To main content

Privacy@Edge: Privacy-aware Edge and Data Subjects

Privacy@Edge develops new knowledge and tools that help people understand how the smart devices in their everyday lives use their personal information and make informed privacy choices. By combining automated analysis of privacy policies with personalized recommendations, the project aims to make privacy control easier in everyday life.

Contact person

AI-generated stock image from Microsoft

While browsing the web, installing an app, or setting up a new device, we are routinely asked to consent to privacy policies or terms of service. These texts are long and dense with legal and technical jargon, so most people reflexively click "I agree". Such uninformed consent exposes people to unfair or deceptive practices and leads to frustration and privacy resignation – people simply give up on managing their privacy. The stakes are especially high for devices that sense our bodies and surroundings, such as fitness trackers, voice assistants, robot vacuums, smart cars and baby monitors.

Privacy resignation, combined with pervasive surveillance capitalism, gives companies enormous power to profile, manipulate and control consumers – affecting many areas of our lives and weakening our democracy. Privacy@Edge addresses this critical societal problem.

Privacy@Edge develops privacy-assisting solutions that make privacy information easier to understand and act on. We have built a dataset of 101 privacy notices for Internet of Things (IoT) products sold in the EU/EEA, annotated with GDPR-relevant data practices by an LLM pipeline and verified by human reviewers. A Notice Analyzer turns a device's privacy notice into a structured overview of what data is collected, why, with whom it is shared and for how long it is kept. A survey of 510 IoT users identified six privacy personas, and a privacy recommender uses them to point consumers to the privacy rights and choices most relevant to them – and how to exercise them. The project also develops communication-efficient, privacy-preserving federated learning methods, so that models can be trained on consumers' own devices without pooling their privacy preference data.

The combined expertise of SINTEF in privacy, LLMs and federated learning, the Norwegian University of Science and Technology (NTNU) in decentralised machine learning and edge computing, and our industry partners Kobla AS in smart cities and Tellu AS in eHealth makes it possible to address the shortcomings of today's "notice and consent" paradigm and bring research results closer to practical use.

Key facts

Project duration

2023 - 2027

Funding

This project has received funding from the Research Council of Norway’s IKTPLUS-ICT and digital innovation Programme under grant agreement for project No. 338909.

Project participants

Shukun Tokas

Shukun Tokas

Research Scientist
Simeon Tverdal

Simeon Tverdal

Research Scientist