SlideShare a Scribd company logo
Informed Consent: Are Your
Participants Aware of
What They Share?
Noreen Whysel
Director of Validation Research
Internet Safety Labs
August 7-9, 2022
SOUPS 2022: Eighteenth Symposium on
Usable Privacy and Security
Informed
Consent
Form
10 Attributes
of Respectful
Me2B Commit
ments
Source: 10 Attributes of Respectful Me2B Commitments https://me2ba.org/flash-guide-9-the-10-
attributes-of-respectful-me2b-commitments/
Data Privacy Risks in
User Testing Software
What Are the
Risks of All
This Data
Sharing?
Participant
• Lack of Sufficient Notice
• Lack of Consent
Researcher
• Data Privacy Legal Violations
• Trust
User Testing Platform
• Data Privacy Legal Violations
• Trust
ISL Safe Software Audit
ISL Safe
Usability
Software
Mini Audit
6
Google
2
Microsoft/
Bing
2
Amazon
5
Vendors
1
Facebook
0
Twitter
Underlying
Technologies
Tracking and
Sharing User
Data
Ada
Appcues
Azure.com
Bing Ads
Bugsnag
Cloudflare
cloudfront.net (Amazon)
Cookielaw.org
Datadog Tracker
Doubleclick.net
Drift.com
Facebook.com
Facebook.net
Google.com
Googleapis.com
Google-analytics.com
Google Adwords
Google Adsense
Google Dynamic
Remarketing
Google Fonts
Google Play
GoogleTagManager.com
Gstatic.com
Hubspot
Jqyuery.com
Klaro
licdn.com (LinkedIn)
Linkedin.com
Microsoft.com
Mixpanel via mxpnl.com
NewRelic.com
nr-data.net
Office.net
Office.com
Pendo
Rollbar
Segment
Sentry
Snowplow
sp
Smassets.net
Stathat.com
Stripe
Surveymonkey.com
app.usabilityhub.com
UserInterviews.com
Windows.net
Zendesk
Zendesk Tracker
_ga
_gid
_sp_id
_sp_ses
Google
Forms and
Microsoft
Source: Tracker Map https://www.crownpeak.com/products/tag-monitoring-and-management
Source: Google Forms
Google
Forms and
SurveySwap
Google
Forms vs
Survey
Swap
Source: Tracker Map https://www.crownpeak.com/products/tag-monitoring-and-management
Google Forms
1 Tracker
0 Ad Networks
2 Widgets (Google)
SurveySwap.io
3 Trackers
4 Ad Networks
1 Analytics (Google)
3 Widgets (incl
Google Tag Manager)
Usability Hub
Usability Test
2 Trackers
1 Ad Network
1 Widget (Google Fonts)
1 Analytics (Google)
Usability Hub
First Click Test
2 Trackers
1 Ad Network
1 Widget (Google Fonts)
1 Analytics (Google)
Optimal Workshop
Tree Test
2 Trackers
1 Ad Network
1 Widget (Google Tag
Manager)
1 Analytics (Google)
Optimal Workshop
Card Sort
4 Trackers
1 Ad Network
1 Widget (Google Tag
Manager)
1 Analytics (Google)
Usability Tests
Source: Tracker Map https://www.crownpeak.com/products/tag-monitoring-and-management
TypeForm Form
0 Trackers
0 Ad Networks
1 Widget (first party)
0 Analytics
SurveyMonkey
0 Trackers
0 Ad Networks
1 Widget (Google Tag Manager)
1 Analytics (New Relic)
Survey Software
Source: Tracker Map https://www.crownpeak.com/products/tag-monitoring-and-management
Source: Tracker Map https://www.crownpeak.com/products/tag-monitoring-and-management
UserInterviews
5 Trackers (incl Facebook, Google and Microsoft
ad trackers)
3 Ad Networks (Bing, Facebook, Doubleclick)
7 Widgets (incl Google Tag Manager)
2 Analytics (Google Analytics, Mix Panel)
Prolific.io
3 Trackers (All
0 Ad Network
2 Widgets (incl Zendesk)
1 Analytics (Google Users)
What Can You Do Now?
What Can
Researchers
Do?
• Provide clear notice and consent
• Highlight any potentially hidden data sharing
by the testing software
• Name the software or testing platforms so
participants can read and consent to their
policies
What Can
User Testing
Software
Platforms
Do?
• Understand your data protection
responsibilities
• Make a greater effort to inform
participants and researchers of your
data sharing policy–every time they use
your software
Thank You!
Noreen Whysel
Director of Validation Research
Internet Safety Labs (formerly
the Me2B Alliance)
Noreen.whysel@internetsafetylabs.org
https://www.internetsafetylabs.org
https://www.me2ba.org

More Related Content

Similar to Informed Consent-Are Your Participants-Aware-o- What-They-Share.pptx

Introduction to Digital Analytics for Apps - Trusted Conf
Introduction to Digital Analytics for Apps - Trusted ConfIntroduction to Digital Analytics for Apps - Trusted Conf
Introduction to Digital Analytics for Apps - Trusted Conf
In Marketing We Trust
 
Tag.bio aws public jun 08 2021
Tag.bio aws public jun 08 2021 Tag.bio aws public jun 08 2021
Tag.bio aws public jun 08 2021
Sanjay Padhi, Ph.D
 
