Key points are not available for this paper at this time.
• Privacy policy analysis is typically carried out using machine learning. • Machine learning techniques mostly co-occur with manual forms of annotation. • Textual and interpretive ambiguity plague privacy policy analyses. • Policy harvesting is complex; limiting the resultant insight gained. • Little privacy-centric theory is used to guide policy analysis research. Online users often neglect the importance of privacy policies - a critical aspect of digital privacy and data protection. This scoping review addresses this oversight by delving into privacy policy analysis, aiming to establish a comprehensive research agenda. The study's objective was to explore the analytic techniques employed in privacy policy analysis and to identify the associated challenges. Following the Preferred Reporting Items for Systematic Reviews and Meta-Analyses for Scoping Reviews (PRISMA-ScR) checklist, the review selected n = 97 relevant studies. The findings reveal a diverse array of techniques used, encompassing automated machine learning and natural language processing, and manual content analysis. Notably, researchers grapple with challenges like linguistic nuances, ambiguity, and complex data harvesting methods. Additionally, the lack of privacy-centric theoretical frameworks and a dearth of user evaluations in many studies limit their real-world applicability. The review concludes by proposing a set of research recommendations to shape the future research agenda in privacy policy analysis.
Schyff et al. (Sun,) studied this question.