Hidden in Plain Sight: a Structured Analysis of Privacy Policies in the Context of Body-worn 'FemTech' Technologies
Authors
Research Background and Issues
-
Issues and Challenges: With growing interest in women's reproductive health within the field of human-computer interaction, there has been an increasing number of technologies focused on women's health, specifically "FemTech" devices. These technologies offer better management and understanding of women's intimate health. However, due to the highly sensitive nature of the data collected by these devices, which often involves politicized topics (e.g., reproductive health and abortion rights), privacy breaches could lead to psychological distress, discrimination, and gender inequality. These potential issues highlight the need to ensure users are fully informed about how their data is collected, used, stored, and shared.
-
Importance: Women's health data, including menstrual cycles, pregnancy status, and contraceptive information, is often more sensitive than financial data. If such health data is misused or shared with third parties, users may face serious threats to their personal privacy and safety, such as workplace discrimination or political consequences (e.g., lawsuits related to abortion). Additionally, breaches of this data could lead to mistrust in technology, ultimately impacting the sustainable development of the FemTech industry.
-
Research Motivation and Existing Studies: While existing studies have addressed privacy and security issues in FemTech technologies, they primarily analyze specific policy texts or focus on privacy practices in mobile applications, rarely examining the complete privacy policy texts of wearable devices. This indicates the need for a systematic analysis of FemTech privacy policies to assess their transparency and provide recommendations for improving user informed consent and data rights.
Solutions
-
Research Methods:
The authors conducted a structured content analysis of privacy policies from 18 existing FemTech devices. Using an empirical privacy taxonomy, the study comprehensively evaluated privacy policies across multiple dimensions, including data storage, data usage, and data sharing. The case studies covered various device types (e.g., smartwatches, wristbands, patches) and analyzed key issues related to user privacy. -
Innovations:
- Comprehensive Analysis: Unlike previous studies that only mention certain parts of privacy clauses, this study examines the complete privacy policy texts, offering a more thorough understanding of actual privacy practices.
- Six Key Challenges Identified: The study distilled six critical issues from the wording, content presentation, and implementation of privacy policies, which impact policy transparency and user comprehension.
- Specific Recommendations: The study provided nine actionable suggestions to improve the transparency and comprehensibility of privacy policies, illustrated with examples of "best practices" and "anti-patterns."
-
Implementation Steps:
- Collect and filter 18 valid privacy policy texts, covering various types of FemTech devices.
- Use an empirical taxonomy to code and analyze multiple aspects, such as data usage, storage locations, and third-party data sharing.
- Combine closed and open coding methods to iteratively refine the coding schema and summarize six key categorical issues.
- Based on the analysis results, propose specific, actionable recommendations for designing more transparent and comprehensible privacy policies.
Research Outcomes
-
Specific Findings:
- Provided a detailed list identifying the types of data collected by FemTech devices (e.g., reproductive health, device information, interaction data) and their sharing practices.
- Identified six key issues, including unclear data usage, unspecified server locations, ambiguous policy wording, mixed handling of data types, inconsistent data rights management, and inadequate mechanisms for notifying users of policy updates.
- Summarized the extent to which each privacy policy supports user rights (e.g., data access, modification, deletion) and found that only a minority of devices offer comprehensive data rights functionality.
-
Advantages:
- Thoroughness: Comprehensive coverage of all aspects of FemTech privacy policies, beyond privacy clauses or specific device features.
- In-depth Analysis: Revealed subtle differences in policies through taxonomy and detailed coding, such as issues with regional legal applicability and insufficient recognition of data sensitivity.
- Practicality: Provided nine specific recommendations to guide device manufacturers and policymakers in enhancing policy transparency and improving user privacy experiences.
-
Experimental or Evaluation Results:
The analysis uncovered specific issues in many policies, such as the use of vague terms (e.g., "may," "for example") or unclear descriptions of server locations and legal applicability for cross-border data. Additionally, mechanisms for notifying users of policy updates remain inadequate, with most devices relying on users to check updates themselves. -
Limitations and Future Directions:
- The study did not address actual user perceptions or interactive experiences with policies, focusing solely on policy text analysis.
- The specific impact of regional laws or cultural contexts on policy interpretation was not explored in depth.
- Future research could delve into linguistic or design approaches to optimize the readability and acceptance of privacy policies, or validate the effectiveness of specific recommendations through user experiments.
Through this study, the authors not only highlighted transparency issues in current FemTech privacy policies but also provided clear directions for promoting greater social responsibility and policy improvements in managing women's health data.
Research Questions / Practical Problems
Question signals indexed for this paper.
Research Questions
3- What key issues in FemTech device privacy policies affect policy transparency and user understanding?Category: Privacy Policy, Notice, and Terms ComprehensionSimilar questionsarrow_forward
- How well do current FemTech privacy policies support users' data rights?Category: Privacy Policy, Notice, and Terms ComprehensionSimilar questionsarrow_forward
- How can FemTech privacy policies be improved to increase transparency and informed consent?Category: Privacy Policy, Notice, and Terms ComprehensionSimilar questionsarrow_forward
Practical Problems
1- Women using FemTech devices worry about data privacy breaches that may lead to discrimination or safety threats.Category: Privacy Policy, Notice, and Terms ComprehensionSimilar questionsarrow_forward
- 80%
Toggles, Dollar Signs, and Triangles: How to (In)Effectively Convey Privacy Choices
CHI '21· Privacy by Design & User Control +1
- 80%
Covert Embodied Choice: Decision-Making and the Limits of Privacy Under Biometric Surveillance
CHI '21· Privacy by Design & User Control +1
- 80%
“Our Users' Privacy is Paramount to Us”: A Discourse Analysis of How Period and Fertility Tracking App Companies Address the Roe v Wade Overturn
CHI '24· Privacy by Design & User Control +1
- 80%
Out-of-Device Privacy Unveiled: Designing and Validating the Out-of-Device Privacy Scale (ODPS)
CHI '24· Privacy by Design & User Control +1
- 80%
Disconnecting: Towards a Semiotic Framework for Personal Data Trails
DIS '20· Privacy by Design & User Control +1
- 67%
Webcam Covering as Planned Behavior
CHI '18· Privacy by Design & User Control +2
- 67%
Bringing Design to the Privacy Table: Broadening
CHI '19· Privacy by Design & User Control +2
- 67%
Smart Home Security Cameras and Shifting Lines of Creepiness: A Design-Led Inquiry
CHI '19· Privacy by Design & User Control +2
- 67%
Evaluating 'Prefer not to say' Around Sensitive Disclosures
CHI '20· Privacy by Design & User Control +1
- 67%
A Psychometric Scale to Measure Individuals' Value of Other People's Privacy (VOPP)
CHI '23· AI Ethics, Fairness & Accountability +2
Based on Jaccard similarity of research subtopics & professions (≥60%)