Building a Marketing Data Warehouse from Scratch - SMX Advanced 202
Building a Marketing Data Warehouse from Scratch - SMX Advanced 202Building a Marketing Data Warehouse from Scratch - SMX Advanced 202
Building a Marketing Data Warehouse from Scratch - SMX Advanced 202
Christopher Gutknecht
 
User Research Fast & Cheap
User Research Fast & Cheap User Research Fast & Cheap
User Research Fast & Cheap
John H Douglass
 
Making Web Analytics actionable with Web Content Management
Making Web Analytics actionable with Web Content ManagementMaking Web Analytics actionable with Web Content Management
Making Web Analytics actionable with Web Content Management
Amplexor
 
EventLogging Workshop
EventLogging WorkshopEventLogging Workshop
EventLogging Workshop
Dario Taraborelli
 
Analytics, data science, & artificial intelligencesy
Analytics, data science, & artificial intelligencesyAnalytics, data science, & artificial intelligencesy
Analytics, data science, & artificial intelligencesy
honey725342
 
Run more experiments with fewer resources
Run more experiments with fewer resourcesRun more experiments with fewer resources
Run more experiments with fewer resources
VWO
 
VWO - Mark de Winter - Run more experiments with fewer resources.pdf
VWO - Mark de Winter - Run more experiments with fewer resources.pdfVWO - Mark de Winter - Run more experiments with fewer resources.pdf
VWO - Mark de Winter - Run more experiments with fewer resources.pdf
VWO
 
Digital media analytics: web, mobile analytics - Ahmad Abdullah - Google
Digital media analytics: web, mobile analytics - Ahmad Abdullah - GoogleDigital media analytics: web, mobile analytics - Ahmad Abdullah - Google
Digital media analytics: web, mobile analytics - Ahmad Abdullah - Google
Jigserv Digital
 
MITRE-Module 1 Slides.pdf
MITRE-Module 1 Slides.pdfMITRE-Module 1 Slides.pdf
MITRE-Module 1 Slides.pdf
ReZa AdineH
 
Cookies tracking and pixels
Cookies tracking and pixelsCookies tracking and pixels
Cookies tracking and pixels
Julien Kervizic
 
Creating Your Own Technology Plan Toledo
Creating Your Own Technology Plan   ToledoCreating Your Own Technology Plan   Toledo
Creating Your Own Technology Plan Toledo
Michigan Nonprofit Association
 
AppInspect: Large-scale Evaluation of Social Networking Apps
AppInspect: Large-scale Evaluation of Social Networking AppsAppInspect: Large-scale Evaluation of Social Networking Apps
AppInspect: Large-scale Evaluation of Social Networking Apps
Markus Huber
 
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
TrustArc
 
FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...
FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...
FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...
Black Duck by Synopsys
 
Search Engine Visibility 2013
Search Engine Visibility 2013Search Engine Visibility 2013
Search Engine Visibility 2013gidgreen
 
Piwik: An Analytics Alternative (Chicago Summit)
Piwik: An Analytics Alternative (Chicago Summit)Piwik: An Analytics Alternative (Chicago Summit)
Piwik: An Analytics Alternative (Chicago Summit)Open Analytics
 
ALT-F1 Techtalk 3 - Google AppEngine
ALT-F1 Techtalk 3 - Google AppEngineALT-F1 Techtalk 3 - Google AppEngine
ALT-F1 Techtalk 3 - Google AppEngine
Abdelkrim Boujraf
 

Similar to Informed Consent-Are Your Participants-Aware-o- What-They-Share.pptx (20)

2011 NASA Open Source Summit - Forge.mil
2011 NASA Open Source Summit - Forge.mil2011 NASA Open Source Summit - Forge.mil
2011 NASA Open Source Summit - Forge.mil
 
Introduction to Digital Analytics for Apps - Trusted Conf
Introduction to Digital Analytics for Apps - Trusted ConfIntroduction to Digital Analytics for Apps - Trusted Conf
Introduction to Digital Analytics for Apps - Trusted Conf
 
Tag.bio aws public jun 08 2021
Tag.bio aws public jun 08 2021 Tag.bio aws public jun 08 2021
Tag.bio aws public jun 08 2021
 
Building a Marketing Data Warehouse from Scratch - SMX Advanced 202
Building a Marketing Data Warehouse from Scratch - SMX Advanced 202Building a Marketing Data Warehouse from Scratch - SMX Advanced 202
Building a Marketing Data Warehouse from Scratch - SMX Advanced 202
 
User Research Fast & Cheap
User Research Fast & Cheap User Research Fast & Cheap
User Research Fast & Cheap
 
Making Web Analytics actionable with Web Content Management
Making Web Analytics actionable with Web Content ManagementMaking Web Analytics actionable with Web Content Management
Making Web Analytics actionable with Web Content Management
 
EventLogging Workshop
EventLogging WorkshopEventLogging Workshop
EventLogging Workshop
 
Analytics, data science, & artificial intelligencesy
Analytics, data science, & artificial intelligencesyAnalytics, data science, & artificial intelligencesy
Analytics, data science, & artificial intelligencesy
 
Run more experiments with fewer resources
Run more experiments with fewer resourcesRun more experiments with fewer resources
Run more experiments with fewer resources
 
VWO - Mark de Winter - Run more experiments with fewer resources.pdf
VWO - Mark de Winter - Run more experiments with fewer resources.pdfVWO - Mark de Winter - Run more experiments with fewer resources.pdf
VWO - Mark de Winter - Run more experiments with fewer resources.pdf
 
