Just as an individual is rightly concerned about the privacy of their personally identifying information, so also is a group of people, a community, concerned about the privacy of sensitive information entrusted to their care. Our research seeks to better understand the factors contributing to the sensitivity of community information, the privacy threats that are recognized by the community, and the means by which the community attempts to fulfill their privacy responsibilities. We are also interested in seeing how the elements of a community privacy model which we developed are related to the findings from the studies of actual communities. This paper presents results from three focus group interviews conducted with participants from two information technology companies and one group from our university. In this paper we report how the studied communities acted to confine sensitive information. These studies capture the character and complexity of community privacy and expose breakdowns in current approaches. We also find significant relationship between these results and the key elements of our community privacy model.
Information privacy is desired not only by individuals but also by a community of individuals to safeguard sensitive information for which they are collectively responsible. This paper reports on two aspects of privacy-aware communities that emerged from focus group interviews of three organizations: privacy awareness and situated disclosures. With respect to privacy awareness the study found that individuals within a community sought to limit the disclosure of information sensitive to their members, to their customers, or to the organization itself. The sensitivity resulted from a variety of factors ranging from legal mandates to concern for the dignity of co-workers. The complexity of the communities and the interactions between community factors and privacy were seen. With respect to situated disclosures it was found that compelling organizational interests motivated the disclosure of sensitive information outside of the usual community. However, these disclosures also involved securing internal agreement prior to disclosure, the weighing of the organizational interests against privacy concerns, and the recognition of varying levels of privacy. The relation of these findings to a community privacy model is also presented.
This paper describes how members of a community can collaboratively protect the privacy of the information they share via email. An extension of email tagging is used to represent communities and establish privacy protection boundaries. The approach is illustrated informally by scenarios and the key concepts are defined formally. The contributions of this paper are: (1) extending the idea of boundary regulation to a community, (2) empowering a community to manage its membership through group consensus and providing awareness of the actions of its members via notifications, and (3) capturing the semantics of this approach in a state-transition system and proving that email sharing is privacy-preserving.
Denis Gračanin合作论文数Department of Computer Science
Virginia Polytechnic Institute & State University1