The growing use of Machine Learning and Artificial Intelligence (AI), particularly Large Language Models (LLMs) like OpenAI's GPT series, leads to disruptive changes across organizations. At the same time, there is a growing concern about how organizations handle personal data. Thus, privacy policies are essential for transparency in data processing practices, enabling users to assess privacy risks. However, these policies are often long and complex. This might lead to user confusion and consent fatigue, where users accept data practices against their interests, and abusive or unfair practices might go unnoticed. LLMss can be used to assess privacy policies for users automatically. In this interdisciplinary work, we explore the challenges of this approach in three pillars, namely technical feasibility, ethical implications, and legal compatibility of using LLMs to assess privacy policies. Our findings aim to identify potential for future research, and to foster a discussion on the use of LLM technologies for enabling users to fulfil their important role as decision-makers in a constantly developing AI-driven digital economy.
%0 Report
%1 5662e072bc2a4586bd0991b8a4ea31dc
%A Aydin, Irem
%A Diebel-Fischer, Hermann
%A Freiberger, Vincent
%A Möller-Klapperich, Julia
%A Buchmann, Erik
%A Färber, Michael
%A Lauber-Rönsberg, Anne
%A Platow, Birte
%D 2024
%K FIS_scads area_responsibleai yaff
%T Assessing Privacy Policies with AI: Ethical, Legal, and Technical Challenges
%X The growing use of Machine Learning and Artificial Intelligence (AI), particularly Large Language Models (LLMs) like OpenAI's GPT series, leads to disruptive changes across organizations. At the same time, there is a growing concern about how organizations handle personal data. Thus, privacy policies are essential for transparency in data processing practices, enabling users to assess privacy risks. However, these policies are often long and complex. This might lead to user confusion and consent fatigue, where users accept data practices against their interests, and abusive or unfair practices might go unnoticed. LLMss can be used to assess privacy policies for users automatically. In this interdisciplinary work, we explore the challenges of this approach in three pillars, namely technical feasibility, ethical implications, and legal compatibility of using LLMs to assess privacy policies. Our findings aim to identify potential for future research, and to foster a discussion on the use of LLM technologies for enabling users to fulfil their important role as decision-makers in a constantly developing AI-driven digital economy.
@techreport{5662e072bc2a4586bd0991b8a4ea31dc,
abstract = { The growing use of Machine Learning and Artificial Intelligence (AI), particularly Large Language Models (LLMs) like OpenAI's GPT series, leads to disruptive changes across organizations. At the same time, there is a growing concern about how organizations handle personal data. Thus, privacy policies are essential for transparency in data processing practices, enabling users to assess privacy risks. However, these policies are often long and complex. This might lead to user confusion and consent fatigue, where users accept data practices against their interests, and abusive or unfair practices might go unnoticed. LLMss can be used to assess privacy policies for users automatically. In this interdisciplinary work, we explore the challenges of this approach in three pillars, namely technical feasibility, ethical implications, and legal compatibility of using LLMs to assess privacy policies. Our findings aim to identify potential for future research, and to foster a discussion on the use of LLM technologies for enabling users to fulfil their important role as decision-makers in a constantly developing AI-driven digital economy. },
added-at = {2024-11-28T16:27:18.000+0100},
author = {Aydin, Irem and Diebel-Fischer, Hermann and Freiberger, Vincent and M{\"o}ller-Klapperich, Julia and Buchmann, Erik and F{\"a}rber, Michael and Lauber-R{\"o}nsberg, Anne and Platow, Birte},
biburl = {https://puma.scadsai.uni-leipzig.de/bibtex/22488aa7dafc05de5ce6b3772412d34f2/scadsfct},
day = 10,
interhash = {007eb3e8f455aae920bf7e0d4f5fcd64},
intrahash = {2488aa7dafc05de5ce6b3772412d34f2},
keywords = {FIS_scads area_responsibleai yaff},
language = {English},
month = oct,
note = {Published at AISyS 2024},
timestamp = {2025-07-29T10:29:43.000+0200},
title = {Assessing Privacy Policies with AI: Ethical, Legal, and Technical Challenges},
type = {WorkingPaper},
year = 2024
}