User Agreements in Digital Mental Health Services: Analysis and Insights

A recent study published on a preprint platform osf.io analyzed 139 user agreements from digital mental health services in Singapore, revealing concerns about data management and informed consent. The research used a mixed-methods approach to examine privacy policies and terms of service from various providers, including international mobile applications, local commercial services, and social service agencies. The findings suggest that while most privacy policies address data collection, fewer cover post-service data management, and terms of service often fail to provide mechanisms for assessing user comprehension.

Key Takeaways:

  • The study examined 139 user agreements from digital mental health services in Singapore, including 79 privacy policies and 60 terms of service.
  • Most privacy policies (83.5%) addressed data collection practices, but fewer (45.6%) covered post-service data management.
  • Terms of service extensively detailed user obligations but only 1.67% included mechanisms to assess user comprehension.
  • The documents demonstrated challenging readability levels, requiring approximately 16 years of education, and power asymmetries between service providers and users.
  • Local services showed variable compliance with Singapore's Personal Data Protection Act, with only 8.33% addressing data breach notification requirements.
  • The CLEAR framework (Comprehensible, Legitimate, Equitable, Accessible, Respectful) is proposed to guide the development of user agreements that support genuine informed consent.

Statistics:

  • 139 user agreements from digital mental health services in Singapore were analyzed.
  • 79 privacy policies and 60 terms of service were examined.
  • 83.5% of privacy policies addressed data collection practices.
  • 45.6% of privacy policies covered post-service data management.
  • 1.67% of terms of service included mechanisms to assess user comprehension.
  • Documents required approximately 16 years of education to be readable.
  • 8.33% of local services addressed data breach notification requirements.

Sources:

  • [osf.io]
  • [Singapore's Personal Data Protection Act]