Investigating Deceptive Design in GDPR's Legitimate Interest
Authors
Document Title
Investigating Deceptive Design in GDPR’s Legitimate Interest
Document Information
- Subject Area: Data Protection and Privacy Design, Compliance Studies
- Keywords: Deceptive Design, Dark Patterns, GDPR, Consent, Privacy Notice, Legitimate Interest, Human-Computer Interaction
Research Background and Issues
-
What problems or challenges did the authors identify?
- The provision for Legitimate Interests in GDPR is flexible yet ambiguous, potentially creating loopholes for data collection.
- Data controllers may exploit deceptive designs in privacy notices to misuse the legitimate interest basis, leading to passive data collection from users.
- There is a lack of robust legal enforcement and systematic studies on privacy notice practices.
-
Why is this issue important?
- The legitimate interest basis enables personal data processing without requiring explicit user consent, making it harder for users to detect and manage their privacy preferences.
- Lack of transparency may infringe on users' rights to personal data protection, undermining the legitimacy and effectiveness of GDPR.
-
Research Motivation and Related Work
- Practicality of contract enforcement and user consent has been widely studied, but the application of legitimate interests remains underexplored.
- Other related work has revealed dark patterns in privacy notices, but few have focused on the implementation of legitimate interests.
Solutions
-
What methods or solutions did the authors propose?
- Two studies were conducted to evaluate the practical application of GDPR’s legitimate interests and users’ understanding and perception of these practices:
- Using a web crawler to analyze privacy notices from 10,000 websites, identifying deceptive designs related to legitimate interests.
- Conducting a survey with 400 participants to understand users’ perceptions of legitimate interests and associated data collection purposes.
- Two studies were conducted to evaluate the practical application of GDPR’s legitimate interests and users’ understanding and perception of these practices:
-
What is innovative about this solution?
- It bridges theory and practice, revealing discrepancies between deceptive designs in legitimate interests and user perceptions for the first time.
- Offers design and legal recommendations for improvement.
-
What are the implementation steps and key technologies used?
- First Experiment: Developed a web crawler to analyze whether top websites mention legitimate interests in their privacy notices and assess the UI or language design of these notices.
- Second Experiment: Designed a questionnaire to survey users’ attitudes toward legitimate interest data collection purposes and analyze factors influencing their acceptance of data collection.
- Statistical analysis and content analysis methods were employed to extract results.
Research Findings
-
What specific findings were obtained?
- Legitimate Interest Practices:
- Disclosure rates of legitimate interests in privacy notices were low, with only 4.74% of websites mentioning them.
- Six types of deceptive designs were identified, including UI complexity, language ambiguity, and lack of unified management options.
- User Perception:
- Users generally perceived legitimate interests as serving the interests of website providers and third-party advertisers rather than their own.
- Users were most resistant to purposes like personalized ads and content, while they were more accepting of purposes such as security, debugging, and fraud detection.
- Legitimate Interest Practices:
-
How does it compare to existing solutions?
- Provides a practical evaluation of legitimate interest usage and its legal assessment.
- Offers specific policy recommendations and design improvements applicable to privacy notice UI and language design.
-
What were the experimental or evaluation results?
- Implementation of legitimate interests often involves deceptive designs, such as mixing legitimate interests with user consent toggles.
- Users’ acceptance of data collection purposes is primarily influenced by perceived benefits, with users more willing to accept purposes that provide personal or societal benefits.
-
Limitations and Future Directions
- Limitations:
- The web crawler analyzed only English websites, which may not represent all EU language contexts.
- Survey participants were predominantly younger, potentially not reflecting the views of the general user population.
- Some users had misconceptions about the concept of legitimate interests.
- Future Directions:
- Expand the sample size and language scope of the study.
- Explore ways to enhance transparency in legitimate interest practices and involve users in policy-making.
- Investigate the impact of automated privacy management tools (e.g., browser-level settings) on reducing deceptive designs.
- Limitations:
Conclusion
- The legitimate interest basis in GDPR has significant potential but is often accompanied by deceptive designs and insufficient legal oversight.
- Users find current privacy notice designs confusing, with many data collection purposes misaligned with their preferences.
- Strengthening GDPR enforcement, improving privacy notice design standards, and incorporating user feedback are essential to optimizing data protection policies.
Research Questions / Practical Problems
Question signals indexed for this paper.
Research Questions
3- Can GDPR legitimate interest provisions be easily exploited by data controllers to implement deceptive design?Category: Privacy Policy, Notice, and Terms ComprehensionSimilar questionsarrow_forward
- How do users understand and perceive data collection behaviors that rely on legitimate interest provisions?Category: Privacy Policy, Notice, and Terms ComprehensionSimilar questionsarrow_forward
- Which design features in privacy notices prevent users from effectively managing privacy preferences?Category: Privacy Policy, Notice, and Terms ComprehensionSimilar questionsarrow_forward
Practical Problems
1- Users struggle to understand and manage data collection under legitimate interest provisions.Category: Research Method Practice, Coding Workflows, and Design Research ReflectionSimilar questionsarrow_forward
- 80%
Dark Patterns in the Opt-Out Process and Compliance with the California Consumer Privacy Act (CCPA)
CHI '25· Privacy by Design & User Control +1
- 67%
A Cross-Country Analysis of GDPR Cookie Banners and Flexible Methods for Scraping Them
CHI '25· Algorithmic Transparency & Auditability +2
- 67%
A Data-Driven Approach to Developing IoT Privacy-Setting Interfaces
IUI '18· Algorithmic Transparency & Auditability +2
- 60%
Defining and Identifying Attention Capture Deceptive Designs in Digital Interfaces
CHI '23· Dark Patterns Recognition
Based on Jaccard similarity of research subtopics & professions (≥60%)