1
AP Seminar
January 18, 2026
Word Count: 1299
Addressing the Privacy Paradox and How We Can Protect Privacy
The issue of online privacy in the United States has grown as digital technology has
become more involved in our everyday lives. Social media platforms, search engines, online
shopping, and artificial intelligence are all ways how personal data is constantly collected,
analyzed, and shared. While many people have expressed concern about how their data is
collected and used, their behavior often contradicts their concerns. This is known as the privacy
paradox. The privacy paradox is a massive issue in the United States. According to Colleen
McClain, a Senior Researcher for the PEW Research Center, “Most Americans (78%) trust
themselves to make the right decisions about their personal information,” but “Our survey finds
that a majority of Americans ignore privacy policies altogether: 56% frequently click ‘agree’
without actually reading their content” (McClain et al). Understanding the causes and effects of
the privacy paradox is crucial to understanding the thesis question, “What approaches best
address the issue of online privacy in the United States?”
One of the major causes of online privacy issues in the United States is that most users
don’t understand how their personal data is collected, shared, or used by companies. According
to McClain, “The public increasingly says they don’t understand what companies are doing with
their data. Some 67% say they understand little to nothing about what companies are doing with
their personal data, up from 59%” (McClain et al). This lack of understanding about privacy
makes it difficult for people to make informed decisions. Also, Paul and Nina Gerber, two
writers of the book Computers and Security, “An overwhelming majority of American adults
2
(91%) think that consumers have lost control over how personal information is collected and
used by companies” (Gerber et al.). This shows that the population is aware of their limited
knowledge of how their information is being used. Even when this information is available, it is
often ineffective. According to DSpace, a market-leading provider of simulation and validation
solutions for embedded, safety-critical systems in the automotive and aerospace industries, “47%
of U.S. adults who use the internet at home say website privacy policies are easy to understand”
(“DSpace”). This connects to the thesis because, from an ethical standpoint, consent without
understanding of the policy isn’t really consent. If individuals do not fully understand how their
data is used, then companies are failing to be ethically responsible.
These weak online privacy protections and carelessness about privacy expose individuals
to risks such as data misuse, identity theft, and loss of control over personal information. Human
error is a large reason for these risks. Marcus Steele, a writer for the Manufacturing Innovation
Blog, stated that “According to the 2020 Verizon Data Breach Report, 22% of breaches in 2019
were due to simple human error- things like an email being sent to the wrong person or an
employee accidentally revealing their login credentials” (Steele). Social media companies also
significantly add to this risk. McClain also writes that “Social media companies harvest sensitive
data about individuals’ activities, interests, personal characteristics, political views, purchasing
habits, and online behaviors… Additionally, mergers and acquisitions have allowed dominant
companies to stifle competition, exercise monopolistic control, and block the emergence of
privacy-focused alternatives. Additionally, personal data collected by these platforms is
vulnerable to being accessed and misused by third parties, including law enforcement” (McClain
et al). These effects clearly show that personal awareness and protection are not nearly enough
3
and are ethically insufficient because individuals alone cannot reduce harm without broader
safeguards in place.
The debate about online privacy focuses on the question of who should be responsible for
protecting individual data. Some argue that individuals should take responsibility for protecting
their own privacy. Although individuals may believe that they can keep their data safe, they
cannot. This is what essentially leads to the privacy paradox. Without strict regulations, privacy
will never be safe. Evidence proves that individuals are not sufficiently aware or capable of
taking action to completely ensure their security online. McClain states, “Our survey finds that a
majority of Americans ignore privacy policies altogether: 56% frequently click 'agree' without
actually reading their content” (McClain et al). As a result, allowing individuals to attempt to
protect themselves from privacy breaches only emphasizes the privacy paradox instead of
solving it.
Others believe that it is the responsibility of the government to protect their privacy. The
government would enforce laws that require companies and websites to follow specific
guidelines to protect the privacy of individuals on their domains. These laws would create more
transparency between the company and consumer, which would in turn create more trust.
