CI Washing Bingo

Spot common misuses and oversimplifications of Contextual Integrity.

đź“– What is Contextual Integrity (CI) Washing?

CI washing, as defined by Shvartzshnaider and Duddu (2025), refers to the use Contextual Integrity (CI) framework without full adherence to its core theoretical commitments. CI is grounded in four central tenets (Nissenbaum, 2019):

  • T1. Privacy is understood as appropriate information flow.
  • T2. Appropriateness is determined by contextual privacy norms.
  • T3. Information flows are specified via five parameters.
  • T4. Normative validity is assessed through the CI heuristic.
References
Nissenbaum, H. (2019). Contextual Integrity up and down the data food chain.
Shvartzshnaider, Y., & Duddu, V. (2025). “Position: Contextual integrity is inadequately applied to language models.”
Wrong CI citation
Omitting CI parameters
Equating law to norms
CI as data minimization
CI to protect private or personal data
CI as secrecy
CI as data leakage
CI as purpose limitation
CI for compliance
Preferences not norms
No CI heuristic
Contextual roles and capacities ignored
Anonymity = transmission principle
Mistreating context
?

Glossary

Click a bingo square to view its explanation, or select

Wrong CI Citation

Citing an outdated source as the primary reference.

Do not cite:
Nissenbaum, Helen. "Privacy as contextual integrity." Washington Law Review 79 (2004): 119.
Instead, please refer to more recent and authoritative accounts of the theory, such as Nissenbaum (2009) and Nissenbaum (2019).
Recommended citations
Nissenbaum, H. (2009). Privacy in Context.
Nissenbaum, H. (2019). Contextual Integrity Up and Down the Data Food Chain.
Nissenbaum, H. (2015). "Respect for context as a benchmark for privacy online: What it is and isn’t." In Social Dimensions of Privacy: Interdisciplinary Perspectives, pp. 278–302.

Omitting CI parameters

Failing to specify one or more of the five transmission parameters — sender, receiver, subject, information type, and transmission principle — thereby preventing a complete evaluation of whether the information flow conforms to contextual norms.

To ascertain whether an action or a practice respects privacy, values for all five parameters must be specified in order to map resulting flows onto governing norms. The comparative template that CI provides has, arguably, served as one of its most successful contributions, for it effectively reveals changes to which other approaches are blind. - Nissenbaum, 2019
Reference
Nissenbaum, H. (2019). Contextual Integrity up and down the data food chain.

Equating law to norms

Treating existing statutes or regulatory compliance as if they fully determine contextual legitimacy, rather than analyzing whether the law actually reflects or distorts entrenched social informational norms.

CI as data minimization

Reducing Contextual Integrity to the idea of collecting or share less data, instead of examining whether the structure and conditions of information transmission are appropriate within the relevant social context.

Privacy as contextual integrity does not accept the implications of other definitions that identify privacy with no flow, with stoppage, secrecy, and data minimization" - Nissenbaum, 2019
Reference
Nissenbaum, H. (2019). Contextual Integrity up and down the data food chain.

CI to protect private or presonal data

Reducing Contextual Integrity to the notion of protecting private and personal data (i.e., one CI parameter) instead of examining all CI parameters to evaluate the appropriateness within the relevant social context. whether the structure and conditions of information transmission are appropriate within the relevant social context.

To ascertain whether an action or a practice respects privacy, values for all five parameters must be specified in order to map resulting flows onto governing norms. The comparative template that CI provides has, arguably, served as one of its most successful contributions, for it effectively reveals changes to which other approaches are blind. - Nissenbaum, 2019
Reference
Nissenbaum, H. (2019). Contextual Integrity up and down the data food chain.

CI as data leakage

Reducing Contextual Integrity to a notion of "leakage" or sharing of specific data types with unintended party, rather than examining whether the structure and conditions of information transmission using the CI parameters are appropriate within the relevant social context.

"[CI] does not agree that when Alice and Bob are talking, Eve always violates their privacy. It does not identify data leakage as a privacy harm, or any collection as privacy violation. CI cares only whether the flow is appropriate, not whether it takes place at all."" - Nissenbaum, 2019
Reference
Nissenbaum, H. (2019). Contextual Integrity up and down the data food chain.

