Data Privacy: An Overlooked Aspect of Assistive Technology
- 19 hours ago
- 6 min read
By Shane Johnson
What is Data Privacy?
According to IBM, “data privacy, also called ‘information privacy,’ is the principle that a person should have control over their personal data, including the ability to decide how organizations collect, store and use their data” [1]. Data privacy is important for everyone, but is especially crucial for people with disabilities, especially those who rely on assistive technology in daily life.
What Does Data Privacy Have to Do with Disability?
People with disabilities are more vulnerable to data privacy threats for a few reasons. Firstly, they often have to hand over personal information, including sensitive information about their health and disability status in order to access necessary services and assistive technologies [2]. Secondly, the use of certain technologies, such as a blind individual using a screen reader, may mark an individual as disabled and incentivize others to take advantage and invade their privacy [3]. Thirdly, the standard approach to data privacy fails to meet the needs of people with cognitive disabilities in 2 key ways. First, and most obviously, privacy policies are typically dense and jargon filled. This goes directly against plain language guidelines [4]. Plain language is beneficial for everyone, but it can be necessary for people with Intellectual Disability or Dementia to understand privacy information [5]. Second, for people with cognitive disabilities, the traditional approach of securing consent once and then collecting data in perpetuity is insufficient because it can result in an individual being subjected to terms of a policy that they do not currently understand or accept. This reveals the importance of establishing ongoing consent [6]. Lastly, individuals with disabilities are more likely than the general population to be exposed to emerging technologies such as machine learning enabled medication management tools or companion robots, in the name of facilitating independent living. However, as noted by disability rights and technology expert, Ariana Aboulafia, these assistive technologies “can be categorized as surveillance technologies, in that they collect massive amounts of sensitive data via active or passive monitoring and, as a result, pose significant risks to the privacy of disabled people” [7].
In spite of this, current research finds that disabled individuals rarely report having disability specific privacy concerns when it comes to their assistive technology, instead voicing general concerns such as worries about being hacked. However, when informed by researchers of potential concerns regarding the ways their data could be collected, stored, used, and sold, clear preferences emerge [3][8].
What Do Disabled People Want to Happen to Their Data?
Available research shows that for individuals with disabilities, the desire to have control over who has access to their data as well as how their data is used is driven by concerns about discrimination [3][8]. For example, a qualitative study of 8 older adults who had difficulty using a mouse due to Essential Tremor of visual impairment found that all 8 participants would be comfortable sharing anonymized data about their mouse activity, collected by assistive technology software, with medical professionals [8]. In contrast, only about half said they would willingly share this data with the government or their employer, and all but one participant was opposed to this data being shared with insurance companies [8]. Another study focused on disabled college students found that students were broadly supportive of their data being used to improve access, but were opposed to uses not seen as beneficial to themselves or the disabled community, with one student noting, “if they’re using it to turn on some features that work with my tools, go ahead. If they’re using it to go into the advertising space, maybe not” [3].
The Current State of Assistive Technology Privacy Policies
Research into the privacy policies of assistive technology devices is currently limited, but recent studies captured key aspects of the current landscape and highlight what needs to change in the future. A study by Abigail Marsh and Lauren R. Milne examined the privacy policies of 14 different assistive technologies used by college students of varying levels (undergraduate, master’s, doctoral) [3]. They found that “only 5 out of 14 products had clear answers for how user data were collected and stored, and only 4 out of 14 products had clear answers for how data were shared and sold” [3]. Relatedly, they also found that a clear majority (10) of the privacy policies were company-wide rather than specific to the assistive technology in question [3].
Another study, by Crawford et al. evaluated the privacy policies of 24 assistive technologies “focusing on those recommended by [U.S.] state and federal agencies” [9]. Troublingly, the researchers found that a quarter of the assistive technologies selected lacked privacy policies altogether [9]. An analysis of the remaining 18 produced 5 main findings: (1) While most had specific protections for certain vulnerable populations, such as children under a given age, none of the policies contained specific protections for people with disabilities [9]. (2) Across the board, the legal language found within policies was concerned with ensuring a company’s compliance with the law rather than promoting privacy for users [9]. (3) Unlike Marsh and Milne, Crawford et al. found that the majority of privacy policies described how data would be collected and used, but the researchers noted that policies varied substantially from company to company, reflecting inconsistency in the field [9]. Additionally they still categorized a third of policies as “ambiguous” [9]. (4) Nearly half of the policies were not clear regarding what data was essential vs nonessential [9]. As an example, the researchers point to the privacy policy of a speech-to-text software, which states it may collect data on “citizenship or immigration status” as well as “sex life and sexual orientation” [9]. (5) Lastly, the researchers found that transparency about 3rd party data sharing differed significantly between companies, as did information on the types of 3rd parties involved and the reasons for sharing [9].
