Playing with Privacy: Uncovering Everyday Judgments of Data Sensitivity Through an Arcade Machine Interface
Authors
Current data protection legal frameworks, including the GDPR, classify “special” categories of personal data that are deemed deserving of higher protection due to their impact on fundamental rights. Yet, these legal abstractions fail to capture how individuals themselves judge sensitivity in everyday digital contexts. This disconnect may undermine intelligibility and erode trust in data protection as a legal institution. Despite its centrality to privacy protection, limited empirical work has systematically compared public sensitivity judgments against the special categories of protected data under Article 9 GDPR. We address this gap through a mixed-methods design that integrates nine semi-structured interviews with a game-like survey deployed on public arcade machines. This approach generated 2,935 responses from 224 participants enabling in-situ analysis of everyday judgments. By operationalising an ontology capturing who collects data, what data are collected, and for what purpose, we systematically compared responses across demographic groups. Contrary to literature assumptions that health and financial data are primary markers of data sensitivity, our findings demonstrate that expressive content, messages, photos, and social ties elicited the strongest resistance to sharing by citizens. Acceptance was shaped decisively by purpose. Citizens tolerated safety and functionality, whilst advertising and vague claims of “research” were rejected. Attitudes varied systematically, with women disproportionately resistant to sharing expressive content, and higher education and digital literacy predicting greater caution. This study demonstrates that data sensitivity cannot be reduced to fixed legal categories. Rather, it is socially situated and purpose-dependent. Our findings provide empirical foundations for reimagining consent flows, privacy defaults, and transparency mechanisms that align with everyday logics. This can enable the development of systems that people can genuinely understand, trust, and consent to.
Research Questions / Practical Problems
Question signals indexed for this paper.
- 71%
Bringing Design to the Privacy Table: Broadening
CHI '19· Privacy by Design & User Control +2
- 63%
From Clicks to Consensus: Collective Consent Assemblies for Data Governance
CHI '26· AI-Assisted Decision-Making & Automation +2
Based on Jaccard similarity of research subtopics & professions (≥60%)