The Role of Privacy Guarantees in Voluntary Donation of Private Health Data for Altruistic Goals

Ruizhe Wang (University of Waterloo)

Network and Distributed System Security (NDSS) Symposium 2026 · Day 3 · Covert Sensing

Overview

This user study examines whether presenting privacy protection guarantees (anonymization, access control, data expiration, purpose restriction) and auditing guarantees (expert auditing, self-auditing) increases people's willingness to donate their medical data for research. Surveying 494 US-based participants, the researchers found a counterintuitive result: presenting privacy protections alone does not significantly increase donation willingness. Instead, non-privacy factors -- such as whether the collecting entity is nonprofit or for-profit, the participant's prior donation history, and general trust levels -- dominate the decision. Auditing guarantees show promise for building trust, even for for-profit entities, but participants struggle to understand what cryptographic auditing means in practice.

Watch on YouTube · Slides

Visual summary for The Role of Privacy Guarantees in Voluntary Donation of Private Health Data for Altruistic Goals by Ruizhe Wang
Visual summary for The Role of Privacy Guarantees in Voluntary Donation of Private Health Data for Altruistic Goals by Ruizhe Wang

Key moments

  1. 0:00 Data breaches and public reluctance to share health data
  2. 2:00 Four privacy guarantees and two auditing guarantees studied
  3. 4:00 Survey methodology and donation scenario design
  4. 6:00 Results: privacy expectations vs actual protection presentation
  5. 8:00 Why people distrust: entity type matters more than protections
  6. 10:00 Regression model: protections alone make no difference in donation willingness
  7. 12:00 Summary: auditing promising but needs better communication

The Role of Privacy Guarantees in Voluntary Donation of Private Health Data for Altruistic Goals

Speakers: Ruizhe Wang

Conference: NDSS Symposium

YouTube: https://www.youtube.com/watch?v=Emc93EPZkcU

Overview

This user study examines whether presenting privacy protection guarantees (anonymization, access control, data expiration, purpose restriction) and auditing guarantees (expert auditing, self-auditing) increases people's willingness to donate their medical data for research. Surveying 494 US-based participants, the researchers found a counterintuitive result: presenting privacy protections alone does not significantly increase donation willingness. Instead, non-privacy factors -- such as whether the collecting entity is nonprofit or for-profit, the participant's prior donation history, and general trust levels -- dominate the decision. Auditing guarantees show promise for building trust, even for for-profit entities, but participants struggle to understand what cryptographic auditing means in practice.

Background

▶ Watch: Data breaches and public reluctance to share health data (0:00)

Medical research requires large-scale personal health data, but data breaches affecting millions of records have made people wary of sharing. A 2017 UK survey found 43% concerned about accidental data loss, 62% worried about hackers, and 70% suspicious that recipients would misuse their data. The technical community has developed privacy-preserving technologies (encrypted queries, differential privacy, secure ML training), but whether these guarantees actually influence donation decisions has not been empirically studied.

Key Findings

▶ Watch: Survey methodology and donation scenario design (4:00)

  • Presenting privacy protections makes almost no difference in donation willingness, even with auditing guarantees added
  • People who expect protections to exist are more willing to donate, but the presentation of protections does not reliably create that expectation
  • Non-privacy factors dominate: entity type (nonprofit vs. for-profit), prior donation history, and general trust levels matter more than technical protections
  • 25% of participants don't trust the protection statement itself, regardless of what it promises
  • Auditing guarantees show promise for building trust, but participants fail to understand the strength of cryptographic auditing when combined with privacy protections
  • The halo effect (overall positive impression of an entity) and horn effect (single negative impression causing overall distrust) drive decisions more than rational assessment of technical guarantees

Technical Deep Dive

▶ Watch: Results: privacy expectations vs actual protection presentation (6:00)

The study used a between-subjects survey design with scenarios varying across four dimensions: privacy guarantee type (anonymization, access control, data expiration, purpose restriction), auditing guarantee (expert auditing, self-auditing, none), collection entity type (for-profit/nonprofit), and egocentricity (whether the participant or close relative has the disease). A regression model identified which factors significantly predicted donation willingness. Understanding questions filtered out participants who could not comprehend the scenario statements.

Demo / Proof of Concept

▶ Watch: Regression model: protections alone make no difference in donation willingness (10:00)

The survey recruited 560 participants from Prolific (494 included in analysis), US-based, gender-balanced, with $1.20 compensation and ~6 minute completion time. Cognitive interviews and pilot studies validated scenario comprehension. Open-text responses were coded to identify trust/distrust drivers.

Defensive Implications

▶ Watch: Summary: auditing promising but needs better communication (12:00)

For organizations collecting health data: technical privacy protections are necessary but insufficient for encouraging data donation. Building institutional trust through non-technical means (reputation, nonprofit status, transparency) matters more. Auditing guarantees should be communicated in accessible terms, potentially using AI-assisted verification tools to make cryptographic auditing practical for non-technical users.

Key Takeaways

  • Presenting privacy protections alone does not increase medical data donation willingness
  • Non-privacy factors (entity type, trust, donation history) dominate donation decisions
  • 25% of participants distrust protection statements regardless of content; 10% distrust the entity entirely
  • Auditing guarantees show promise but need better communication to be understood
  • The halo/horn effect means organizational reputation matters more than technical guarantees
  • Future work should focus on effectively communicating auditing guarantees to build trust

About the Speaker(s)

Ruizhe Wang (Rael) is from the University of Waterloo. The research focuses on the intersection of privacy-preserving technologies and human factors, studying how technical privacy guarantees influence real-world data sharing behavior.

Reviews

Dr. Zero (Offensive Security Researcher) — HARD PASS

A user study about health data donation willingness that finds privacy protections don't increase donation rates. While methodologically sound, this is a social science survey with no technical security content -- no attacks, no defenses, no tools, no novel techniques. The finding that 'presenting protections doesn't matter' is interesting for policy but irrelevant for anyone doing security work.

Heather Calloway (CISO) — USEFUL

A methodologically sound user study revealing that technical privacy protections alone do not increase people's willingness to donate health data. For CISOs and privacy officers building data collection programs, the finding that institutional trust and entity reputation matter more than technical guarantees is actionable for program design.

→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2026

All talks from Network and Distributed System Security (NDSS) Symposium 2026