt card or a one-tap in-app explanation — lowering the cost of bringing it up.
  • Resident layer, participatory notice: a standing inventory of devices and data; changes to capture configuration (recording on, voice enabled) go through a household confirmation flow, not the owner's unilateral switch.
  • Configure the middle by frequency: for high-frequency guests (cleaner, elders) provide an in-between channel — e.g. a shareable read-only "about this device" page viewable without registration.
  • How to check: test the two groups separately — for guests, a 3-second attention-capture test on entry (did the notice register) plus ability to restate the core fact; for residents, ability to list the collection inventory and the latest configuration change. Report separately; do not merge.

Related

  • Same group: Z6.06.1 Passive collection differs from active query, and usually goes unnoticed · Z6.06.2 After-the-fact notice cannot replace a prior opportunity to know · Z6.06.3 Notice must match the situation; dense terms do not work
  • Nearby: Z6.04 The presence of non-users · Z6.05.3 Family members diverge sharply in camera acceptance
  • Search terms: bystander privacy · guest notice · secondary users · smart home privacy

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/Z6.06.4