Digital media analytics: web, mobile analytics - Ahmad Abdullah - Google
Digital media analytics: web, mobile analytics - Ahmad Abdullah - GoogleDigital media analytics: web, mobile analytics - Ahmad Abdullah - Google
Digital media analytics: web, mobile analytics - Ahmad Abdullah - Google
 
MITRE-Module 1 Slides.pdf
MITRE-Module 1 Slides.pdfMITRE-Module 1 Slides.pdf
MITRE-Module 1 Slides.pdf
 
Cookies tracking and pixels
Cookies tracking and pixelsCookies tracking and pixels
Cookies tracking and pixels
 
Creating Your Own Technology Plan Toledo
Creating Your Own Technology Plan   ToledoCreating Your Own Technology Plan   Toledo
Creating Your Own Technology Plan Toledo
 
AppInspect: Large-scale Evaluation of Social Networking Apps
AppInspect: Large-scale Evaluation of Social Networking AppsAppInspect: Large-scale Evaluation of Social Networking Apps
AppInspect: Large-scale Evaluation of Social Networking Apps
 
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
 
FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...
FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...
FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...
 
Search Engine Visibility 2013
Search Engine Visibility 2013Search Engine Visibility 2013
Search Engine Visibility 2013
 
Piwik: An Analytics Alternative (Chicago Summit)
Piwik: An Analytics Alternative (Chicago Summit)Piwik: An Analytics Alternative (Chicago Summit)
Piwik: An Analytics Alternative (Chicago Summit)
 
ALT-F1 Techtalk 3 - Google AppEngine
ALT-F1 Techtalk 3 - Google AppEngineALT-F1 Techtalk 3 - Google AppEngine
ALT-F1 Techtalk 3 - Google AppEngine
 

More from Noreen Whysel

User Experience Research: Deriving Insights for Customer Development
User Experience Research: Deriving Insights for Customer DevelopmentUser Experience Research: Deriving Insights for Customer Development
User Experience Research: Deriving Insights for Customer Development
Noreen Whysel
 
IAC22 Safe Tech Audit Presentation Noreen Whysel.pptx
IAC22 Safe Tech Audit Presentation Noreen Whysel.pptxIAC22 Safe Tech Audit Presentation Noreen Whysel.pptx
IAC22 Safe Tech Audit Presentation Noreen Whysel.pptx
Noreen Whysel
 
IAC21: Shedding Light on Dark Patterns.pdf
IAC21: Shedding Light on Dark Patterns.pdfIAC21: Shedding Light on Dark Patterns.pdf
IAC21: Shedding Light on Dark Patterns.pdf
Noreen Whysel
 
Consumer Views on Respectful Technology.pdf
Consumer Views on Respectful Technology.pdfConsumer Views on Respectful Technology.pdf
Consumer Views on Respectful Technology.pdf
Noreen Whysel
 
Information architecture for science gateways
Information architecture for science gatewaysInformation architecture for science gateways
Information architecture for science gateways
Noreen Whysel
 
How to Create and Maintain an Effective Information Architecture and Navigati...
How to Create and Maintain an Effective Information Architecture and Navigati...How to Create and Maintain an Effective Information Architecture and Navigati...
How to Create and Maintain an Effective Information Architecture and Navigati...
Noreen Whysel
 
Shaping the Future of Trusted Digital Identity
Shaping the Future of Trusted Digital IdentityShaping the Future of Trusted Digital Identity
Shaping the Future of Trusted Digital Identity
Noreen Whysel
 
Trust and inclusion
Trust and inclusionTrust and inclusion
Trust and inclusion
Noreen Whysel
 
Finding Empathy for Your Future Self: UX User Researchers Meetup April 4, 2018
Finding Empathy for Your Future Self: UX User Researchers Meetup April 4, 2018Finding Empathy for Your Future Self: UX User Researchers Meetup April 4, 2018
Finding Empathy for Your Future Self: UX User Researchers Meetup April 4, 2018
Noreen Whysel
 
Kantara Orientation for CARIN Digital ID Summit
Kantara Orientation for CARIN Digital ID SummitKantara Orientation for CARIN Digital ID Summit
Kantara Orientation for CARIN Digital ID Summit
Noreen Whysel
 
Preserving Performance at DHWEEK 2018
Preserving Performance at DHWEEK 2018Preserving Performance at DHWEEK 2018
Preserving Performance at DHWEEK 2018
Noreen Whysel
 
Journey App: Empathy Jam 2017 Hackathon Entry
Journey App: Empathy Jam 2017 Hackathon EntryJourney App: Empathy Jam 2017 Hackathon Entry
Journey App: Empathy Jam 2017 Hackathon Entry
Noreen Whysel
 
SLP 2018 Customer Development
SLP 2018 Customer DevelopmentSLP 2018 Customer Development
SLP 2018 Customer Development
Noreen Whysel
 
Dreams, resilience and making a difference
Dreams, resilience and making a differenceDreams, resilience and making a difference
Dreams, resilience and making a difference
Noreen Whysel
 
Diversity and Inclusion in Wikipedia
Diversity and Inclusion in WikipediaDiversity and Inclusion in Wikipedia
Diversity and Inclusion in Wikipedia
Noreen Whysel
 
