Balancing Privacy and Data Utilization: A Comparative Vignette Study on User Acceptance of Data Trustees in Germany and the US

Leona Lassak

Network and Distributed System Security (NDSS) Symposium 2025 · Day 2 · Privacy & Usability 2 · Privacy & Usability 2

Overview

This talk, presented by Leona Lassak, delves into the nascent concept of data trustees as a potential solution to the pervasive problem of opaque and untransparent data sharing in modern society. As individuals increasingly generate vast amounts of data through online activities, smart devices, vehicles, and medical records, there is a growing concern about who accesses this data, how it is used, and who ultimately benefits. The core idea of a data trustee is to introduce a trusted intermediary between the data subject (the individual) and the data user (the entity utilizing the data), allowing for more controlled, privacy-preserving, and transparent data sharing based on the user's explicit preferences.

Watch on YouTube · Slides

Key moments

  1. 0:40 Introduction and concept of data trustees
  2. 2:00 Study methodology and factors investigated
  3. 4:00 Overall low user acceptance of data trustees
  4. 5:20 Impact of data anonymity on user acceptance
  5. 6:00 Recipient's influence on data trustee acceptance
  6. 6:50 Monetary and personal benefits impact acceptance
  7. 7:40 Factors with no user influence (mismatch literature)

Balancing Privacy and Data Utilization: A Comparative Vignette Study on User Acceptance of Data Trustees in Germany and the US

Speakers: Leona Lassak

Conference: NDSS Symposium

YouTube: https://www.youtube.com/watch?v=3HYRuL_nJQc

Overview

This talk, presented by Leona Lassak, delves into the nascent concept of data trustees as a potential solution to the pervasive problem of opaque and untransparent data sharing in modern society. As individuals increasingly generate vast amounts of data through online activities, smart devices, vehicles, and medical records, there is a growing concern about who accesses this data, how it is used, and who ultimately benefits. The core idea of a data trustee is to introduce a trusted intermediary between the data subject (the individual) and the data user (the entity utilizing the data), allowing for more controlled, privacy-preserving, and transparent data sharing based on the user's explicit preferences.

Lassak's research aims to bridge a critical gap: while the concept of data trustees has received some mention in significant legislation like the European Data Governance Act and the California Consumer Privacy Act (CCPA), its practical implementation details remain largely undefined. Crucially, there has been limited investigation into user acceptance of such a model and the specific factors that influence this acceptance. This talk presents the findings of a large-scale vignette study conducted in Germany and the US, providing invaluable insights for policymakers and designers striving to create data trustee frameworks that genuinely align with user expectations and foster trust.

The study's findings are particularly pertinent given the global emphasis on data privacy and the challenges of implementing effective data governance mechanisms. By understanding user perceptions and preferences across different cultural contexts, the research offers a foundational understanding necessary for developing robust and user-centric data trustee models. It highlights the complexities of balancing data utilization with individual privacy rights, offering a pragmatic perspective on how to design these intermediaries to maximize both utility and trust.

Background

▶ Watch: Introduction and concept of data trustees (0:40)

The digital age has ushered in an era of unprecedented data generation and sharing. From smart home devices collecting IoT data to connected cars generating automotive data, and from online browsing habits to sensitive medical data, individuals constantly contribute to a vast ecosystem of information. However, this omnipresent data flow comes with a significant drawback: a severe lack of transparency and control for the data subject. Users often share data without a clear understanding of its ultimate destination, how it will be processed, or who stands to gain from its usage. This opacity fuels a widespread desire for more privacy-preserving and transparent data sharing options.

Enter the concept of data trustees. The high-level vision positions a trusted institution as an intermediary. Instead of individuals directly sharing their data with potentially unknown or untrusted data users, they would entrust their data to a data trustee. This trustee would then manage and share the data with data users strictly according to the individual's predefined preferences and consent. This model is envisioned to empower users, giving them greater control and visibility over their digital footprint.

