Institut für IT-Sicherheit Fachgebiet Usable Security and Privacy Forschung IT-Sicherheits- und Privatsphäre-Maßnahmen
"Of course, that’s not feasible for everyone" – Compiling and Evaluating Privacy Recommendations in Expert Interviews

"Of course, that’s not feasible for everyone" – Compiling and Evaluating Privacy Recommendations in Expert Interviews

Information and supplementary materials on the page "Of course, that's not feasible for everyone" published on HAISA 2025

Digital privacy is and will remain an important issue for end users, and there are many recommendations on how to protect one's privacy. However, the majority of research focuses on security advice, thereby creating a potential gap in the field. In this paper, we present the results of n=10 expert interviews on privacy recommendations given to end users. We collect the recommendations given by experts, as well as their evaluation and prioritisation of these recommendations. In addition, the experts consider for which user groups the recommendation is appropriate, distinguishing between different levels of knowledge and experience.
The resulting 31 privacy recommendations cover a wide range, from general caution when sharing on social media to using privacy-friendly browsers and plug-ins that automatically delete cookies, most of which are considered suitable for all user groups.

The results are published as a paper at the IFIP International Symposium on Human Aspects of Information Security & Assurance (HAISA 2025).

At this page, you can find additional information and supplementary materials on our research.

Additional Information

  • Criteria for the different expert groups

    Experts from Industry:

    Study participants are employed in the IT department in a company AND take care of privacy-related issues for the company AND have a degree (apprenticeship or university degree) in an IT security or privacy related field or five years of professional experience.

    Experts from School:

    Study participants are people that are employed at a school (secondary school, high school) AND teach programming, computer science or a related subject and/or have IT jobs at school AND teach either currently or a maximum of five years ago.

    Experts from Academia:

    Study participants are people that are employed at a university as professor or research associate AND teach a subject with relation to cybersecurity and/or privacy AND teach either currently or a maximum of five years ago.

  • Recruitment Email and Declaration of Consent

    Dear Mrs ... / Dear Mr ...,

    I would like to conduct an interview with you as part of my Bachelor's thesis on the topic of privacy when browsing online. The aim of the thesis is to compile a list of measures to improve privacy on the Internet and to evaluate these measures.

    The interview will take place in the period from 11/12/2023 to 19/01/2024 in Hanover or online. The date and location will be arranged individually. The interview will last approx. 25 minutes and the audio will be recorded for evaluation purposes.

    If you have any questions about the interview process or other questions, I can be contacted by email or telephone.

    I look forward to receiving an appointment proposal from you as soon as possible.

    <<Contact information of the research team>>

    Yours sincerely

  • Interview Guide
    Minute Procedure
    0 Checking the tech / Guiding people to the room
    1 Greetings
    2 - 3 Icebreaker questions
    4 Lead to the main question
    5 Main question with further questions
    6 - 7 Collecting 3-5 privacy measures
    8 - 15 Evaluation of usefulness and user-friendliness
    16 - 19 Sorting the measures
    20 - 22 Dismissal / Farewell ?
    23 - 30 Spare time before next interview

    Checking the tech / Guiding people to the room

    • Ask about difficulties with audio or video or any other problems

    Greetings

    Welcome to my interview on the topic "Privacy in online browsing".

    I am <<name>>, <<job>> at Leibniz University Hannover.

    I am pleased that it worked out. I would like to briefly introduce the process.

    I have prepared a couple of questions that I would like to ask you, which you can answer freely. There are no right or wrong answers.

    I have already received a declaration of consent from you beforehand that you agree to the interview being recorded. If you have no objections, I would start the recording now.

    • Interviewee should have signed consent form beforehand
    • Only then start recording

    Icebreaker questions

    Great! I'd like to start with a few simple questions about your internet behaviour so that we can briefly get to know you.

    How many hours a day do you use the internet privately on average? This means emails, news, video and audio streaming or similar activities.

    • Interviewee gives an approximate number of hours

    How many hours a day do you use the internet professionally on a working day?

