Drowning in EULA, T&S, and Privacy Policy Updates

Introduction

If you use a computer in almost any capacity, you have been exposed to an End-User License Agreement (EULA) before. As far as Internet lore goes they have a special place in infamy and contempt. Even before the Internet as well as the early days it was worse in some ways. When you went to a store and purchased software that came in a box you found yourself facing a Catch-22. You had to remove the shrink-wrap plastic around the box to open it where you would find the software medium (e.g. floppy disc, CD-ROM) as well as the EULA. You had to agree to the EULA before using the software. If the box was opened you could not return it for a refund. You see the problem here?

This was referred to as a “shrink-wrap license” back then referring to the Catch-22. Since then the prevalence of EULAs has become ridiculous as every single piece of hardware and software you purchase has one. Many EULAs have thousands of words and take considerable time to read, if you can even understand the legal jargon. They are written by lawyers, for lawyers, not the end users. Because we’re subjected to so many it leads many to question if they are even read. Very rarely is the answer to that question. Designer Dima Yarovinsky is one of many over the years to print out EULAs to show how comically absurd they are. Further, there is debate if they are even enforceable in court as tracked by PILOT Lab in their “EULA OF DESPAIR” project.

(Image by Dima Yarovinsky)

It didn’t take long for EULAs to get increasingly more verbose and in some cases egregious. Others are ridiculous in a variety of ways. Software companies and developers are well-aware that users rarely read them, and some have fun with it, going so far as to offer rewards for reading them. Aleecia M. McDonald and Lorrie Faith Cranor asked and answered the questionif website users were to read the privacy policy for each site they visit just once a year, what would their time be worth?” They found that the cost for the time to read such policies “is on the order of $781 billion“.

Beyond the ludicrous and amusing though is the question on the validity and potential severity of the EULA. Andrea Matwyshyn, in her beefy paper titled “The Internet of Bodies” (IOB) goes into detail about the complexity of EULAs as applied to the evolution of technology, specifically ones directly related to health and implants. Amusingly, she notes that “Chief Justice John Roberts has admitted to not always reading” EULAs either. Her paper goes on to discuss how “some IoT companies have allegedly threatened to deactivate or “brick” devices unless a consumer assents to contract changes relating to data privacy and information sharing. In IoB contexts, that potentially bricked device may be embedded in a body, and may control physical functionality of that body.” The implications of this are heavy and scary.

It Gets Worse

Of course EULAs get worse every year between the increase in wordcount, more complicated legal jargon, and legal overreach. That said, the problem is related to that but comes in the form of EULA updates. Starting in 2019 I started saving the emails from services (primarily) that notified me of changes to their Terms & Services (T&S), which is a EULA by a different name. But this is the tip of the iceberg as there are many facets to this problem.

Perhaps the most troubling for the end-user, meaning you, is that the email notifications often are brief notifications that the T&S have changed and link to it on a web site. So you have to go to the site and presumably re-read something you have mostly read before, try to determine what changed, and then likely become confused between the legal jargon and what often seems like contradictory language, all of which is often tied to a second privacy policy that the company says applies as noted in “Privacy, The Hacker Way“. Like EULAs, T&S are often clicked through without reading. Some applications try to enforce ‘reading’ by making you scroll to the end before you can agree. Doesn’t matter if you do all of that in four seconds and agree, they don’t put a mandatory ‘reading time’ before you can click. I am sure the enforced scrolling is another way corporate lawyers can help defend the terms you agreed to.

Even if you read the email, click through, and read the new terms, so what? Did you save a copy? If not you have agreed to something that you don’t even have a copy of any longer. If you are lucky that version of the page might be saved on a site like the Internet Archive’s Wayback machine. In the extremely unlikely case you ended up in court over a breach of such terms the first thing you would have to do is have your lawyer obtain a copy of what you agreed to from the prosecuting attorneys.

Another issue with this update process is that even if you had read the EULA / T&S originally, perhaps a year or three prior, you are now forced to re-read the entire thing if you are interested in what changed. But will you remember what the original said to mentally compare and see what changed? Of course not. It becomes an easy way for companies to sneak in more changes that benefit them. Unless you save copies of every T&S and then compare the two you are at their mercy. If you are lucky the email might summarize what changed, but that will be in friendly, readable terms that you can understand, not the actual complicated legal jargon that lies beneath.

