

From One-Size-Fits-All Privacy to User-Held Preferences: PETs, Negotiation, and Governable Data Ecosystems
Ask the Expert ft. Dr. Daniel Smullen
Synopsis:
Modern privacy systems still rely heavily on static notices, fragmented consent dialogs, and one-size-fits-all defaults that fail to reflect the diversity and nuance of people’s privacy expectations. This talk explores how user-held preferences and privacy-enhancing technologies (PETs) can help shift privacy from a passive compliance exercise into an active, negotiable, and technically enforceable relationship between users, services, and ecosystems.
Drawing from research in usable privacy, IoT ecosystems, machine learning-assisted preference modeling, and standards development, the discussion will examine how privacy controls can better align with people’s mental models while reducing user burden. Topics will include centralized preference management, usable consent and choice mechanisms, governance approaches that allow rights and obligations to follow data, and how interoperable standards can enable privacy preferences to persist across connected systems.
The session will also discuss the practical challenges of implementing these ideas in real-world ecosystems involving connected devices, AI systems, and multi-party data sharing environments.
Problem Statement:
Current privacy ecosystems place an unrealistic burden on individuals to continuously interpret notices, configure settings, and manage fragmented consent experiences across websites, applications, devices, and data ecosystems. Existing controls are often poorly aligned with users’ mental models, difficult to understand, inconsistent across services, and incapable of expressing nuanced contextual preferences.
As connected-device ecosystems and AI systems become more pervasive, these problems are amplified by increasing data complexity, multi-party data flows, and opaque downstream uses of data. The challenge is not simply offering more controls, but designing privacy mechanisms that are understandable, interoperable, enforceable, and scalable without overwhelming users.
We’ll discuss how user-held preferences, machine learning-assisted privacy management, interoperable standards, and PETs can reduce user burden while enabling more meaningful, context-aware, and governable privacy choices.
Related Privacy Enhancing Technologies (PETs):
User-held privacy preference frameworks
Data minimization architectures
Policy-aware data governance systems
Consent and preference signaling mechanisms
Privacy-preserving identity and authentication systems
On-device AI and edge processing
Privacy preference modeling and recommendation systems
Interoperable standards for privacy signaling and enforcement
Pre-Discussion Recources:
Daniel Smullen website publications and CV — https://www.daniel-smullen.com
PETs In Practice Webinar — https://www.brighttalk.com/webcast/19414/664461
Naeini et al., “Privacy Expectations and Preferences in an IoT World,” SOUPS 2017 — https://www.usenix.org/conference/soups2017/technical-sessions/presentation/naeini
Personalized Privacy Assistant Project: IoT Privacy Infrastructure — https://www.privacyassistant.org/iot/
Informing the Design of a Personalized Privacy Assistant for the Internet of Things — https://dl.acm.org/doi/fullHtml/10.1145/3313831.3376389
IoT Privacy Infrastructure — https://iotprivacy.io/about
Global Privacy Control specification, W3C — https://www.w3.org/TR/gpc/
Advanced Data Protection Control specification — https://www.dataprotectioncontrol.org/specification/
Guest Expert: Dr. Daniel Smullen
Dr. Daniel Smullen is a Principal Privacy Research Engineer at CableLabs specializing in privacy engineering, connected-device ecosystems, IoT privacy, technical standards, privacy-enhancing technologies (PETs), usable privacy and security, human-computer interaction, machine learning, and AI-enabled trust systems. His work focuses on translating socio-technical privacy goals into interoperable technical standards, engineering requirements, and deployable privacy architectures for real-world products and infrastructure.
Previously, Daniel worked at Amazon Lab126 on privacy engineering, AI systems, and customer trust technologies for Alexa and connected devices. He completed his Ph.D. at Carnegie Mellon University’s CyLab Security and Privacy Institute, where his research explored usable privacy controls, machine learning-assisted privacy management, and privacy preference modeling for web, mobile, and IoT ecosystems. He has also contributed to standards activities across the Connectivity Standards Alliance (Matter, Zigbee, Aliro), Internet Engineering Task Force, and broader privacy governance initiatives.
Moderator: Jason Cronk
With over two decades of experience in principle and trust consultancy, Jason Cronk is a seasoned privacy engineer, developer, author of the IAPP textbook “Strategic Privacy by Design,” Privacy Engineering Section Leader at the IAPP, and founder and president of the Institute of Operational Privacy Design. His knowledge and involvement reaches across the spectrum as an active member of the academic, engineering, legal and professional privacy communities and a pioneering voice in the development of privacy by design.