Skip to main content
. 2023 Oct 17;9(10):e20648. doi: 10.1016/j.heliyon.2023.e20648

Table 7.

The final ten privacy principles and 31 privacy criteria for use in the scoring model and their associated weights.

Privacy principles Privacy criteria Weight
1. Data processing (Collection, Purpose)/
Information use / On data processing and usage /
Processing entities /
First party collection or usage

1. Give meaning of personal data
1/50
2. Give meaning of cookies
1/50
3. Purpose of personal data collection
1/50
4. Data processing
1/50
5. Purpose of cookie collecting 1/50

2. Information disclosure / Third-party transfer /
On the disclosure of personal data to third parties /
Third party sharing or collection

6. Purpose of marketing promotion
1/30
7. Provide the first/third party cookie information

1/30
8. Sharing personal data with third party 1/30

3. Data retention / Storage and retention
of collected data

9. Type of personal data collection
1/40
10. Storage and data retention period
1/40
11. Where the data will be stored
1/40
12. Cookie retention period 1/40

4. Rights of data subjects: User access, Edit,
Delete, Object, Data accuracy and control,
Data portability

13. Accessibility
1/40
14. Data subject's rights
1/40
15. Cookie banner / User of cookie /
Notification of the usage of cookie

1/40
16. Provide link to cookie policy 1/40

5. Data protection / Data security /
Security measures / Security of personal data /
Integrity and confidentiality

17. Hypertext Transfer Protocol Secure (HTTPS)
1/30
18. How to protect the collected personal data
1/30
19. Statement notifying users of the limitation
or scope of its liability when visiting other websites
1/30

6. User controls / User choice / Control /
Opt-out options

20. Consent form
1/60
21. A channel or button for user to withdraw
consent easily

1/60
22. Non-necessary cookie rejection
1/60
23. Cookie settings
1/60
24. Non-necessary cookie consent
1/60
25. How to disable cookies 1/60

7. Policy change / Revisions in the privacy
statements / Policy updates

26. If the policy changes, how data controller will do
1/20
27. Latest revision date 1/20

8. Privacy contact information /
Additional information /
Contact possibilities for inquiries
regarding the privacy policies
28. Contact information 1/10

9. International and specific audiences 29. Protection of children's data / Child privacy 1/10

10. Data categories / Collected information 30. Type of cookie collection
1/20
31. Where personal data come from /
How to collect: directly or get from third party
1/20