(Gemini created using reference image of Lazlo and gold coins.)

Since I started saving them, Google has sent 40 updates for their various services, PayPal 24, Ebay 23, Amazon 13, and even LEGO / BrickLink has sent seven updates. In total, I have received 304 emails about updates to T&S, privacy policies, “legal agreements”, “policies”, Policy & Controls, user agreements, terms of use, ads setting controls, “settings”, “personalization”, ad terms, privacy notice, arbitration agreements, program sunsetting, program updates, “cancellation experience”, and “experiences”. A legal agreement by any other name…

It’s also worth noting that these changes are occasionally not clearly reflected in the subject of the email. While a vast majority do make it clear with the wording above, DHL sent an email in 2023 with a subject “DHL On Demand Delivery” that doesn’t speak to the content of the email. Reading it then makes it clear that “have introduced a new Terms of Use for DHL Express On Demand Delivery“. The shortest email came from LiveJournal in 2022 at a measly 4.8KB. The largest was from Marvel Insider in 2025 that came in at 125KB. That larger email though still did not have the actual T&S included, it linked to it.

This matters because the actual T&S can be substantial. A recent “update” to Capitol One Shopping came in an email that said it had “updated Capital One Shopping’s User Agreement, including adding an agreement to arbitrate any disputes you may have with us.” It sounds like one important update but “including” means there are other updates. That agreement is 12,420 words and the text alone is 79k. To put that in perspective, that is about 12% of a beefy adult novel. So if just eight companies want you to agree to similar terms of service and you read all of them, it is the equivalent of reading The Hobbit or The Da Vinci Code.

As someone who occasionally skims or searches for words in these agreements out of morbid curiosity, I did find it refreshing that the current T&S from Capitol One Shopping is actually friendly to the user. The arbitration agreement that was updated may or may not have changed this part, but the first thing I look for is the state that arbitration will happen. Companies typically stipulate it will happen in a state that is favorable to them in some manner. Either in the state of their headquarters, where their lawyers are located, or a jurisdiction they find has favorable rulings. In this case, arbitration will happen in the state the consumer lives in. Wow, that’s actually pretty nice of them. Also, Capitol One can go to hell for excluding their sites from the Internet Archive Wayback machine meaning we can’t more easily preserve copies in a public manner.

Fixing the Problem

So what do we do, or how do we fix the problem? There isn’t an easy solution because lawyers gonna’ lawyer when it comes to EULAs and T&S. Some lawyers make a career out of the laws surrounding this and companies use it to protect themselves, often overly so in an unfair way to the consumer. One idea is that a body like the Federal Trade Commission (FTC) come up with a framework for a EULA / T&S that uses more standard language that gives more equality in such agreements. The FTC could then push for companies to adopt that language in some manner perhaps. Theoretically this would benefit consumers while still giving adequate protection from liability to corporations.

PILOT Labs has proposed Short Form EULA Disclosure Statements as one way to help address the problem. “Modeled on (the spirit of) securities regulation filings, real estate and other disclosure forms, and food labeling approaches, this type of uniform disclosure allows for easy head-to-head comparison of products and services and encourages independent analysis to guide informed market choices.” The site goes on to propose such a form.

Another idea is for lawyers that are against aggressive EULAs and T&S to digest these updates and write about them in terms that consumers can understand. For those interested in such changes we would be able to read a blog or subscribe to a newsletter for the reader-friendly updates. A nonprofit made up of lawyers that do this would be phenomenal to see.

Finally, a change in the law that requires corporations to make a condensed, reader-friendly version of their T&S for customers would be great. Lawyers would still agonize over every word to seek any minute change that would favor them of course, but it would still make the language understandable to non-lawyers. If you have never gone back and forth with a lawyer over a legal contract making changes or “redlining“, you won’t understand how such minor changes in a single word can have significant differences in the meaning. Failing that, requiring companies to give a redlined version of the EULA, T&S, and/or Privacy Policy that clearly show every single change would be helpful.

Leave a Reply

Discover more from Rants of a deranged squirrel.

Subscribe now to keep reading and get access to the full archive.

Continue reading