Playing with Privacy: Uncovering Everyday Judgments of Data Sensitivity Through an Arcade Machine Interface

Privacy by Design & User ControlPrivacy Perception & Decision-MakingParticipatory DesignUser Research Methods (Interviews, Surveys, Observation)Privacy Policy MakersHCI ResearchersSociologists & Anthropologists

Current data protection legal frameworks, including the GDPR, classify “special” categories of personal data that are deemed deserving of higher protection due to their impact on fundamental rights. Yet, these legal abstractions fail to capture how individuals themselves judge sensitivity in everyday digital contexts. This disconnect may undermine intelligibility and erode trust in data protection as a legal institution. Despite its centrality to privacy protection, limited empirical work has systematically compared public sensitivity judgments against the special categories of protected data under Article 9 GDPR. We address this gap through a mixed-methods design that integrates nine semi-structured interviews with a game-like survey deployed on public arcade machines. This approach generated 2,935 responses from 224 participants enabling in-situ analysis of everyday judgments. By operationalising an ontology capturing who collects data, what data are collected, and for what purpose, we systematically compared responses across demographic groups. Contrary to literature assumptions that health and financial data are primary markers of data sensitivity, our findings demonstrate that expressive content, messages, photos, and social ties elicited the strongest resistance to sharing by citizens. Acceptance was shaped decisively by purpose. Citizens tolerated safety and functionality, whilst advertising and vague claims of “research” were rejected. Attitudes varied systematically, with women disproportionately resistant to sharing expressive content, and higher education and digital literacy predicting greater caution. This study demonstrates that data sensitivity cannot be reduced to fixed legal categories. Rather, it is socially situated and purpose-dependent. Our findings provide empirical foundations for reimagining consent flows, privacy defaults, and transparency mechanisms that align with everyday logics. This can enable the development of systems that people can genuinely understand, trust, and consent to.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/iui/226653/2026

AdRecommended

Learn AI Coding at CodeNow

At a Glance

Paper Snapshot

fact_check
dataset
Source
IUI
calendar_month
Year
2026
emoji_events
Award
No award tagged
group
Authors
8 authors
sell
Subtopics
Privacy by Design & User Control, Privacy Perception & Decision-Making, Participatory Design, User Research Methods (Interviews, Surveys, Observation)
work
Professions
Privacy Policy Makers, HCI Researchers, Sociologists & Anthropologists
article
Content Status
Abstract only
hub
Related Papers
2 related papers