Search papers, labs, and topics across Lattice.
This study operationalizes the concept of "privacy washing" by developing a four-stage pipeline to detect internal contradictions in privacy policies, focusing on commitments that conflict with documented practices. Analyzing privacy policies from two distinct time periods, the authors find that third-party sharing contradictions are the most common, suggesting that these discrepancies arise from structural issues in policy composition rather than intentional deception. The prevalence of contradictions is significant, with 12.2% of recent policies and 36.5% of older policies exhibiting at least one confirmed contradiction, highlighting a persistent issue in privacy documentation over time.
Privacy policies are riddled with contradictions, with over a third of older policies failing to align commitments with practices, raising questions about transparency and accountability in data handling.
Privacy policies may contain internal contradictions in which commitments are undermined by practices documented elsewhere in the same policy. We operationalize this phenomenon, privacy washing, through a four-stage pipeline: statement extraction, compatibility filtering and natural language inference screening, multi-model judge verification, and thematic analysis, with contradictions confirmed by majority vote of a three-model LLM panel. Applied to two corpora of website privacy policies, 123 collected in 2026 (OPPT) and 115 collected in 2015 (OPP-115), the pipeline finds the same category patterns recurring across the 11-year gap, with third-party sharing contradictions the majority of confirmed cases in each primary run, consistent with structural factors in policy composition rather than necessarily intentional deception. At least one panel-confirmed contradiction appears in 12.2% of OPPT companies (15/123; 9.8% excluding legacy pairs) and 36.5% of OPP-115 companies (42/115). A stability re-run seven months later, with a fully separated configuration (new extraction models, judges from three Chinese providers absent from both corpora, matched filters, no judge-submission similarity threshold), reproduces the OPPT prevalence under the original protocol (13.0% vs. 12.2%), finds sub-threshold pairs confirm at rates of the same order as those above (raising prevalence to 20.3% and 40.9%), and shows the third-party majority is panel-sensitive while the recurrence of the same category pairs is not. Two caveats govern all figures: panel verdicts are not validated against human expert judgment, so precision is unknown and prevalence figures are lower bounds; and the two primary runs used different filter configurations, so their prevalence difference is not interpretable as a corpus or era effect (the matched re-run reduces the gap to roughly twofold but does not eliminate it).