Understanding User Needs Underlying the Expected Roles of LLM-Based Chatbots in Privacy Decision-Making

Explainable AI (XAI)Privacy by Design & User ControlPrivacy Perception & Decision-MakingUI/UX DesignersPrivacy Policy MakersAI/ML Researchers & Engineers

Paper Title

Understanding User Needs Underlying the Expected Roles of LLM-Based Chatbots in Privacy Decision-Making

Publication Info

  • Topic area: User expectations and roles of LLM-based chatbots in privacy decision-making.
  • Keywords: LLM-based chatbots, privacy decision-making, notice and choice, user needs, privacy policies, ethical considerations, role-based design, user expectations, privacy governance, AI in privacy.

Background and Problem

  • Problem / challenge: Privacy policies are lengthy, complex, and ambiguous, leading users to ignore them and make uninformed decisions. Current tools for improving privacy policy comprehension lack interactivity and fail to address user-specific needs or provide actionable guidance.
  • Significance: Enhancing privacy decision-making is critical as users frequently interact with digital services requiring personal data disclosure. Effective tools could empower users to make informed privacy choices and mitigate risks.
  • Motivation and related work: Prior efforts, such as summarization tools and conversational interfaces, improved privacy policy comprehension but were limited by one-way communication and technical challenges (e.g., hallucinations in LLMs). This study addresses the gap in understanding user expectations and unmet needs for LLM-based chatbots in privacy contexts.

Solution

  • Proposed approach: Investigate user expectations and needs for LLM-based chatbots in privacy decision-making through a technology probe, focus groups, and expert interviews.
  • Novelty:
    1. Identification of three user-expected roles for LLM-based chatbots: Interpreter, Guardian, and Evaluator.
    2. Analysis of satisfied and unmet user needs within these roles, enriched with expert perspectives.
    3. Role-based practical implications for deploying LLM-based chatbots responsibly in privacy decision-making.
  • Procedure and key techniques:
    • Conducted a study with 16 participants using a fictional fitness tracking service and an LLM-based chatbot (GPT-4).
    • Explored user interactions with the chatbot and their expectations through focus groups.
    • Complemented findings with insights from three privacy experts.
    • Thematically analyzed user prompts and needs, categorizing them into three roles and 11 prompting strategies.

Results

  • Concrete findings:
    • Users expect LLM-based chatbots to act as:
      1. Interpreter: Summarizing and clarifying privacy policies.
      2. Guardian: Identifying risks and providing actionable guidance.
      3. Evaluator: Assisting in privacy judgments and aligning policies with personal criteria.
    • 11 user strategies were identified, with 53 prompts for the Interpreter role, 25 for the Guardian role, and 36 for the Evaluator role.
    • Key unmet needs include concise summaries, proactive risk evaluations, and actionable guidance for managing privacy risks.
  • Advantage over baselines: LLM-based chatbots offer interactive and personalized responses compared to static tools, but their limitations (e.g., hallucinations, vague responses) hinder full effectiveness.
  • Experiments / evaluation:
    • Participants interacted with a chatbot integrated into a fictional privacy policy scenario.
    • Focus groups and expert interviews provided qualitative insights into user needs and ethical considerations.
  • Limitations and future work:
    • Limited to South Korean participants aged 19–26; broader demographics are needed for generalizability.
    • Findings based on GPT-4; newer models may address some limitations.
    • Study context focused on a single fictional service; real-world applications and diverse scenarios require further investigation.

Summary

This study identifies three roles—Interpreter, Guardian, and Evaluator—that users expect from LLM-based chatbots in privacy decision-making, along with 11 prompting strategies. While chatbots effectively support comprehension and engagement, unmet needs include concise summaries, actionable guidance, and proactive risk evaluations. Expert insights highlight ethical risks, such as hallucinations and data exposure, and suggest role-based hybrid architectures combining deterministic and LLM-based approaches. The findings underscore the limitations of the notice and choice framework, advocating for structural reforms to better support rational privacy decision-making.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/222391/2026

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://doi.org/10.1145/3772318.3790981
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2026
emoji_events
Award
No award tagged
group
Authors
4 authors
sell
Subtopics
Explainable AI (XAI), Privacy by Design & User Control, Privacy Perception & Decision-Making
work
Professions
UI/UX Designers, Privacy Policy Makers, AI/ML Researchers & Engineers
article
Content Status
Full text indexed
hub
Related Papers
10 related papers