Privacy Bills of Materials (PriBOM): A transparent privacy information inventory for collaborative privacy notice generation in mobile app development

Zhen Tao, Shidong Pan, Zhenchang Xing, Xiaoyu Sun, Omar Haggag, John Grundy, Jingjie Li, Liming Zhu

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

Privacy regulations mandate that developers must provide authentic and comprehensive privacy notices, e.g., privacy policies or labels, to inform users of their apps’ privacy practices. However, due to a lack of knowledge of privacy requirements, developers often struggle to create accurate privacy notices, especially for sophisticated mobile apps with complex features and in crowded development teams. To address these challenges, we introduce PriBOM (Privacy Bills of Materials), a systematic software engineering approach that leverages different development team roles to better capture and coordinate mobile app privacy information. PriBOM facilitates transparency-centric privacy documentation and specific privacy notice creation, enabling traceability and trackability of privacy practices. We present a pre-fill of PriBOM based on static analysis and privacy notice analysis techniques. We explore the perceived usefulness of PriBOM through a human evaluation with 150 diverse participants. The role of PriBOM in enhancing privacy-related communication is well received with 83.33% agreement, suggesting that PriBOM could serve as a significant solution for providing privacy support in DevOps for mobile apps.
Original languageEnglish
Title of host publicationProceedings of the 25th Privacy Enhancing Technologies Symposium
EditorsRob Jansen, Zubair Shafiq
PublisherPrivacy Enhancing Technologies Board
Pages392-409
Number of pages18
DOIs
Publication statusPublished - 19 Jul 2025
EventThe 25th Privacy Enhancing Technologies Symposium - George Washington University, Washington, United States
Duration: 14 Jul 202519 Jul 2025
Conference number: 25
https://petsymposium.org/cfp25.php

Publication series

NameProceedings on Privacy Enhancing Technologies
PublisherPrivacy Enhancing Technologies Board
Number4
Volume2025
ISSN (Electronic)2299-0984

Symposium

SymposiumThe 25th Privacy Enhancing Technologies Symposium
Abbreviated titlePETS 2025
Country/TerritoryUnited States
CityWashington
Period14/07/2519/07/25
Internet address

Keywords / Materials (for Non-textual outputs)

  • transparency
  • usable privacy
  • mobile applications
  • privacy policy
  • privacy paradox

Fingerprint

Dive into the research topics of 'Privacy Bills of Materials (PriBOM): A transparent privacy information inventory for collaborative privacy notice generation in mobile app development'. Together they form a unique fingerprint.

Cite this