IA Wikipedia Edit-a-thon
IA Wikipedia Edit-a-thonIA Wikipedia Edit-a-thon
IA Wikipedia Edit-a-thon
Noreen Whysel
 
Creating a Collaborative Learning Gateway
Creating a Collaborative Learning GatewayCreating a Collaborative Learning Gateway
Creating a Collaborative Learning Gateway
Noreen Whysel
 
Prelude 16: Preserving Performance
Prelude 16: Preserving PerformancePrelude 16: Preserving Performance
Prelude 16: Preserving Performance
Noreen Whysel
 
Mentoring Women in Open Source
Mentoring Women in Open SourceMentoring Women in Open Source
Mentoring Women in Open Source
Noreen Whysel
 
Pinterest as Digital Archive, IA Summit 2016, Atlanta
Pinterest as Digital Archive, IA Summit 2016, AtlantaPinterest as Digital Archive, IA Summit 2016, Atlanta
Pinterest as Digital Archive, IA Summit 2016, Atlanta
Noreen Whysel
 

More from Noreen Whysel (20)

User Experience Research: Deriving Insights for Customer Development
User Experience Research: Deriving Insights for Customer DevelopmentUser Experience Research: Deriving Insights for Customer Development
User Experience Research: Deriving Insights for Customer Development
 
IAC22 Safe Tech Audit Presentation Noreen Whysel.pptx
IAC22 Safe Tech Audit Presentation Noreen Whysel.pptxIAC22 Safe Tech Audit Presentation Noreen Whysel.pptx
IAC22 Safe Tech Audit Presentation Noreen Whysel.pptx
 
IAC21: Shedding Light on Dark Patterns.pdf
IAC21: Shedding Light on Dark Patterns.pdfIAC21: Shedding Light on Dark Patterns.pdf
IAC21: Shedding Light on Dark Patterns.pdf
 
Consumer Views on Respectful Technology.pdf
Consumer Views on Respectful Technology.pdfConsumer Views on Respectful Technology.pdf
Consumer Views on Respectful Technology.pdf
 
Information architecture for science gateways
Information architecture for science gatewaysInformation architecture for science gateways
Information architecture for science gateways
 
How to Create and Maintain an Effective Information Architecture and Navigati...
How to Create and Maintain an Effective Information Architecture and Navigati...How to Create and Maintain an Effective Information Architecture and Navigati...
How to Create and Maintain an Effective Information Architecture and Navigati...
 
Shaping the Future of Trusted Digital Identity
Shaping the Future of Trusted Digital IdentityShaping the Future of Trusted Digital Identity
Shaping the Future of Trusted Digital Identity
 
Trust and inclusion
Trust and inclusionTrust and inclusion
Trust and inclusion
 
Finding Empathy for Your Future Self: UX User Researchers Meetup April 4, 2018
Finding Empathy for Your Future Self: UX User Researchers Meetup April 4, 2018Finding Empathy for Your Future Self: UX User Researchers Meetup April 4, 2018
Finding Empathy for Your Future Self: UX User Researchers Meetup April 4, 2018
 
Kantara Orientation for CARIN Digital ID Summit
Kantara Orientation for CARIN Digital ID SummitKantara Orientation for CARIN Digital ID Summit
Kantara Orientation for CARIN Digital ID Summit
 
Preserving Performance at DHWEEK 2018
Preserving Performance at DHWEEK 2018Preserving Performance at DHWEEK 2018
Preserving Performance at DHWEEK 2018
 
Journey App: Empathy Jam 2017 Hackathon Entry
Journey App: Empathy Jam 2017 Hackathon EntryJourney App: Empathy Jam 2017 Hackathon Entry
Journey App: Empathy Jam 2017 Hackathon Entry
 
SLP 2018 Customer Development
SLP 2018 Customer DevelopmentSLP 2018 Customer Development
SLP 2018 Customer Development
 
Dreams, resilience and making a difference
Dreams, resilience and making a differenceDreams, resilience and making a difference
Dreams, resilience and making a difference
 
Diversity and Inclusion in Wikipedia
Diversity and Inclusion in WikipediaDiversity and Inclusion in Wikipedia
Diversity and Inclusion in Wikipedia
 
IA Wikipedia Edit-a-thon
IA Wikipedia Edit-a-thonIA Wikipedia Edit-a-thon
IA Wikipedia Edit-a-thon
 
Creating a Collaborative Learning Gateway
Creating a Collaborative Learning GatewayCreating a Collaborative Learning Gateway
Creating a Collaborative Learning Gateway
 
Prelude 16: Preserving Performance
Prelude 16: Preserving PerformancePrelude 16: Preserving Performance
Prelude 16: Preserving Performance
 
Mentoring Women in Open Source
Mentoring Women in Open SourceMentoring Women in Open Source
Mentoring Women in Open Source
 
Pinterest as Digital Archive, IA Summit 2016, Atlanta
Pinterest as Digital Archive, IA Summit 2016, AtlantaPinterest as Digital Archive, IA Summit 2016, Atlanta
Pinterest as Digital Archive, IA Summit 2016, Atlanta
 

Recently uploaded

【社内勉強会資料_Octo: An Open-Source Generalist Robot Policy】
【社内勉強会資料_Octo: An Open-Source Generalist Robot Policy】【社内勉強会資料_Octo: An Open-Source Generalist Robot Policy】
【社内勉強会資料_Octo: An Open-Source Generalist Robot Policy】
NABLAS株式会社
 