However, there are some limitations to this approach. Companies and websites, including those
connected to the government, can find workarounds in these laws and collect and misuse private
information. In fact, companies and governments have been using workarounds for years. Acts
like the Privacy Act of 1974 state “that agencies give the public notice of their systems of
records by publication in the Federal Register. The Privacy Act also prohibits the disclosure of a
record about an individual from a system of records absent the written consent of the individual,
4
unless the disclosure is pursuant to one of twelve statutory exceptions. The Act also provides
individuals with a means by which to seek access to and amendment of their records, and sets
forth various agency record-keeping requirements” (U.S. Department of Justice). Companies
work around this by labeling themselves as private companies, so they don’t technically fall
under the category of “US Federal Agencies”. Companies also use user agreements to gain
consent for data collection and sharing, although these policies and agreements are barely read,
shown in the data above. The Electronic Privacy Information Center, a highly credible,
non-profit research center focused on civil liberties and consumer privacy, also writes that
“Mergers and acquisitions have allowed dominant companies to stifle competition, exercise
monopolistic control, and block the emergence of privacy-focused alternatives. Additionally,
personal data collected by these platforms is vulnerable to being accessed and misused by third
parties, including law enforcement” (Electronic Privacy Information Center). Despite these
limitations, government regulations are essential to helping solve the privacy paradox. Having
stricter government regulations in place for companies and individuals would be beneficial to
help manage privacy leaks, as well as to keep companies ethically sound.
Based on the existing research shown, the best solution for the privacy paradox would be
stronger government regulations that limit data collection and require clearer privacy disclosures,
as well as simplifying privacy policies for the understanding of the users. Using stronger
government regulations would force companies to become more ethical and become more
transparent with people using their services. A statistic according to DSpace states “86% of
Americans believe that laws that force website policies to have a standard format will be
effective in helping them protect their information” (“DSpace”). Increasing digital privacy
5
education will also help reduce the impact of online privacy leaks. An addition to the possible
solution could be to simplify privacy policies even more. The United States Federal Trade
Commission (FTC) has been “encouraging standardized, tabular privacy policies similar to
nutrition labels” (Barth et al.). Online privacy can be improved through stronger federal laws as
well as clearer rules and labels for how companies use data.
Overall, the approaches that best address the issue of online privacy in the United States
are stronger government regulations that limit data collection as well as simplifying privacy
policies to enhance user understanding. Addressing online privacy in the United States requires
both ethical and systemic solutions, including both regulation and simplification. As technology
continues to shape everyday life, ethical responsibility must extend beyond individual users to
the institutions that collect that personal information. Resolving the privacy paradox involves
ethics not only for protection, but also for creating an environment of trust, equality, and equity.
6
WORKS CITED
Barth, Susanne, et al. “Understanding Online Privacy—a Systematic Review of Privacy
Visualizations and Privacy by Design Guidelines.” ACM Computing Surveys, vol. 55, no.
3, Apr. 2023, pp. 1–37, [Link]
“DSpace.” [Link], 2025,
[Link]/bitstreams/528409f9-e413-4b93-86d8-e44fe70c85d8/download.
Accessed 12 Dec. 2025.
Electronic Privacy Information Center. “Social Media Privacy.” [Link], 2024,
[Link]/issues/consumer-privacy/social-media-privacy/.
Gerber, Nina, et al. “Explaining the Privacy Paradox: A Systematic Review of Literature
Investigating Privacy Attitude and Behavior.” Computers & Security, vol. 77, Aug. 2018,
pp. 226–61, [Link]
“How Websites and Apps Collect and Use Your Information.” Consumer Advice, 13 May 2021,
[Link]/articles/how-websites-apps-collect-use-your-information.
McClain, Colleen, et al. “How Americans View Data Privacy.” Pew Research Center, Pew
Research Center, 18 Oct. 2023,
[Link]/internet/2023/10/18/how-americans-view-data-privacy/.
Steele, Marcus. “Maintaining Your Online Privacy.” NIST, 28 May 2021,
[Link]/blogs/manufacturing-innovation-blog/maintaining-your-online-privacy.
U.S. Department of Justice. “Privacy Act of 1974.” [Link], 4 Oct. 2022,
[Link]/opcl/privacy-act-1974.
7