"My Privacy for their Security": Employees' Privacy Perspectives and Expectations when using Enterprise Security Software

09/23/2022
by   Jonah Stegman, et al.
0

Employees are often required to use Enterprise Security Software ("ESS") on corporate and personal devices. ESS products collect users' activity data including users' location, applications used, and websites visited - operating from employees' device to the cloud. To the best of our knowledge, the privacy implications of this data collection have yet to be explored. We conduct an online survey (n=258) and a semi-structured interview (n=22) with ESS users to understand their privacy perceptions, the challenges they face when using ESS, and the ways they try to overcome those challenges. We found that while many participants reported receiving no information about what data their ESS collected, those who received some information often underestimated what was collected. Employees reported lack of communication about various data collection aspects including: the entities with access to the data and the scope of the data collected. We use the interviews to uncover several sources of misconceptions among the participants. Our findings show that while employees understand the need for data collection for security, the lack of communication and ambiguous data collection practices result in the erosion of employees' trust on the ESS and employers. We obtain suggestions from participants on how to mitigate these misconceptions and collect feedback on our design mockups of a privacy notice and privacy indicators for ESS. Our work will benefit researchers, employers, and ESS developers to protect users' privacy in the growing ESS market.

READ FULL TEXT

page 5

page 6

research
05/28/2021

Are Privacy Dashboards Good for End Users? Evaluating User Perceptions and Reactions to Google's My Activity (Extended Version)

Privacy dashboards and transparency tools help users review and manage t...
research
03/20/2022

Should Users Trust Their Android Devices? An Analysis and Scoring System for Pre-Installed Applications

Most users have no idea that their Android devices are equipped with man...
research
03/11/2020

Opportunistic multi-party shuffling for data reporting privacy

An important feature of data collection frameworks, in which voluntary p...
research
02/09/2022

Privacy Concerns Raised by Pervasive User Data Collection From Cyberspace and Their Countermeasures

The virtual dimension called `Cyberspace' built on internet technologies...
research
02/08/2018

Open Data, Grey Data, and Stewardship: Universities at the Privacy Frontier

As universities recognize the inherent value in the data they collect an...
research
11/01/2019

On the two-dataset problem

This paper considers the two-dataset problem, where data are collected f...
research
05/05/2017

Data Readiness Levels

Application of models to data is fraught. Data-generating collaborators ...

Please sign up or login with your details

Forgot password? Click here to reset