Despite its intuitive appeal and potential to address pressing privacy concerns, the concept of data trustees is still largely theoretical. Legislative frameworks such as the European Data Governance Act and the CCPA have acknowledged the idea, but they stop short of providing concrete definitions or implementation guidelines. This legislative ambiguity leaves a void, making it challenging to translate the abstract concept into practical, acceptable systems. Prior to this research, there was a notable absence of empirical studies investigating user acceptance of data trustees and the specific design parameters that would influence this acceptance. Such insights are crucial for moving beyond theoretical discussions and designing data trustee systems that users will actually adopt and trust. The research presented here directly addresses this gap by systematically exploring user attitudes and preferences towards various aspects of data trustee design.

Key Findings

▶ Watch: Overall low user acceptance of data trustees (4:00)

The study yielded several critical findings regarding user acceptance of data trustees, highlighting both challenges and opportunities for their design and implementation.

Firstly, overall acceptance of data trustees was found to be rather low. Approximately 30% of German participants selected the lowest possible rating, indicating strong opposition, while around 25% of US participants did the same. Although there were some positive responses (20-30% in Germany, 30-40% in the US), the high level of opposition suggests that the concept, being novel to most participants, faces significant hurdles. The researchers also concluded that a certain segment of the population is fundamentally opposed to the idea of data trustees, and no amount of design refinement is likely to sway their opinion.

Secondly, the study identified three factors that significantly influenced user acceptance: the level of anonymity provided, the recipient of the data, and the benefits offered to the user.

  • Anonymity: Unsurprisingly, higher levels of anonymity led to greater acceptance. Participants showed significantly higher agreement for sharing anonymized data and non-personal data compared to raw data. This effect was particularly pronounced for IoT data and online data in Germany, and for anonymized data in the medical domain in the US.
  • Recipient: The identity of the data recipient played a crucial role. Acceptance was significantly lower if law enforcement agencies were given access to medical data in Germany. Similarly, allowing "everyone" (the general public) access to online data in Germany and medical data in the US also resulted in significantly lower acceptance. Interestingly, the researchers were surprised not to find more negative reactions to law enforcement access across other domains or countries, and no clear explanation was provided for this specific observation.
  • Benefits: Offering benefits, whether monetary or personal and non-monetary, positively influenced acceptance. Specifically, both monetary benefits and personal non-monetary benefits led to significantly higher acceptance for medical data in Germany. In the US, only monetary benefits showed a significant positive influence, specifically for medical data and automotive data. The researchers noted their surprise that monetary benefits, often considered a "holy grail" for encouraging data sharing, did not have a broader impact across all domains.

Conversely, the study found that four factors, which are often heavily discussed in legal and regulatory literature, had no significant influence on user acceptance: the operator of the data trustee, the storage location of the data (e.g., EU vs. worldwide), how access is regulated, and how the data trustee is monitored. This highlights a notable mismatch between the priorities of regulators and the concerns of end-users.

Finally, analysis of open-ended responses revealed distinct cultural differences between Germany and the US. German participants primarily focused on privacy protection and user anonymity as their main reasons for their ratings. In contrast, US participants prioritized personal benefits and the purpose of data collection. This suggests that while Germans are primarily concerned with how their privacy is protected, Americans are more interested in what they get out of sharing their data and why it is being collected.

Technical Deep Dive

▶ Watch: Impact of data anonymity on user acceptance (5:20)

The research employed a rigorous social science methodology, specifically a vignette study design, to investigate user acceptance of data trustees. This approach is common in social sciences for understanding how different factors influence decision-making without requiring participants to interact with a live system. The study involved a substantial participant pool of 1,800 individuals, evenly split between Germany and the US, ensuring a representative sample for both populations.