一比一原版(UniSA毕业证书)南澳大学毕业证如何办理
一比一原版(UniSA毕业证书)南澳大学毕业证如何办理一比一原版(UniSA毕业证书)南澳大学毕业证如何办理
一比一原版(UniSA毕业证书)南澳大学毕业证如何办理
slg6lamcq
 
一比一原版(UPenn毕业证)宾夕法尼亚大学毕业证成绩单
一比一原版(UPenn毕业证)宾夕法尼亚大学毕业证成绩单一比一原版(UPenn毕业证)宾夕法尼亚大学毕业证成绩单
一比一原版(UPenn毕业证)宾夕法尼亚大学毕业证成绩单
ewymefz
 
一比一原版(UofS毕业证书)萨省大学毕业证如何办理
一比一原版(UofS毕业证书)萨省大学毕业证如何办理一比一原版(UofS毕业证书)萨省大学毕业证如何办理
一比一原版(UofS毕业证书)萨省大学毕业证如何办理
v3tuleee
 
做(mqu毕业证书)麦考瑞大学毕业证硕士文凭证书学费发票原版一模一样
做(mqu毕业证书)麦考瑞大学毕业证硕士文凭证书学费发票原版一模一样做(mqu毕业证书)麦考瑞大学毕业证硕士文凭证书学费发票原版一模一样
做(mqu毕业证书)麦考瑞大学毕业证硕士文凭证书学费发票原版一模一样
axoqas
 
06-04-2024 - NYC Tech Week - Discussion on Vector Databases, Unstructured Dat...
06-04-2024 - NYC Tech Week - Discussion on Vector Databases, Unstructured Dat...06-04-2024 - NYC Tech Week - Discussion on Vector Databases, Unstructured Dat...
06-04-2024 - NYC Tech Week - Discussion on Vector Databases, Unstructured Dat...
Timothy Spann
 
一比一原版(Coventry毕业证书)考文垂大学毕业证如何办理
一比一原版(Coventry毕业证书)考文垂大学毕业证如何办理一比一原版(Coventry毕业证书)考文垂大学毕业证如何办理
一比一原版(Coventry毕业证书)考文垂大学毕业证如何办理
74nqk8xf
 
一比一原版(IIT毕业证)伊利诺伊理工大学毕业证成绩单
一比一原版(IIT毕业证)伊利诺伊理工大学毕业证成绩单一比一原版(IIT毕业证)伊利诺伊理工大学毕业证成绩单
一比一原版(IIT毕业证)伊利诺伊理工大学毕业证成绩单
ewymefz
 
Criminal IP - Threat Hunting Webinar.pdf
Criminal IP - Threat Hunting Webinar.pdfCriminal IP - Threat Hunting Webinar.pdf
Criminal IP - Threat Hunting Webinar.pdf
Criminal IP
 
一比一原版(BCU毕业证书)伯明翰城市大学毕业证如何办理
一比一原版(BCU毕业证书)伯明翰城市大学毕业证如何办理一比一原版(BCU毕业证书)伯明翰城市大学毕业证如何办理
一比一原版(BCU毕业证书)伯明翰城市大学毕业证如何办理
dwreak4tg
 
一比一原版(CBU毕业证)不列颠海角大学毕业证成绩单
一比一原版(CBU毕业证)不列颠海角大学毕业证成绩单一比一原版(CBU毕业证)不列颠海角大学毕业证成绩单
一比一原版(CBU毕业证)不列颠海角大学毕业证成绩单
nscud
 
一比一原版(Deakin毕业证书)迪肯大学毕业证如何办理
一比一原版(Deakin毕业证书)迪肯大学毕业证如何办理一比一原版(Deakin毕业证书)迪肯大学毕业证如何办理
一比一原版(Deakin毕业证书)迪肯大学毕业证如何办理
oz8q3jxlp
 
The affect of service quality and online reviews on customer loyalty in the E...
The affect of service quality and online reviews on customer loyalty in the E...The affect of service quality and online reviews on customer loyalty in the E...
The affect of service quality and online reviews on customer loyalty in the E...
jerlynmaetalle
 
一比一原版(YU毕业证)约克大学毕业证成绩单
一比一原版(YU毕业证)约克大学毕业证成绩单一比一原版(YU毕业证)约克大学毕业证成绩单
一比一原版(YU毕业证)约克大学毕业证成绩单
enxupq
 
一比一原版(TWU毕业证)西三一大学毕业证成绩单
一比一原版(TWU毕业证)西三一大学毕业证成绩单一比一原版(TWU毕业证)西三一大学毕业证成绩单
一比一原版(TWU毕业证)西三一大学毕业证成绩单
ocavb
 
Q1’2024 Update: MYCI’s Leap Year Rebound
Q1’2024 Update: MYCI’s Leap Year ReboundQ1’2024 Update: MYCI’s Leap Year Rebound
Q1’2024 Update: MYCI’s Leap Year Rebound
Oppotus
 
Criminal IP - Threat Hunting Webinar.pdf
Criminal IP - Threat Hunting Webinar.pdfCriminal IP - Threat Hunting Webinar.pdf
Criminal IP - Threat Hunting Webinar.pdf
Criminal IP
 
Opendatabay - Open Data Marketplace.pptx
Opendatabay - Open Data Marketplace.pptxOpendatabay - Open Data Marketplace.pptx
Opendatabay - Open Data Marketplace.pptx
Opendatabay
 
