ConsentDiff at Scale: Longitudinal Audits of Web Privacy Policy Changes and UI Frictions
By: Haoze Guo
Potential Business Impact:
Tracks how websites change privacy promises.
Web privacy is experienced via two public artifacts: site utterances in policy texts, and the actions users are required to take during consent interfaces. In the extensive cross-section audits we've studied, there is a lack of longitudinal data detailing how these artifacts are changing together, and if interfaces are actually doing what they promise in policy. ConsentDiff provides that longitudinal view. We build a reproducible pipeline that snapshots sites every month, semantically aligns policy clauses to track clause-level churn, and classifies consent-UI patterns by pulling together DOM signals with cues provided by screenshots. We introduce a novel weighted claim-UI alignment score, connecting common policy claims to observable predicates, and enabling comparisons over time, regions, and verticals. Our measurements suggest continued policy churn, systematic changes to eliminate a higher-friction banner design, and significantly higher alignment where rejecting is visible and lower friction.
Similar Papers
A Longitudinal Measurement of Privacy Policy Evolution for Large Language Models
Cryptography and Security
Makes AI companies share how they use your data.
"You don't need a university degree to comprehend data protection this way": LLM-Powered Interactive Privacy Policy Assessment
Human-Computer Interaction
Helps you understand website privacy rules easily.
An LLM-enabled semantic-centric framework to consume privacy policies
Artificial Intelligence
Helps computers understand website privacy rules.