Key points are not available for this paper at this time.
This study presents the first data-driven review of research on the privacy of eye tracking, covering gaze, iris, and eye image data across immersive, mobile, and clinical contexts. The analysis examined 78 papers published between 2015 and 2025 using ensemble topic modeling with non-negative matrix factorization. Nine topics emerged, showing how normative and technical approaches address privacy across different stages of eye tracking data processing. Findings reveal that normative works emphasize inference of identity and personal traits as an unresolved risk, whereas technical studies treat privacy as a computational problem and mitigate risks within specific contexts. However, protections are often constrained by utility requirements, meaning eye tracking data cannot be sufficiently safeguarded without impairing function, leaving enough detail to enable inference. This persistent vulnerability suggests that eye tracking data may warrant regulatory protection comparable to other sensitive categories, requiring stronger governance and safeguards across its collection and use.
Kovacs et al. (Thu,) studied this question.