OPC key findings:
76 per cent of privacy policies were very long (over 3,000 words)
1
5
Forced action: Requiring or tricking users into disclosing more personal information to access a service than is necessary to provide that service
User is unnecessarily forced to sign up for an account to access the service
Example:
Forced action occurs when a website or mobile app forces users to take a specific action to access a service, when that action is not necessary to provide the service.
16 per cent of websites and mobile apps had forced actions
83 per cent of privacy policies were difficult to read (required university or graduate education reading level)
Privacy policies should include simple explanations with key information (additional details could be linked)
OPC recommendations:
Do not force users to provide more personal information than necessary to access a service