Jurisdiction as Structural Barrier: How Privacy Policy Organization May Reduce Visibility of Substantive Disclosures
This paper identifies and analyzes "jurisdiction-siloed disclosure," a structural pattern in privacy policies where substantive data practice details are hidden within regional compliance sections rather than the main body, thereby reducing visibility for users outside regulated jurisdictions and proposing a universal disclosure standard to ensure material information reaches all affected parties.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
The Big Idea: The "Hidden Menu" Problem
Imagine you walk into a restaurant to order dinner. You pick up the menu, which is supposed to tell you exactly what the kitchen is doing with your food.
- The General Menu: The main part of the menu lists "We use fresh ingredients" and "We might share your order with the chef." It's vague and safe.
- The "California" Section: At the very back, there is a small, separate page titled "California Residents Only." If you flip to that page, you see a bold, specific warning: "We sell your personal data to advertisers."
If you live in Ohio, you see the "California Residents Only" header, think, "That's not for me," and skip that page. You go home thinking, "Oh, they just share my data with the chef." You never learn that they are actually selling your data.
This is exactly what the paper calls "Jurisdiction-Siloed Disclosure."
The author, Thomas Brackin, argues that many big companies (like Google, Meta, Amazon, and others) are hiding their most important, specific secrets about what they do with your data inside sections labeled for specific places (like "California," "EU/UK," or "Illinois"). If you don't live in those places, you likely skip those sections, leaving you in the dark about practices that actually affect you, too.
How They Found This (The Audit)
The researcher looked at the privacy policies of 123 major companies. He didn't just read them; he used a smart computer system (AI) to act like a detective, looking for a specific pattern:
- The Trap: Does the company say something vague in the main text (e.g., "We might share info")?
- The Reveal: Does the company say something very specific and concrete in a regional section (e.g., "We sell your biometric data")?
The Results:
- They found this "hiding" pattern in 77 out of 123 companies (about 62%).
- They found 282 specific examples of this happening.
- Even if we only count the most certain, proven examples, it still happens in 44% of the companies.
Why This Matters: The "Scent" of Information
The paper uses a theory called Information Foraging. Think of it like a dog hunting for food.
- Dogs follow a "scent." If a scent is strong, they follow it. If the scent says "This is for a different dog," they stop.
- Humans do the same with websites. We scan headings. If we see a heading that says "Your California Privacy Rights," our brain says, "I am not in California. That scent is irrelevant. I will skip it."
The paper argues that companies are relying on this behavior. They put the scary, specific truths in the "California" section, knowing that a user in Texas will skip it. The company isn't lying (the truth is there), but they are hiding it in a place you are trained to ignore.
The Proposed Solution: "Universal Substantive Disclosure"
The author suggests a new rule for how privacy policies should be written. He calls it Universal Substantive Disclosure.
Think of it like a Nutrition Label on a box of cereal.
- Current System: The label says "Contains Sugar" in the main box, but the exact amount of sugar is only listed on a tiny sticker in the back that says "For California Residents."
- Proposed System: The main box must say "Contains 15g of Sugar" for everyone. The back sticker can then just say, "California residents can ask for a refund if they don't like the sugar."
The Rule:
- What they DO (The Facts): If a company sells your data, collects your face scan, or uses AI to make decisions, they must say this clearly in the main part of the policy for everyone to see.
- How you FIX it (The Rights): The regional sections should only contain the "how-to" instructions for people in that specific place (e.g., "Here is the link to opt-out if you live in California").
Real-World Examples from the Paper
The paper gives five specific stories (case studies) to show how this works:
- Clearview AI (Facial Recognition): The main policy uses fancy, confusing words like "face vector data." But the "Illinois" section explicitly says, "We collect biometric data." If you aren't in Illinois, you miss the word "biometric" and don't realize they are scanning your face.
- Grindr (Dating App): The main text says, "We might collect sensitive data in some places." The California section says, "Yes, we collect your sexual orientation and location." A user in Ohio misses the confirmation that their data is being collected.
- Roblox (Gaming): The main text says, "We personalize ads." The "EU" section says, "We use partner data to decide which ads to show you and track if they work." A child in the US misses the detail that their data is being shared with partners.
- Thomson Reuters (Data Company): The main text says, "We might sell data under some laws." The California section says, "We do sell data across 10 categories."
- Northrop Grumman (Defense): The US section says, "We don't use AI to make hiring decisions." The EU section says, "We do use AI to rank candidates."
What the Author is NOT Saying
It is important to stick to what the paper actually claims:
- It is not saying companies are doing this on purpose to trick you. The author suggests companies are just following legal templates that tell them to put California laws in a California box. It's a structural mistake, not necessarily a malicious one.
- It is not saying this happens to every website on the internet. They only checked 123 big, famous companies.
- It is not saying they have measured exactly how many people skip these sections. They are using existing research (which says people skip things they think are irrelevant) to predict that people would skip them. They are asking for more studies to prove this behavior.
The Bottom Line
The paper argues that transparency isn't just about having the information; it's about where you put it.
If a company puts the truth in a box labeled "Not for You," and you skip that box, the company has technically told the truth, but they have failed to give you notice. The author wants a rule that says: "If a practice affects everyone, the truth about that practice must be told to everyone, right at the front of the door."
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.