Between the two studies, only one assistive technology was covered by both teams. This means that 37 distinct products were covered. Taken together, current research suggests that assistive technology privacy policies are inadequately designed and likely failing to appropriately inform and protect users.
The Need For Privacy by Design
The shortcomings of current assistive technology privacy policies highlight the need for privacy by design. According to the Center for Democracy & Technology, privacy by design a framework is built on 7 principles:
(1) proactive not reactive; preventative not remedial,
(2) privacy as the default setting,
(3) privacy embedded into design,
(4) full functionality,
(5) end-to-end security,
(6) visibility and transparency, and
(7) respect for user privacy. [10].
When applied to assistive technology, this would look like companies voluntarily engaging in a variety of practices that prioritize user privacy needs. These include, but are not limited to: Seeking out the perspectives of people with disabilities early on in the development process and continuously implementing their feedback, only collecting the data that is necessary for their product to work as intended, having plain language documentation available to enable users to fully understand “which data is being collected, why that data is being collected, and how long it will be stored,” as well as to enable informed consent, not selling or sharing user data, and allowing users to delete their data [10].
Going forward, companies should also work to mitigate the particular privacy risks of implementing artificial intelligence (AI) [11]. While privacy is typically concerned with how many people have access to given information, the Center for Democracy & Technology emphasizes that “AI is not inherently privacy protective” because AI systems collect data on a much larger scale than people do, and as a result there is a much greater risk of harm in an AI data breach [10].
References:
[1] M. K. Forrest Amber, “What Is Data Privacy? | IBM.” Accessed: Jul. 28, 2026. [Online]. Available: https://www.ibm.com/think/topics/data-privacy
[2] A. Aboulafia, “Internet Privacy Is A Disability Rights Issue,” Tech Policy Press. Accessed: Jul. 28, 2026. [Online]. Available: https://techpolicy.press/internet-privacy-is-a-disability-rights-issue
[3] A. Marsh and L. R. Milne, “I Don’t Want to Sound Rude, but It’s None of Their Business: Exploring Security and Privacy Concerns around Assistive Technology Use in Educational Settings,” ACM Trans Access Comput, vol. 17, no. 2, p. 7:1-7:30, Jul. 2024, doi: 10.1145/3670690.
[4] “Plain Language,” U.S. Office of Personnel Management. Accessed: Jul. 28, 2026. [Online]. Available: https://www.opm.gov/information-management/plain-language/
[5] “Using Plain Language to Support Individuals with Cognitive Disabilities,” University of Colorado. Accessed: Jul. 28, 2026. [Online]. Available: https://www.cu.edu/coleman/resources/plain-language/using-plain-language-support-individuals-cognitive-disabilities
[6] V. Cobigo et al., “Protecting the privacy of technology users who have cognitive disabilities: Identifying areas for improvement and targets for change,” J. Rehabil. Assist. Technol. Eng., vol. 7, p. 2055668320950195, Sep. 2020, doi: 10.1177/2055668320950195.
[7] “From Inside The House: How Surveillance Tech Further Threatens Independent Living,” Disability Culture Lab. Accessed: Jul. 28, 2026. [Online]. Available: https://www.disabilityculturelab.org/posts/from-inside-the-house-how-surveillance-tech-further-threatens-independent-living
[8] F. Hamidi, K. Poneres, A. Massey, and A. Hurst, “Who Should Have Access to my Pointing Data? Privacy Tradeoffs of Adaptive Assistive Technologies,” in Proceedings of the 20th International ACM SIGACCESS Conference on Computers and Accessibility, in ASSETS ’18. New York, NY, USA: Association for Computing Machinery, Oct. 2018, pp. 203–216. doi: 10.1145/3234695.3239331.
[9] K. Crawford, Y. X. Khoo, A. Kumar, H. Mentis, and F. Hamidi, “Decoding the Privacy Policies of Assistive Technologies,” in Proceedings of the 21st International Web for All Conference, in W4A ’24. New York, NY, USA: Association for Computing Machinery, Oct. 2024, pp. 87–95. doi: 10.1145/3677846.3677850.
[10] “CDT - Inclusive Innovation: How to Incorporate Privacy into Inclusive Design for Assistive Technologies.” Accessed: Jul. 28, 2026. [Online]. Available: https://cdt.org/wp-content/uploads/2025/07/2025-09-15-CDT-Issue-Brief-Inclusive-Innovation-FINAL.pdf
[11] H.-P. (Hank) Lee, Y.-J. Yang, T. S. Von Davier, J. Forlizzi, and S. Das, “Deepfakes, Phrenology, Surveillance, and More! A Taxonomy of AI Privacy Risks,” in Proceedings of the 2024 CHI Conference on Human Factors in Computing Systems, in CHI ’24. New York, NY, USA: Association for Computing Machinery, May 2024, pp. 1–19. doi: 10.1145/3613904.3642116.



