🤖 AI Summary
This study addresses the long-standing lack of a unified software engineering perspective on privacy documents throughout their lifecycle, which has led to fragmented approaches in generation, analysis, compliance verification, and usability evaluation. Through a systematic literature review (SoK) of 290 studies published between 2010 and 2025, this work proposes the first comprehensive lifecycle framework encompassing definition, generation, analysis, compliance validation, and usability assessment. The research identifies 15 key trends, 21 open challenges, and four major future directions, with particular emphasis on leveraging large language models for analyzing consistency between privacy policies and code implementations. By establishing a structured knowledge base and introducing a novel paradigm that balances usability for both end users and developers, this work lays a shared foundation for privacy documentation research in the AI era.
📝 Abstract
Privacy documents (e.g., privacy policies) are a central mechanism through which digital services disclose data practices and seek user consent. Over the past decades, research on privacy documents has expanded significantly, encompassing not only traditional privacy policies but also short notices (e.g., privacy labels) and interface-level transparency mechanisms. As this research area continues to grow, it has become increasingly difficult to obtain a coherent view of how privacy documents are created, analyzed, evaluated, and maintained across their lifecycle. This SoK provides a unified, lifecycle-oriented view of privacy documents from a software engineering perspective. We systematically review and analyze 290 papers published between 2010 and 2025, organizing them around five research questions that examine how privacy documents are (1) defined and scoped, (2) generated, (3) analyzed and extracted, (4) checked for inconsistencies and noncompliance, and (5) evaluated and improved for usability. Building on our findings, we identify 15 key research trends and 21 open opportunities. We further chart four broader research directions that highlight (i) emerging challenges in AI-centric platforms, (ii) the need for diverse and up-to-date data foundations, (iii) LLM-based unified policy-code analysis, and (iv) dual usability for end-users and developers. We hope this SoK provides a shared foundation for future research on privacy policies and privacy documents.