The choice of processing location must be visible, not hidden
Aliases: data residency disclosure · processing transparency
What it is
When "where my data is processed" — on-device, in the cloud, or which leg of a hybrid — is a black box to users, they cannot turn privacy preferences into purchase and configuration decisions. "Visible" means the processing location is a discoverable product fact: findable before buying, legible in settings, noticeable when it changes. This is not moral exhortation but the precondition of a market mechanism: consumers without information cannot vote with their wallets, and privacy exits the competitive dimension.
The reality this entry targets: vendors defaulting to cloud have no incentive to advertise it ("cloud processing" is not a selling point and is a privacy demerit), so everything on the shelf looks the same — "smart", "home protection", "cloud storage" — and the processing-location information is systematically erased.
Why it happens
Why visibility changes behaviour and markets:
- Decisions happen at purchase and configuration, and their input is cognition. The user's understanding of "how this device handles data" is the main input to privacy decisions, and processing location is its highest-weighted variable (it determines who can reach the data). With cognition absent, decisions collapse into resolution-and-price comparisons — the privacy dimension vanishes from the demand side.
- Concealment produces adverse selection. When "local-first" products cannot turn that into a verifiable selling point, vendors who invest in privacy get no market reward while cloud-dependent products that skip local compute get cheaper — with the information off the shelf, the whole vote-with-your-purchase mechanism fails and bad money drives out good.
- Visibility also serves failure expectations. Users who know a device depends on the cloud predict offline behaviour accurately ("cloud features will stop"); users who do not read an outage as a broken device. Processing location is an explanatory variable for degraded behaviour; hiding it hides the system's failure modes along with it.
The concrete forms of concealment are worth naming: location buried on page 40 of the privacy policy, data flows silently redirected after a firmware update, marketing pages saying "secure and encrypted" while never saying where data goes — no technical lie told, all cognition obscured.
Studying it
- Consumer-cognition studies: measure how well users' beliefs about home-device data handling (local or cloud, retained how long, accessed by whom) match reality — smart-home interviews show high misunderstanding rates, baselining the existence of concealment.
- Labelling experiments: in the spirit of energy-efficiency labels, add a processing-location label to product pages (local / cloud / hybrid, by data type) and compare choice distributions and willingness-to-pay before and after — a direct test of visibility's market effect.
- Change-awareness studies: track actual data-flow changes across firmware updates against what users were told, measuring the rate of "silent redirection".
One methodological caution: guard against social-desirability bias in willingness-to-pay — stated privacy concern and actual payment diverge; forced-choice designs (paired comparisons, budget-constrained trade-offs) beat direct questions.
Where it stops holding
- Visible is not the same as legible. Throwing "edge computing" or "hybrid architecture" at users is not visibility; facts must be translated to the level of "who can see your data" (footage never leaves the house / uploaded to vendor cloud for 7 days). Information organisation matters more than terminological honesty.
- Granularity depends on the product's audience. DIY users (self-built NAS cameras) can read architectural detail; managed users (subscription bundles) need conclusion-grade badges. One granularity for everyone either frightens novices or insults experts.
- A duty to disclose is not a duty to offer choice. Letting users see the location and letting them choose it are separate steps; many products technically cannot offer the choice (the model lives in the cloud), and the duty there is honest labelling, not a pretend option.
Applying it
- Label processing location on product pages and packaging: present "does data leave the home network" as a first-class fact alongside data types and retention, one row in the spec table next to resolution and battery life.
- A standing "where data goes" view in settings: each class (video, audio, events, telemetry) with its current processing location and destination, updated live as configuration changes.
- Announce changes with the version: firmware updates that redirect data state so on the first page of release notes (not clause 7), with a change history kept in settings.
- Give "local-first" verifiable credentials: pair local claims with independent verification (full offline-function demos, third-party audit marks) — otherwise the claim itself becomes the new marketing line.
- How to check: sample users at random — "where is your camera's data stored and processed?" The share answering at class level (local / cloud / hybrid plus rough destination) is the visibility score; in purchase scenarios, measure the weight processing-location information carries in choice.
Related
- Same group: Z6.07.1 Local processing lowers exposure risk but caps capability · Z6.07.2 Cloud processing is more capable but enlarges the transport and storage attack surface · Z6.07.3 Hybrid architectures must pin down which data types never leave
- Nearby: Z6.06 Notice for passive collection · Z6.05.4 Storage location determines the actual risk of exposure
- Search terms:
data residency disclosure·processing transparency·privacy labelling·IoT privacy label