Levelwise PageRank with Loop-Based Dead End Handling Strategy : SHORT REPORT ...
Levelwise PageRank with Loop-Based Dead End Handling Strategy : SHORT REPORT ...Levelwise PageRank with Loop-Based Dead End Handling Strategy : SHORT REPORT ...
Levelwise PageRank with Loop-Based Dead End Handling Strategy : SHORT REPORT ...
Subhajit Sahu
 
一比一原版(QU毕业证)皇后大学毕业证成绩单
一比一原版(QU毕业证)皇后大学毕业证成绩单一比一原版(QU毕业证)皇后大学毕业证成绩单
一比一原版(QU毕业证)皇后大学毕业证成绩单
enxupq
 

Recently uploaded (20)

【社内勉強会資料_Octo: An Open-Source Generalist Robot Policy】
【社内勉強会資料_Octo: An Open-Source Generalist Robot Policy】【社内勉強会資料_Octo: An Open-Source Generalist Robot Policy】
【社内勉強会資料_Octo: An Open-Source Generalist Robot Policy】
 
一比一原版(UniSA毕业证书)南澳大学毕业证如何办理
一比一原版(UniSA毕业证书)南澳大学毕业证如何办理一比一原版(UniSA毕业证书)南澳大学毕业证如何办理
一比一原版(UniSA毕业证书)南澳大学毕业证如何办理
 
一比一原版(UPenn毕业证)宾夕法尼亚大学毕业证成绩单
一比一原版(UPenn毕业证)宾夕法尼亚大学毕业证成绩单一比一原版(UPenn毕业证)宾夕法尼亚大学毕业证成绩单
一比一原版(UPenn毕业证)宾夕法尼亚大学毕业证成绩单
 
一比一原版(UofS毕业证书)萨省大学毕业证如何办理
一比一原版(UofS毕业证书)萨省大学毕业证如何办理一比一原版(UofS毕业证书)萨省大学毕业证如何办理
一比一原版(UofS毕业证书)萨省大学毕业证如何办理
 
做(mqu毕业证书)麦考瑞大学毕业证硕士文凭证书学费发票原版一模一样
做(mqu毕业证书)麦考瑞大学毕业证硕士文凭证书学费发票原版一模一样做(mqu毕业证书)麦考瑞大学毕业证硕士文凭证书学费发票原版一模一样
做(mqu毕业证书)麦考瑞大学毕业证硕士文凭证书学费发票原版一模一样
 
06-04-2024 - NYC Tech Week - Discussion on Vector Databases, Unstructured Dat...
06-04-2024 - NYC Tech Week - Discussion on Vector Databases, Unstructured Dat...06-04-2024 - NYC Tech Week - Discussion on Vector Databases, Unstructured Dat...
06-04-2024 - NYC Tech Week - Discussion on Vector Databases, Unstructured Dat...
 
一比一原版(Coventry毕业证书)考文垂大学毕业证如何办理
一比一原版(Coventry毕业证书)考文垂大学毕业证如何办理一比一原版(Coventry毕业证书)考文垂大学毕业证如何办理
一比一原版(Coventry毕业证书)考文垂大学毕业证如何办理
 
一比一原版(IIT毕业证)伊利诺伊理工大学毕业证成绩单
一比一原版(IIT毕业证)伊利诺伊理工大学毕业证成绩单一比一原版(IIT毕业证)伊利诺伊理工大学毕业证成绩单
一比一原版(IIT毕业证)伊利诺伊理工大学毕业证成绩单
 
Criminal IP - Threat Hunting Webinar.pdf
Criminal IP - Threat Hunting Webinar.pdfCriminal IP - Threat Hunting Webinar.pdf
Criminal IP - Threat Hunting Webinar.pdf
 
一比一原版(BCU毕业证书)伯明翰城市大学毕业证如何办理
一比一原版(BCU毕业证书)伯明翰城市大学毕业证如何办理一比一原版(BCU毕业证书)伯明翰城市大学毕业证如何办理
一比一原版(BCU毕业证书)伯明翰城市大学毕业证如何办理
 
一比一原版(CBU毕业证)不列颠海角大学毕业证成绩单
一比一原版(CBU毕业证)不列颠海角大学毕业证成绩单一比一原版(CBU毕业证)不列颠海角大学毕业证成绩单
一比一原版(CBU毕业证)不列颠海角大学毕业证成绩单
 
一比一原版(Deakin毕业证书)迪肯大学毕业证如何办理
一比一原版(Deakin毕业证书)迪肯大学毕业证如何办理一比一原版(Deakin毕业证书)迪肯大学毕业证如何办理
一比一原版(Deakin毕业证书)迪肯大学毕业证如何办理
 
The affect of service quality and online reviews on customer loyalty in the E...
The affect of service quality and online reviews on customer loyalty in the E...The affect of service quality and online reviews on customer loyalty in the E...
The affect of service quality and online reviews on customer loyalty in the E...
 
