Z8.03.2Purpose specificationdesignresearch

Notice must state the purpose of collection, not merely the fact

Aliases: purpose limitation · purpose transparency

What it is

"This area is monitored" is not adequate notice — effective notice must say why the collection happens: footage kept for theft prevention, counts for passenger-flow scheduling, audio for fault diagnosis. The requirement is usually called purpose specification: the core content of notice is the use, not the existence of the device.

The substantive difference: people evaluate collection by what will be done with it, not by data type. The same camera means something different when retained for security than when analysed for behaviour in real time. Stating the fact while withholding the purpose withholds the raw material of assessment — the covered can neither judge what the collection is to them, nor exercise downstream rights (whom to ask for deletion or correction of which data).

Why it happens

  • Purpose is the input to assessment: risk judgements about collection run on use frames — "for security" and "for profiling" activate entirely different normative expectations. Factual notice ("a camera is present") suspends the assessment, and the suspended state defaults toward distrust.
  • Purpose binds the operator: a publicly declared use is a self-restriction — the operational layer of the purpose limitation principle. The characteristic slide of public sensing is function creep: a camera installed for theft prevention later feeds passenger profiling, behaviour analysis, even external requests. The declared purpose is the anchor by which out-of-scope use can later be identified; without it, creep is undefinable.
  • The unit of comprehensibility: the unit ordinary people can reason over is the purpose phrase (theft prevention / flow statistics / fire monitoring), not sensor models, technical parameters, or legal citations. Purpose phrases translate the technical black box into socially assessable behaviour categories — notice functioning as a translation layer.

Studying it

  • Privacy-notice readability research: comparing notice formats is a mature line in privacy research — short notices, layered notices (one line at entry, details on demand), and icon-based notices differ in reading and comprehension rates; the consistent finding is that long policies are not read, and form determines effectiveness.
  • Purpose-framing experiments: the same collection paired with different purpose statements, measuring trust and acceptance differences — the effect of purpose framing on acceptance is stable in privacy research, and the design transfers directly to evaluating public-sensing notices.
  • Function-creep case studies: retrospective analyses of how monitoring and data systems expanded in use (declared purpose at deployment versus actual use years later), giving empirical shape to the creep path.

Methodological caution: measure purpose recall separately from existence recall — many remember "there are cameras" but cannot say what for. The gap between the two recalls is exactly the gap between factual and purposeful notice, and sets the priority for upgrading it.

Where it stops holding

  • Notice cannot substitute for system design: declaring "flow statistics" while deploying face-recognizing cameras is systematically misleading however clear the notice — alignment between the declared purpose and the actual technical capability is the precondition of truthful notice. A mismatched notice is worse than none (it spends the public good of "notices are believable").
  • Multiple purposes must be declared separately: collection serving both security and marketing analysis, bundled into "to improve services and safety", amounts to no specification at all. Declare them apart, and where possible make them separately declinable — the minimal implementation of purpose limitation.
  • The test of an assessable purpose: overly broad purposes ("to improve user experience", "for safety") do not qualify. The check is whether the covered person can infer consequences relevant to themselves from it — a purpose from which nothing follows is decoration.
  • This entry covers the content of notice; its position, persistence and responsible party are the business of neighbouring entries — do not expand them here.

Applying it

  • Fix the sign template at four elements: type icon, a one-line purpose in plain words, the operating body, and a complaint/enquiry contact; keep the purpose phrase at everyday reasoning concreteness ("retained 30 days for theft prevention", not "for safety assurance").
  • Keep the on-sign purpose wording verbatim aligned with the data-registry text, preventing the two versions from drifting apart.
  • Make purpose change a notice trigger: new uses, new analytics vendors, longer retention all update the sign and the registry together — notice rides in the data-change approval flow, not in the refurbishment budget.
  • How to check: intercept surveys measuring existence recall and purpose recall separately, accepting on the latter; re-survey after any purpose change. Persistently low purpose recall points to wording concreteness and placement, not to notice frequency.

Related

  • Same group: Z8.03.1 Sensing in public places requires noticeable and persistent notice · Z8.03.3 The lack of an exit is what separates public monitoring from personal devices · Z8.03.4 The duty to inform lies with the venue operator, not the individual
  • Nearby: Z2.07 Making context inferences visible and explainable · the privacy domain for general mechanisms
  • Search terms: purpose specification · purpose limitation · function creep · privacy notice

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/Z8.03.2