The core of the methodology involved presenting participants with hypothetical scenarios, or "vignettes," that described various configurations of data trustees. Each vignette consisted of two main parts:

  1. A scenario description: This varied based on four different data domains investigated: medical data, automotive data, IoT data, and online data. This contextualized the type of data being shared and its potential uses.
  2. A description of the data trustee: This was the crucial part where eight distinct factors, primarily derived from legal literature where data trustees are currently being discussed, were systematically varied. These factors were:
  • Operator: Who runs the data trustee (e.g., government, non-profit, private company).
  • Level of Anonymity: How the data is processed to protect identity. The factor levels compared were raw data, anonymized data, and non-personal data only.
  • How data is processed: The methods used by the trustee.
  • Where data is stored: Geographical location of data storage (e.g., within the EU, worldwide).
  • Recipient: Who gets access to the data. Factor levels included research institutions, businesses, everyone (general public), and law enforcement agencies.
  • How access is regulated: The rules governing data access.
  • Benefits for users: What individuals gain from using the trustee. Factor levels included not mentioning any benefits, monetary benefits, or personal non-monetary benefits.
  • How the data trustee is monitored: Oversight mechanisms.

Participants were asked to rate their likelihood of agreeing to use the described data trustee scenario on a scale. By statistically analyzing these ratings against the varied factors, the researchers could identify which specific design elements significantly influenced user acceptance. For instance, comparing acceptance for raw data versus anonymized data, or for different recipient types, allowed for a quantitative assessment of user preferences. The use of a large sample size and a controlled experimental design strengthened the statistical power and generalizability of the findings, especially when comparing cultural differences between Germany and the US. The analysis also included coding open-ended responses to capture qualitative insights into participants' reasoning, further enriching the understanding of their motivations and concerns.

Demo / Proof of Concept

▶ Watch: Monetary and personal benefits impact acceptance (6:50)

As this talk presents the results of a social science study investigating user acceptance of a theoretical concept, there was no live technical demonstration or proof of concept in the traditional sense of a software or hardware exploit. Instead, the "demonstration" of the research involved presenting the methodological setup of the vignette study design and the statistical results derived from the 1,800 participant responses.

The speaker utilized graphs to visually represent the distribution of user acceptance ratings across different domains for both German and US participants, clearly illustrating the high proportion of participants opposed to the idea. Further, the presentation detailed how the eight varied factors influenced these ratings, breaking down the significant impacts of anonymity, recipient, and benefits with specific comparisons between factor levels (e.g., raw data vs. anonymized data). The qualitative data, derived from coding participants' open answers, was also presented to highlight the distinct cultural emphasis on privacy protection in Germany versus personal benefits in the US. While not a technical exploit, this rigorous presentation of empirical data served to validate the study's findings and provide concrete evidence for the observed user preferences.

Defensive Implications

▶ Watch: Factors with no user influence (mismatch literature) (7:40)

The findings of this study offer crucial defensive implications, not in the sense of protecting against a specific cyberattack, but in the broader context of designing robust and user-accepted data governance mechanisms. For organizations, policymakers, and designers aiming to implement data trustees or similar privacy-enhancing technologies, understanding these user preferences is paramount to fostering trust and ensuring adoption.

