Research project · Data governance
turning regulatory goals into design and code
Evidence-informed and human-centered data governance policies based on privacy-enhancing DEsign and CODE.
Data protection law promises that people can understand how their data is processed and decide what happens to it. In practice, that promise is settled elsewhere: in the interface designs people are shown and the software code that runs underneath. DECODE builds the evidence base regulators need to govern both — and to make transparency and empowerment something individuals actually experience in smart environments.
About
Smart devices increasingly mediate everyday life. Technology companies design our interactions with them and write the code that determines how much personal information is processed — and so, in practice, how the right to informational privacy is honoured.
Privacy-invasive designs and code are abundant. Yet the same fields — human-computer interaction, computational law, and computer science — also produce privacy-enhancing designs and technologies. What is missing is the scientific evidence that would let regulators put them to work.
Strategy papers in Switzerland and the EU call for human-centered data governance. On the ground, individuals face opaque, one-size-fits-all data processing and a complex patchwork of rules they must fight to enforce. DECODE closes that gap by systematically analyzing interface designs, privacy-enhancing technologies, and the encoding of data protection rights; by testing them with users; and by translating what we learn into a form regulators can act on. The project combines methodologies from legal design, HCI, and evidence-informed policymaking, and works with data protection authorities, civil society, standard-setting bodies, and policymakers throughout.
Overarching research question
To what extent can regulators leverage design and code to foster a human-centered data governance regime?
Research
Three sub-questions build towards the overarching question. Each is a block of the evidence base: what design and code can do, what personalization adds and costs, and how the resulting findings change the regulatory process itself.
RQ 1
Dark patterns, information overload, and invisible processing leave people unable to grasp what happens to their data — and unable to act on it. We study transparency measures such as privacy labels, icons, and inspectable data flows alongside empowerment mechanisms that encode individual rights so they can be exercised automatically rather than through an uphill battle.
RQ 2
Personalized disclosures and settings could make protection more effective — or erode the uniform application of the law. We test where tailoring genuinely helps people understand and act, and where the arguments for uniform rules should prevail, connecting the legal debate on personalized law to the design field for the first time.
RQ 3
Evidence-informed policymaking, anticipatory regulation, and policy prototyping share a collaborative, future-oriented view of regulation, but have gained little traction in data governance. We put them to work on our own findings and evaluate what they produce.
DECODE runs for four years across three consecutive work packages, moving from exploration to experimentation to translation. Empirical work starts with conversational agents and smart speakers in home settings, then examines how the findings transfer to other domains.
We systematize the transparency- and empowerment-enhancing approaches and personalization mechanisms scattered across HCI, computational law, and computer science, and link them into one typology. Expert interviews fill the gaps the literature leaves open.
We build six prototypes — two on transparency, two on empowerment, two on personalizing both — and measure their effects on understanding, behavioral change, and acceptability. Where data-driven methods are used, we document compliance with current AI regulation.
We take the evidence to the people who can act on it. Structured workshops with data protection authorities, civil society, industry, and policymakers turn findings into regulatory learnings, best practices, and digital-ready policies that lend themselves to machine execution.
Groundwork
DECODE builds on the team's joint work on Visual Privacy, a web plugin that reads a privacy policy and uses generative AI to produce a visual label rating it from A to F. In an online experiment mimicking a news aggregator (n = 825) and an accompanying survey, the ratings measurably shifted how people judged a site's risks and benefits, with an indirect effect on privacy protection behavior. Over 75% of participants said they would like such labels to become mandatory. The work was presented at the CNIL Privacy Research Days 2025, and the accompanying paper has since been accepted in ACM Transactions on Social Computing.
Read the paper →News
September 2026
The DECODE website is live. Project updates, outputs, and open positions will be published here as the project progresses.
2025
The team's work on AI-generated visual privacy labels, which forms part of the groundwork for DECODE, was presented at the CNIL Privacy Research Days and has attracted interest from the French data protection authority.
Team
DECODE brings together expertise in law, communication research, human-computer interaction, and computer science. The co-principal investigators and the project partner have collaborated on privacy and data-related aspects of emerging technologies for a decade.
Project leads
Co-PI
Aurelia Tamò-Larrieux
Law & technology
University of St.Gallen
Researchers
Open position
PhD researcher, Law
University of St.Gallen
Open position
PhD researcher, Empirical social science
BI Norwegian Business School
Open position
Postdoctoral researcher, Digital law
University of St.Gallen
Open position
PhD researcher, Computer science
University of St.Gallen
Partners
In cooperation with
Many events hosted by the Future Society Hub are relevant to DECODE — have a look at the FuSo events calendar.