The increasingly widespread of generative artificial intelligence (GenAI) have challenged the security of user personal information (UPI). This study aims to investigate the current situation of UPI processing and protection in GenAI services through platform policies and proposes improvement strategies.
This paper employed a qualitative text analysis method, selecting 59 state-registered Chinese GenAI service platforms as research objects. The inductive-deductive category construction was applied to provide a systematic interpretation of these platforms’ policies, extracting key points and characteristics of UPI processing and protection. Then the numbers and proportions of platforms addressing specific vital points were counted to identify existing problems.
The platforms haven’t fully demonstrated the functional characteristics and risks of GenAI, hindering users’ self-management and cooperation with platforms to protect UPI. The protection measures are relatively single. To address these issues, the study recommends developing clear policy standards for GenAI service platforms, and involving users and experts in policy formulation. Platforms should strengthen filtering, anonymization and de-identification combined with encryption technologies. Enhancing public AI literacy and technical risk response capabilities is advised.
This study emphasizes the importance of platform policies in protecting UPI in GenAI services. It analyses the general content framework of current GenAI service platform policies and proposes specific strategies for optimizing protection from the perspectives of regulators, platforms and users. The findings offer practical references for platform policies and standards formulation and promote collaborative UPI protection between platforms and users.
