Search papers, labs, and topics across Lattice.
To determine why privacy-enhancing technologies (PETs) fail to prevent real-world harms, this study constructs a new information flow model grounded in an empirical analysis of 257 documented privacy incidents. The findings reveal a critical structural flaw in privacy engineering: current PETs primarily secure the data flows enabling specific functionalities, leaving the downstream harms inherent in those functionalities completely unmitigated. This disconnect is compounded by systemic market failure, as the multi-entity actors best positioned to implement preventive mitigations routinely face the weakest incentives to act.
Most privacy-enhancing technologies merely secure the pipelines for inherently harmful functionalities rather than preventing the harms themselves.
Privacy-enhancing technologies (PETs) have emerged as a technical means for providing individuals with greater control over their information. Yet despite the growing deployment of PETs, people continue to experience privacy harms. In this work, we revisit our understanding of privacy incidents and the realities of those experiencing privacy harms, to assess whether the goals and abilities of PETs are misaligned with the harms people face. For our study, we collect news articles that correspond to a sample of 257 real-world privacy incidents. We employ content analysis over the articles to develop a new information flow model that encompasses the complexity of data flows and their relation to resulting harms. We demonstrate that our model captures both established and novel aspects of privacy incidents and their mitigations. In particular, it captures why consent is often insufficient to prevent privacy violations, how harms emerge from complex interactions among multiple entities and actions, and reveals a flaw in our understanding of PETs: a focus on enabling functionalities still permits the harms inherent in those functionalities. Moreover, we find that the entities best positioned to implement harm-preventing measures for the incidents in our sample are the least incentivized to do so. Overall, our model and analysis identify limitations of privacy technology research for harm prevention and further identifies paths for transforming how we approach the advancement of these technologies.