Research project  ·  Data governance

DECODE

turning regulatory goals into design and code

Evidence-informed and human-centered data governance policies based on privacy-enhancing DEsign and CODE.

Law×Communication×HCI×Computer Science

DECODE project mark

Data protection law promises that people can understand how their data is processed and decide what happens to it. In practice, that promise is settled elsewhere: in the interface designs people are shown and the software code that runs underneath. DECODE builds the evidence base regulators need to govern both — and to make transparency and empowerment something individuals actually experience in smart environments.

Regulatory goals are written in law, but decided in design and code.

Smart devices increasingly mediate everyday life. Technology companies design our interactions with them and write the code that determines how much personal information is processed — and so, in practice, how the right to informational privacy is honoured.

Privacy-invasive designs and code are abundant. Yet the same fields — human-computer interaction, computational law, and computer science — also produce privacy-enhancing designs and technologies. What is missing is the scientific evidence that would let regulators put them to work.

From evidence to policy

Strategy papers in Switzerland and the EU call for human-centered data governance. On the ground, individuals face opaque, one-size-fits-all data processing and a complex patchwork of rules they must fight to enforce. DECODE closes that gap by systematically analyzing interface designs, privacy-enhancing technologies, and the encoding of data protection rights; by testing them with users; and by translating what we learn into a form regulators can act on. The project combines methodologies from legal design, HCI, and evidence-informed policymaking, and works with data protection authorities, civil society, standard-setting bodies, and policymakers throughout.

Evidence Design Prototypes Encoded Rights Lab Experiments User Studies Stakeholder Workshops Policy Prototyping Policy

Overarching research question

To what extent can regulators leverage design and code to foster a human-centered data governance regime?

Research questions

Three sub-questions build towards the overarching question. Each is a block of the evidence base: what design and code can do, what personalization adds and costs, and how the resulting findings change the regulatory process itself.

RQ 1

How can design and code promote human-centered transparency and empowerment over data processing?

Dark patterns, information overload, and invisible processing leave people unable to grasp what happens to their data — and unable to act on it. We study transparency measures such as privacy labels, icons, and inspectable data flows alongside empowerment mechanisms that encode individual rights so they can be exercised automatically rather than through an uphill battle.

RQ 2

How can personalization of designs, code, and the law further enhance the goals of transparency and empowerment?

Personalized disclosures and settings could make protection more effective — or erode the uniform application of the law. We test where tailoring genuinely helps people understand and act, and where the arguments for uniform rules should prevail, connecting the legal debate on personalized law to the design field for the first time.

RQ 3

How can we methodologically innovate the regulatory process and outcomes to enable a human-centered data governance regime?

Evidence-informed policymaking, anticipatory regulation, and policy prototyping share a collaborative, future-oriented view of regulation, but have gained little traction in data governance. We put them to work on our own findings and evaluate what they produce.

Work packages

DECODE runs for four years across three consecutive work packages, moving from exploration to experimentation to translation. Empirical work starts with conversational agents and smart speakers in home settings, then examines how the findings transfer to other domains.

WP1

Exploration

We systematize the transparency- and empowerment-enhancing approaches and personalization mechanisms scattered across HCI, computational law, and computer science, and link them into one typology. Expert interviews fill the gaps the literature leaves open.

  • Two systematic literature reviews
  • Expert interviews across transparency, empowerment, and personalization
  • A synthesized typology of approaches, published as a report
WP2

Experimentation & evidence

We build six prototypes — two on transparency, two on empowerment, two on personalizing both — and measure their effects on understanding, behavioral change, and acceptability. Where data-driven methods are used, we document compliance with current AI regulation.

  • Six design- and code-based prototypes
  • Usability tests, focus groups, and controlled experiments
  • Representative user studies per prototype (N > 500)
  • A compilation of evaluation metrics for privacy interventions
WP3

Translation

We take the evidence to the people who can act on it. Structured workshops with data protection authorities, civil society, industry, and policymakers turn findings into regulatory learnings, best practices, and digital-ready policies that lend themselves to machine execution.

  • Regulatory briefs from each stakeholder workshop
  • A consolidated report for regulatory audiences
  • A blueprint for interdisciplinary privacy research
  • A closing symposium bringing the communities together

Groundwork

Visual Privacy

DECODE builds on the team's joint work on Visual Privacy, a web plugin that reads a privacy policy and uses generative AI to produce a visual label rating it from A to F. In an online experiment mimicking a news aggregator (n = 825) and an accompanying survey, the ratings measurably shifted how people judged a site's risks and benefits, with an indirect effect on privacy protection behavior. Over 75% of participants said they would like such labels to become mandatory. The work was presented at the CNIL Privacy Research Days 2025, and the accompanying paper has since been accepted in ACM Transactions on Social Computing.

Read the paper →
Preview of the accepted paper “Visual Privacy: The Impact of Privacy Labels on Privacy Behaviors Online”, ACM Transactions on Social Computing

News & updates

September 2026

Project website online

The DECODE website is live. Project updates, outputs, and open positions will be published here as the project progresses.

2025

Visual Privacy presented at the CNIL Privacy Research Days

The team's work on AI-generated visual privacy labels, which forms part of the groundwork for DECODE, was presented at the CNIL Privacy Research Days and has attracted interest from the French data protection authority.

Our team

DECODE brings together expertise in law, communication research, human-computer interaction, and computer science. The co-principal investigators and the project partner have collaborated on privacy and data-related aspects of emerging technologies for a decade.

Project leads

Aurelia Tamò-Larrieux

Co-PI

Aurelia Tamò-Larrieux

Law & technology
University of St.Gallen

Co-PI

Christoph Lutz

Communication & social science
BI Norwegian Business School

Simon Mayer

Project partner

Simon Mayer

Computer science & HCI
University of St.Gallen

Researchers

Open position

PhD researcher, Law

University of St.Gallen

Open position

PhD researcher, Empirical social science

BI Norwegian Business School

Open position

Postdoctoral researcher, Digital law

University of St.Gallen

Open position

PhD researcher, Computer science

University of St.Gallen

Project partners

In cooperation with

Many events hosted by the Future Society Hub are relevant to DECODE — have a look at the FuSo events calendar.