Understanding User Needs Underlying the Expected Roles of LLM-Based Chatbots in Privacy Decision-Making
Authors
Paper Title
Understanding User Needs Underlying the Expected Roles of LLM-Based Chatbots in Privacy Decision-Making
Publication Info
- Topic area: User expectations and roles of LLM-based chatbots in privacy decision-making.
- Keywords: LLM-based chatbots, privacy decision-making, notice and choice, user needs, privacy policies, ethical considerations, role-based design, user expectations, privacy governance, AI in privacy.
Background and Problem
- Problem / challenge: Privacy policies are lengthy, complex, and ambiguous, leading users to ignore them and make uninformed decisions. Current tools for improving privacy policy comprehension lack interactivity and fail to address user-specific needs or provide actionable guidance.
- Significance: Enhancing privacy decision-making is critical as users frequently interact with digital services requiring personal data disclosure. Effective tools could empower users to make informed privacy choices and mitigate risks.
- Motivation and related work: Prior efforts, such as summarization tools and conversational interfaces, improved privacy policy comprehension but were limited by one-way communication and technical challenges (e.g., hallucinations in LLMs). This study addresses the gap in understanding user expectations and unmet needs for LLM-based chatbots in privacy contexts.
Solution
- Proposed approach: Investigate user expectations and needs for LLM-based chatbots in privacy decision-making through a technology probe, focus groups, and expert interviews.
- Novelty:
- Identification of three user-expected roles for LLM-based chatbots: Interpreter, Guardian, and Evaluator.
- Analysis of satisfied and unmet user needs within these roles, enriched with expert perspectives.
- Role-based practical implications for deploying LLM-based chatbots responsibly in privacy decision-making.
- Procedure and key techniques:
- Conducted a study with 16 participants using a fictional fitness tracking service and an LLM-based chatbot (GPT-4).
- Explored user interactions with the chatbot and their expectations through focus groups.
- Complemented findings with insights from three privacy experts.
- Thematically analyzed user prompts and needs, categorizing them into three roles and 11 prompting strategies.
Results
- Concrete findings:
- Users expect LLM-based chatbots to act as:
- Interpreter: Summarizing and clarifying privacy policies.
- Guardian: Identifying risks and providing actionable guidance.
- Evaluator: Assisting in privacy judgments and aligning policies with personal criteria.
- 11 user strategies were identified, with 53 prompts for the Interpreter role, 25 for the Guardian role, and 36 for the Evaluator role.
- Key unmet needs include concise summaries, proactive risk evaluations, and actionable guidance for managing privacy risks.
- Users expect LLM-based chatbots to act as:
- Advantage over baselines: LLM-based chatbots offer interactive and personalized responses compared to static tools, but their limitations (e.g., hallucinations, vague responses) hinder full effectiveness.
- Experiments / evaluation:
- Participants interacted with a chatbot integrated into a fictional privacy policy scenario.
- Focus groups and expert interviews provided qualitative insights into user needs and ethical considerations.
- Limitations and future work:
- Limited to South Korean participants aged 19–26; broader demographics are needed for generalizability.
- Findings based on GPT-4; newer models may address some limitations.
- Study context focused on a single fictional service; real-world applications and diverse scenarios require further investigation.
Summary
This study identifies three roles—Interpreter, Guardian, and Evaluator—that users expect from LLM-based chatbots in privacy decision-making, along with 11 prompting strategies. While chatbots effectively support comprehension and engagement, unmet needs include concise summaries, actionable guidance, and proactive risk evaluations. Expert insights highlight ethical risks, such as hallucinations and data exposure, and suggest role-based hybrid architectures combining deterministic and LLM-based approaches. The findings underscore the limitations of the notice and choice framework, advocating for structural reforms to better support rational privacy decision-making.
Research Questions / Practical Problems
Question signals indexed for this paper.
- 100%
A Scoping Review and Guidelines on Privacy Policy's Visualization from an HCI Perspective
CHI '26· Privacy Perception & Decision-Making +2
- 100%
Privy: Envisioning and Mitigating Privacy Risks for Consumer-facing AI Product Concepts
CHI '26· Explainable AI (XAI) +2
- 86%
From Fragmentation to Integration: Exploring the Design Space of AI Agents for Human-as-the-Unit Privacy Management
CHI '26· Privacy by Design & User Control +3
- 86%
Privacy Control in Conversational LLM Platforms: A Walkthrough Study
CHI '26· Explainable AI (XAI) +3
- 83%
Beyond PII: How Users Attempt to Estimate and Mitigate Implicit LLM Inference
CHI '26· Explainable AI (XAI) +2
- 75%
PrivacyAkinator: Articulating Key Privacy Design Decisions by Answering LLM-Generated Multiple-choice Questions
CHI '26· Explainable AI (XAI) +3
- 71%
Understanding Challenges for Developers to Create Accurate Privacy Nutrition Labels
CHI '22· Privacy by Design & User Control +1
- 71%
Mind the Gap: Mapping Wearer–Bystander Privacy Tensions and Context-Adaptive Pathways for Camera Glasses
CHI '26· Privacy by Design & User Control +2
- 71%
Supporting Informed Self-Disclosure: Design Recommendations for Presenting AI-Estimates of Privacy Risks to Users
CHI '26· Privacy by Design & User Control +2
- 71%
The Nuances of Creepiness: A Systematic Literature Review of Creepy Technology
CHI '26· Technology Ethics & Critical HCI +2
Based on Jaccard similarity of research subtopics & professions (≥60%)