  1. Prioritize Anonymity: The most significant defensive implication is to bake strong anonymity features into the core design of any data trustee system. Users overwhelmingly prefer to share anonymized data or non-personal data over raw data. Designers must prioritize technical solutions that enable effective data anonymization and communicate these capabilities clearly to users. This builds trust by reducing the perceived risk of personal identification.
  2. Carefully Vet Data Recipients: The choice of data recipients is a critical trust factor. Designers should be extremely cautious about allowing law enforcement agencies access, particularly for sensitive data like medical data, as this significantly reduces acceptance. Similarly, the notion of "everyone" having access to data, even for less sensitive categories like online data, is met with strong opposition. Data trustee frameworks should define strict, transparent criteria for recipient eligibility, potentially limiting access to trusted research institutions or vetted businesses with clear, beneficial purposes.
  3. Articulate Clear Benefits: While not a "holy grail," clearly articulating the benefits for the data subject is essential. These benefits don't exclusively have to be monetary benefits; personal non-monetary benefits (e.g., improved services, personalized recommendations based on their own data) can also drive acceptance. Organizations should focus on demonstrating tangible value back to the user to incentivize participation.
  4. Address Cultural Nuances: A one-size-fits-all approach to data trustee design is unlikely to succeed. For populations like Germany, where privacy protection and anonymity are paramount, communication strategies and system designs must heavily emphasize these aspects. For populations like the US, highlighting the personal benefits and the clear purpose of data collection will be more effective in driving adoption. This requires a nuanced understanding of cultural differences in privacy attitudes.
  5. Re-evaluate Regulatory Priorities: The study revealed a mismatch between what regulators often focus on (e.g., operator type, storage location, monitoring, access regulation) and what users actually care about. While these factors are important for legal compliance and operational integrity, they do not appear to be primary drivers of user acceptance. Policymakers should consider re-prioritizing their efforts to align more closely with user concerns, focusing on the highly influential factors of anonymity, recipient control, and clear benefits, while ensuring foundational regulatory aspects are still met.
  6. Acknowledge Fundamental Opposition: Acknowledging that a segment of the population will likely remain fundamentally opposed to data trustees, regardless of design, is a defensive posture in itself. It prevents designers from endlessly tweaking systems to appease everyone and instead allows them to focus on building trust with the majority who might be open to the concept under the right conditions.

In essence, the defensive implication is to design data trustee systems from a user-centric perspective, proactively addressing their primary concerns about privacy, control, and value, rather than solely relying on technical or legal frameworks that might not resonate with the end-user.

Key Takeaways

  • Low Initial Acceptance: Overall user acceptance of data trustees is currently low, with a significant portion of participants (around 30% in Germany, 25% in the US) expressing strong opposition to the concept, suggesting a need for careful introduction and education.
  • Three Critical Design Factors: User acceptance is significantly influenced by the level of anonymity provided, the specific recipient of the data, and the benefits offered to the user (monetary or personal non-monetary).
  • Anonymity is Key: Users strongly prefer sharing anonymized data or non-personal data over raw data, highlighting the importance of robust anonymization techniques in data trustee design.
  • Recipient Matters Greatly: Allowing sensitive entities like law enforcement agencies or the general public ("everyone") access to personal data significantly reduces acceptance, emphasizing the need for strict and transparent recipient policies.
  • Cultural Differences in Privacy: German users prioritize privacy protection and anonymity, while US users focus more on personal benefits and the purpose of data collection, indicating that communication and design strategies should be culturally tailored.
  • Mismatch with Regulatory Focus: Factors heavily debated in legal literature, such as the operator of the trustee, data storage location, and monitoring mechanisms, had little influence on user acceptance, suggesting a divergence between regulatory and user priorities.

About the Speaker(s)

Leona Lassak is a researcher who presented this work at the NDSS Symposium. Her research focuses on understanding user acceptance of novel data governance concepts, specifically data trustees, to inform the design of privacy-preserving data sharing mechanisms. Her work involves conducting large-scale empirical studies to identify factors influencing user perceptions and expectations regarding data handling and privacy.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Competent empirical work on user acceptance of data trustees — methodologically sound, cross-cultural, and large enough to be credible. The findings are useful for policy designers and privacy engineers, but this is a social science study at a security conference: the insights are incremental rather than surprising, and the gap between what it reveals and what an informed practitioner already suspects is narrow.

Heather Calloway (CISO) — SOLID

Credible empirical work that surfaces a real gap between regulatory priorities and user expectations in data trustee design. The findings are interesting and the methodology is sound, but the talk stays in the research lane and never fully crosses into the institutional accountability or operational implications that would make it matter to security and privacy leaders.

→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025

All talks from Network and Distributed System Security (NDSS) Symposium 2025