一比一原版(YU毕业证)约克大学毕业证成绩单
一比一原版(YU毕业证)约克大学毕业证成绩单一比一原版(YU毕业证)约克大学毕业证成绩单
一比一原版(YU毕业证)约克大学毕业证成绩单
 
一比一原版(TWU毕业证)西三一大学毕业证成绩单
一比一原版(TWU毕业证)西三一大学毕业证成绩单一比一原版(TWU毕业证)西三一大学毕业证成绩单
一比一原版(TWU毕业证)西三一大学毕业证成绩单
 
Q1’2024 Update: MYCI’s Leap Year Rebound
Q1’2024 Update: MYCI’s Leap Year ReboundQ1’2024 Update: MYCI’s Leap Year Rebound
Q1’2024 Update: MYCI’s Leap Year Rebound
 
Criminal IP - Threat Hunting Webinar.pdf
Criminal IP - Threat Hunting Webinar.pdfCriminal IP - Threat Hunting Webinar.pdf
Criminal IP - Threat Hunting Webinar.pdf
 
Opendatabay - Open Data Marketplace.pptx
Opendatabay - Open Data Marketplace.pptxOpendatabay - Open Data Marketplace.pptx
Opendatabay - Open Data Marketplace.pptx
 
Levelwise PageRank with Loop-Based Dead End Handling Strategy : SHORT REPORT ...
Levelwise PageRank with Loop-Based Dead End Handling Strategy : SHORT REPORT ...Levelwise PageRank with Loop-Based Dead End Handling Strategy : SHORT REPORT ...
Levelwise PageRank with Loop-Based Dead End Handling Strategy : SHORT REPORT ...
 
一比一原版(QU毕业证)皇后大学毕业证成绩单
一比一原版(QU毕业证)皇后大学毕业证成绩单一比一原版(QU毕业证)皇后大学毕业证成绩单
一比一原版(QU毕业证)皇后大学毕业证成绩单
 

Informed Consent-Are Your Participants-Aware-o- What-They-Share.pptx

  • 1. Informed Consent: Are Your Participants Aware of What They Share? Noreen Whysel Director of Validation Research Internet Safety Labs August 7-9, 2022 SOUPS 2022: Eighteenth Symposium on Usable Privacy and Security
  • 2.
  • 4. 10 Attributes of Respectful Me2B Commit ments Source: 10 Attributes of Respectful Me2B Commitments https://me2ba.org/flash-guide-9-the-10- attributes-of-respectful-me2b-commitments/
  • 5. Data Privacy Risks in User Testing Software
  • 6. What Are the Risks of All This Data Sharing? Participant • Lack of Sufficient Notice • Lack of Consent Researcher • Data Privacy Legal Violations • Trust User Testing Platform • Data Privacy Legal Violations • Trust
  • 9. Underlying Technologies Tracking and Sharing User Data Ada Appcues Azure.com Bing Ads Bugsnag Cloudflare cloudfront.net (Amazon) Cookielaw.org Datadog Tracker Doubleclick.net Drift.com Facebook.com Facebook.net Google.com Googleapis.com Google-analytics.com Google Adwords Google Adsense Google Dynamic Remarketing Google Fonts Google Play GoogleTagManager.com Gstatic.com Hubspot Jqyuery.com Klaro licdn.com (LinkedIn) Linkedin.com Microsoft.com Mixpanel via mxpnl.com NewRelic.com nr-data.net Office.net Office.com Pendo Rollbar Segment Sentry Snowplow sp Smassets.net Stathat.com Stripe Surveymonkey.com app.usabilityhub.com UserInterviews.com Windows.net Zendesk Zendesk Tracker _ga _gid _sp_id _sp_ses
  • 10. Google Forms and Microsoft Source: Tracker Map https://www.crownpeak.com/products/tag-monitoring-and-management
  • 12. Google Forms vs Survey Swap Source: Tracker Map https://www.crownpeak.com/products/tag-monitoring-and-management Google Forms 1 Tracker 0 Ad Networks 2 Widgets (Google) SurveySwap.io 3 Trackers 4 Ad Networks 1 Analytics (Google) 3 Widgets (incl Google Tag Manager)
  • 13. Usability Hub Usability Test 2 Trackers 1 Ad Network 1 Widget (Google Fonts) 1 Analytics (Google) Usability Hub First Click Test 2 Trackers 1 Ad Network 1 Widget (Google Fonts) 1 Analytics (Google) Optimal Workshop Tree Test 2 Trackers 1 Ad Network 1 Widget (Google Tag Manager) 1 Analytics (Google) Optimal Workshop Card Sort 4 Trackers 1 Ad Network 1 Widget (Google Tag Manager) 1 Analytics (Google) Usability Tests Source: Tracker Map https://www.crownpeak.com/products/tag-monitoring-and-management
  • 14. TypeForm Form 0 Trackers 0 Ad Networks 1 Widget (first party) 0 Analytics SurveyMonkey 0 Trackers 0 Ad Networks 1 Widget (Google Tag Manager) 1 Analytics (New Relic) Survey Software Source: Tracker Map https://www.crownpeak.com/products/tag-monitoring-and-management
  • 15. Source: Tracker Map https://www.crownpeak.com/products/tag-monitoring-and-management UserInterviews 5 Trackers (incl Facebook, Google and Microsoft ad trackers) 3 Ad Networks (Bing, Facebook, Doubleclick) 7 Widgets (incl Google Tag Manager) 2 Analytics (Google Analytics, Mix Panel) Prolific.io 3 Trackers (All 0 Ad Network 2 Widgets (incl Zendesk) 1 Analytics (Google Users)
  • 16. What Can You Do Now?
  • 17. What Can Researchers Do? • Provide clear notice and consent • Highlight any potentially hidden data sharing by the testing software • Name the software or testing platforms so participants can read and consent to their policies
  • 18. What Can User Testing Software Platforms Do? • Understand your data protection responsibilities • Make a greater effort to inform participants and researchers of your data sharing policy–every time they use your software
  • 19. Thank You! Noreen Whysel Director of Validation Research Internet Safety Labs (formerly the Me2B Alliance) Noreen.whysel@internetsafetylabs.org https://www.internetsafetylabs.org https://www.me2ba.org

