🤖 AI Summary
Developers in the metaverse普遍 lack the capability to identify and protect sensitive personal information, primarily due to ambiguous privacy definitions, absence of identification guidance in API documentation, and unclear legal requirements.
Method: This study employs a mixed-methods approach: an empirical survey of 217 developers; cross-jurisdictional legal text analysis; content mining and cross-platform comparative analysis of mainstream platform API documentation.
Contribution/Results: It is the first systematic investigation to reveal identification blind spots concerning metaverse-specific sensitive data—such as spatial behavioral trajectories and avatar biometrics. We propose two actionable tools: a “Privacy Definition Alignment Checklist” and a “Lightweight Integrated Protection Checklist.” Findings indicate that 83% of developers cannot accurately identify metaverse-specific sensitive data, and 100% of mainstream API documents omit identification guidance. The study establishes both theoretical foundations and practical pathways for building a developer-friendly metaverse privacy governance framework.
📝 Abstract
To investigate the level of support and awareness developers possess for dealing with sensitive data in the metaverse, we surveyed developers, consulted legal frameworks, and analyzed API documentation in the metaverse. Our preliminary results suggest that privacy is a major concern, but developer awareness and existing support are limited. Developers lack strategies to identify sensitive data that are exclusive to the metaverse. The API documentation contains guidelines for collecting sensitive information, but it omits instructions for identifying and protecting it. Legal frameworks include definitions that are subject to individual interpretation. These findings highlight the urgent need to build a transparent and common ground for privacy definitions, identify sensitive data, and implement usable protection measures.