The privacy paradox applies to IoT devices too: a Saudi Arabian study

Noura Aleisa, Karen Renaud*, Ivano Bongiovanni

*Corresponding author for this work

Research output: Contribution to journalArticlepeer-review

13 Citations (Scopus)
295 Downloads (Pure)


The “privacy paradox” is the term used to describe the disconnect between self-reported privacy value attributions and actions actually taken to protect and preserve personal privacy. This phenomenon has been investigated in a number of domains and we extend the body of research with an investigation in the IoT domain. We presented participants with evidence of a specific IoT device’s (smart plug) privacy violations and then measured changes in privacy concerns and trust, as well as uptake of a range of behavioural responses. Our Saudi Arabian participants, despite expressing high levels of privacy concerns, generally chose not to respond to this evidence with preventative action. Most preferred to retain the functionality the smart device offered, effectively choosing to tolerate likely privacy violations. Moreover, while the improved awareness increased privacy concerns and reduced trust in the device straight after the experiment, these had regressed to pre-awareness levels a month later. Our study confirms the existence of the privacy paradox in the Saudi Arabian IoT domain, and also reveals the limited influence awareness raising exerts on long-term privacy concern and trust levels.
Original languageEnglish
Article number101897
Number of pages40
JournalComputers and Security
Early online date29 May 2020
Publication statusPublished - 1 Sept 2020


Dive into the research topics of 'The privacy paradox applies to IoT devices too: a Saudi Arabian study'. Together they form a unique fingerprint.

Cite this