    • Interviewee gives approximate number of hours

    How many emails do you send per day? This refers to emails that they send for business or private purposes.

    • Interviewee gives approximate number of hours

    How often do you post information about yourself on social media? e.g. never, twice a year, once a week, every day, etc. A specific time period should be given if possible.

    • Interviewee gives approximate number of hours

    Main question

    Which measures would you suggest to internet users to protect their privacy? Ideal would be 3 to 5 measures.

    • Independent of the previous questions
    • Clarify ambiguities
    • Context of use is irrelevant. Wether it is aimed at smartphones or PCs, online shopping etc.

    Collecting 3-5 privacy measures

    • Collect and specify 3 - 5 measures, but do not suggest them, let the person think about them. We are looking for keywords for the whiteboard
    • If the answers are too long, ask: How could I summarise this measure in a few words so that I could write it on a post-it note?
    • Collect them all next to each other / distributed so that a hierarchy can be established later on

    Evaluation of usefulness and user-friendliness

    In the next step, we now want to evaluate the collected measures.

    Firstly, we want to consider whether each measure is useful from a technical point of view and whether it improves privacy at all.

    Briefly assess how useful each of these measures is. We use german school grades from 1 to 6. 1 means the measure improves privacy very well. 6 The measure brings practically no improvement.

    • The usefulness of each measure should be rated from 1 to 6

    Great! Next, let's take a look at the measures from the user's perspective. They should be able to implement the measures with as little stress and frustration as possible and with acceptable effort.

    How would you rate each of the measures from 1 to 6 in terms of user-friendliness? 1 is very user-friendly and 6 is not user-friendly.

    • For each measure, user-friendliness should be estimated from 1 to 6

    How much technical knowledge would a person need to implement this measure?

    Is this a measure for everyone, technically experienced people, people with a computer science background or only for experts?

    • Answer one of the categories for each measure

    Sorting the measures

    Jetzt haben wir noch eine abschließende inhaltliche Frage zu den Maßnahmen.

    Es geht darum welche Maßnahmen besonders wichtig sind und welche weniger wichtig sind.

    Wie würden sie denn die genannten Maßnahmen priorisieren?

    - Maßnahmen sollen priorisiert werden. Verschieben auf dem Whiteboard

    Farewell

    Thank you very much for your ideas! Finally, we have a few demographic questions.

    Which federal state do you come from?

    • State

    How old are you and what gender do you identify with?

    • Age
    • Gender

    Now I would like to ask you a few questions about your current profession.

    Do you teach at an educational institution? If yes, what kind (university/school/none)

    Do you work in the industry? (yes/no)

    Do you work in scientific research? (yes/no)

    Knowledge Quiz

    Finally, we have a small quiz to help you categorise your IT knowledge. The aim is to form pairs from one term to one topic. The assignments vary in difficulty and one pair of assignments is not possible so that the last ones cannot be guessed.
    How would you assign the following terms to a topic?

    • IT knowledge: Match the terms (two pairs cannot be matched):
    • Online a list on the right with the topics in random order and on the left the terms in a pile. In presence with post-its or notes and magnets
    Term Topic Difficulty
    Twitter Social Media Easy
    Google Search Engine Easy
    Cookies Tracking Medium
    https Browsing Medium
    Email Phishing Medium
    CVE Vulnerabilities Hard
    DRM Copy Protection Hard
    ZIP Virus Protection Nonsense
    Bluetooth Virtual Reality Nonsense

    Very nice!

    I would like to thank you for taking part in the interview and, if you have no further comments, I would like to end the recording.

    Do you have any further questions?

  • Codebook and Coded Segments

    During the analysis, we created a codebook which was then applied to all interviews.

    Attached you can find the codebook with the numbers of quotations each code applies. It includes one example quote per code. 

  • Translation Tables

    The interviews were conducted in German. The quotes used were translated from the original German into English for use in the codebook and in the paper. Enclosed are the respective German and English versions of the individual sentences.