TY - JOUR U1 - Zeitschriftenartikel, wissenschaftlich - begutachtet (reviewed) A1 - Tolsdorf, Jan A1 - Dehling, Florian A1 - Reinhardt, Delphine A1 - Lo Iacono, Luigi T1 - Exploring mental models of the right to informational self-determination of office workers in Germany JF - Proceedings on Privacy Enhancing Technologies N2 - Applied privacy research has so far focused mainly on consumer relations in private life. Privacy in the context of employment relationships is less well studied, although it is subject to the same legal privacy framework in Europe. The European General Data Protection Regulation (GDPR) has strengthened employees’ right to privacy by obliging that employers provide transparency and intervention mechanisms. For such mechanisms to be effective, employees must have a sound understanding of their functions and value. We explored possible boundaries by conducting a semistructured interview study with 27 office workers in Germany and elicited mental models of the right to informational self-determination, which is the European proxy for the right to privacy. We provide insights into (1) perceptions of different categories of data, (2) familiarity with the legal framework regarding expectations for privacy controls, and (3) awareness of data processing, data flow, safeguards, and threat models. We found that legal terms often used in privacy policies used to describe categories of data are misleading. We further identified three groups of mental models that differ in their privacy control requirements and willingness to accept restrictions on their privacy rights. We also found ignorance about actual data flow, processing, and safeguard implementation. Participants’ mindsets were shaped by their faith in organizational and technical measures to protect privacy. Employers and developers may benefit from our contributions by understanding the types of privacy controls desired by office workers and the challenges to be considered when conceptualizing and designing usable privacy protections in the workplace. KW - informational self-determination KW - privacy at work KW - mental models KW - usable privacy controls UN - https://nbn-resolving.org/urn:nbn:de:hbz:1044-opus-53837 SN - 2299-0984 SS - 2299-0984 U6 - https://doi.org/10.2478/popets-2021-0035 DO - https://doi.org/10.2478/popets-2021-0035 VL - 2021 IS - 3 SP - 5 EP - 27 S1 - 23 PB - Sciendo ER -