I’m going to assume readers know what’s meant by the “Creepy Test” in privacy. Here’s a short appeal to use the Creepy Test sparingly and carefully.
The most obvious problem with the Creepy Test is its subjectivity. One person’s “creepy” can be another person’s “COOL!!”. For example, a friend of mine thought it was cool when he used Google Maps to check out a hotel he was going to, and the software usefully reminded him of his check-in time (evidently, Google had scanned his gmail and mashed up the registration details next time he searched for the property). I actually thought this was way beyond creepy; imagine if it wasn’t a hotel but a mental health facility, and Google was watching your psychiatric appointments.
In fact, for some people, creepy might actually be cool, in the same way as horror movies or chilli peppers are cool. There’s already an implicit dare in the “Nothing To Hide” argument. Some brave souls seem to brag that they haven’t done anything they don’t mind being made public.
Our sense of what’s creepy changes over time. We can get used to intrusive technologies, and that suits the agendas of infomoplists who make fortunes from personal data, hoping that we won’t notice. On the other hand, objective and technology-neutral data privacy principles have been with us for over thirty years, and by and large, they work well to address contemporary problems like facial recognition, the cloud, and augmented reality glasses.
Using folksy terms in privacy might make the topic more accessible to laypeople, but it tends to distract from the technicalities of data privacy regulations. These are not difficult matters in the scheme of things; data privacy is technically about objective and reasonable controls on the collection, use and disclosure of personally identifiable information. I encourage anyone with an interest in privacy to spend time familiarising themselves with common Privacy Principles and the definition of Personal Information. And then it’s easy to see that activities like Facebook’s automated face recognition and Tag Suggestions aren’t merely creepy; they are objectively unlawful!
Finally and most insideously, when emotive terms like creepy are used in debating public policy, it actually disempowers the critical voices. If “creepy” is the worst thing you can say about a given privacy concern, then you’re marginalised.
We should avoid being subjective about privacy. By all means, let’s use the Creepy Test to help spot potential privacy problems, and kick off a conversation. But as quickly as possible, we need to reduce privacy problems to objective criteria and, with cool heads, debate the appropriate responses.
See also A Theory of Creepy: Technology, Privacy and Shifting Social Norms by Omer Tene and Jules Polonetsky.