Editor's Notes

  1. Hi. I'm Noreen Whysel from the Internet Safety Labs here to talk about informed consent and participant data privacy. Are Your Participants Aware of what they share?
  2. We'd like to be sure that the data about our research participant stays between us and the test participant. But are our participants fully aware of the data sharing agreements underlying the participants’ use of these testing tools?
  3. The confidentiality agreement they have with us is only part of the picture. In this short talk, I'll discuss how to ensure that your participants know how their data is collected and how it might be used or shared beyond the scope of the covered research project.
  4. I'll focus on a mini audit of several user testing software packages that we performed based on the Ten Attributes for Respectful Me2B Commitments that underly the our Me2B Safe Technology Specification. Me2B is a term that flips the traditional shortcut B2C, or business to consumer relationship, by putting the individual first.
  5. To understand the background of this talk, we take a brief look at the Data Privacy. I'm not a lawyer so this is really just a broad brush overview.
  6. Data may get collected in a number of different ways like when you enter data directly into forms, your account profile if you have one, or via aggregated profile and behavioral data that may be collected from third party data brokers or your own app use. 
  7. Those of us who collect, use and share data from our research participants are becoming subject to a greater and greater number of data protection laws.
  8. Each law has varying degrees of requirements, so you want to get your data governance policies right. And it's fair to expect the same from usability software that collects and controls data for you and your participants.
  9. Researchers collect and store data with a number of different research tools, that in turn use underlying technology that may also access this data. Knowing who might be eavesdropping through the testing platform's relationship with these underlying tools helps you to evaluate whether you are exposing your team or your participants to risks that come with access by technologies.
  10. Lack of notice and consent to share data is a significant risk. These are key components of many of the data privacy laws that govern which data we can and cannot save, use or share. While the risk to the researcher are similar to those of the user testing platform, the platform also bears responsibility for ensuring that anyone participating in a test on their platform has an appropriate level of notification of the data being collected and shared, as well as allowing the participant control over whether to continue.
  11. So now let's look at our audit. Researchers collect and store data with a number of different research tools, creating what we call a Me2T relationship between the individual and the technology. 
  12. This is a non-scientific study: It's not randomized and reflects the software packages that we either have been using in our own research or those that we've documented from forums that we participate in. You'll note that most of the software we looked at share data with Google and other external vendors. At least one shared with Facebook and two shared with Amazon and Microsoft.
  13. You can also see that just for these eight companies, there are a few dozen companies or company assets that are receiving data. The ones in bold are advertising or tracking software. Many of these tools aren't necessarily exploiting user data, but they are doorways to entities that now have some access to your participants' data.
  14. We used a tool called TrackerMap which exposes paths for data sharing between entities. What you are seeing is a map of the underlying connections between the testing software and various first and third-party technologies. We were particularly interested in advertising networks noted in blue, analytics packages in red, and trackers in gold. We started with Google and Microsoft forms because they are popular, free tools and don't require a lot of expertise to set up. We expected to see sharing with their own advertising networks, but only found Microsoft shared with Bing Ads here in blue. Google's shares are to more functional programs.
  15. What does this look like to the participant? Google Forms doesn't require it, but researchers can add a description at the top with information about the study, and details for informed consent if they choose to. A lot of studies don't have this much information and this short message is not sufficient for informed consent.
  16. A savvy user may see that Google has it's own privacy policy at the bottom of the form and may note that it would be in addition to any data policy for the study itself. And notice that this study also has a line here that says "P.S. This survey contains a completion code for SurveySwap.io," This indicates that participants may come from an external panel recruiting site. So there is a couple of third party technologies in play here but no reference to privacy and consent practices for any of these underlying Me2T relationships.
  17. So maybe google doesn't share much. But the SurveySwap data indicates that participants in this study are potentially being exposed to data sharing from the panel company.
  18. We ran a few other tests. Here are the tracker maps from live tests at usability testing platforms we examined in our study. You can see that these platforms both share with  Doubleclick  and Google.
  19. Survey vendors tended to have a relatively small number of tracking vendors.
  20. And the third group we looked at was panel recruiters where we saw a lot of data sharing with entities like Facebook, Doubleclick, Microsoft Marketing and Adobe Metrics.  When you look at these you should be asking yourself whether your participants are aware that these entities may have access to their data. We feel it's a good idea to remind participants of any Me2T consent relationships they may have when they participate your study.
  21. Product development is flawed. Often there is no consent when testing with potential users. Researchers should advocate for informed consent form that highlights all potential recipients of participant data including any additional data policies underlying the usability platform software or panel recruitment agencies.
  22. Software testing platforms should take a close look at their data protection responsibilities and make a greater effort to inform participants and test creators of the data sharing policy – not just once but every time they participate.
  23. So that's my PSA and I'd love to hear your questions. Enjoy the rest of SOUPS22!