CI as data secrecy

Reducing Contextual Integrity to a notion of privacy as secrecy, or merely the "stoppage of flow," rather than examining whether the structure and conditions of information transmission are appropriate within the relevant social context.


"[CI] does not agree that when Alice and Bob are talking, Eve always violates their privacy."
...
If privacy were stoppage, or secrecy, it would stand to reason that more often than not it would need to be traded off against other useful, socially valuable exchanges. But, as contextual integrity, privacy allows for information flows that are appropriate, including flows needed to promote utility — i.e., security, convenience, and the like." - Nissenbaum, 2019
Reference
Nissenbaum, H. (2019). Contextual Integrity up and down the data food chain.

CI as purpose limitation

Collapsing CI into simple purpose-restriction logic (e.g., GDPR-style use limits) while ignoring how roles, actors, and transmission principles jointly structure legitimate information flows.


" [Fred Cate poited out] FIPPS themselves do not provide privacy protection, merely procedural guidance whose substantive clout is indeterminate. According to Cate the FIPPS purpose specification principle offers some traction for privacy protection. He points out, however, that unless constraints are placed on what purposes are legitimate (and why), a purely procedural Purpose Specification Principle opens a glaring loophole in FIPPS. This point is crucial for my argument about context." - Nissenbaum, 2015
Reference
Nissenbaum, H. (2015). Respecting Context to Protect Privacy: Why Meaning Matters
Cate, Fred H. (2016) The failure of fair information practice principles." Consumer Protection in the Age of the'Information Economy'. Routledge, 2016. 341-377.

CI for compliance

Deploying CI as a checkbox audit tool or defensive legal framework rather than as a normative diagnostic method for critically evaluating questionable or status-quo data practices.

"[CI is different] from procedural definitions, such as privacy as compliance with FIPPs or as control over information about oneself, which also do not distinguish between data primitives and semantically meaningful data. Although, on the face of it, these alternatives sidestep the challenge, a closer look indicates they may, in fact, be kicking it down the road." - Nissenbaum, 2019
Reference
Nissenbaum, H. (2019). Contextual Integrity up and down the data food chain.

Preferences not norms

Substituting individual user settings, consent clicks, or privacy preferences for socially grounded informational norms, which are collective, context-dependent, and not reducible to personal choice.


" Contextual purposes and values sometimes may disfavor the data subject’s interests, even in the healthcare context. Having advanced in our understanding of environmental health hazards and communicable diseases, CI may support overriding individual patient interests or preferences in favor of onward sharing of information with others, for example, public health officials. " - Nissenbaum, 2019
Reference
Nissenbaum, H. (2019). Contextual Integrity up and down the data food chain.

No CI heuristic

Reaching conclusions about privacy violations without applying the structured CI decision heuristic: mapping the flow, identifying baseline norms, comparing altered flows, and evaluating moral and contextual impact.

"Radical changes in the nature of data and surrounding technologies outpace the capacity to proceed according to the discrete steps of the CI heuristic — first to locate divergences in entrenched norms measured in terms of the five parameters and then to evaluate them. However, despite the need to relax and revise the mechanics of the heuristic, I remain convinced that a) mapping the data flows in terms of the five parameters and b) evaluating these flows, to the best of our knowledge, in terms of interests, values, and contextual ends — messy, uncertain, and burdensome as it may be — remains an ideal worth striving for." - Nissenbaum, 2019
Reference
Nissenbaum, H. (2019). Contextual Integrity up and down the data food chain.

Contextual Roles and Capacities Ignored

Not stating the parameter CI values in terms of their respective contextual role ontologies.

"First, values for actor and information-type parameters are identified in terms of respective contextual ontologies. Subjects, senders, and recipients are described in their contextual roles, that is, are acting in capacities drawn from contextual ontologies, whether physician, teacher, elected politician, priest, customer, police officer, investor, friend, or congregant. Information likewise is conceptualized according to contextual ontologies, whether symptoms, medications, grades, voting records, demographics, salary, social security number, or church donations. - Nissenbaum, 2019
Reference
Nissenbaum, H. (2019). Contextual Integrity up and down the data food chain.

Anonymity as a transmission principle (TP)

Anonymity or anonymously is not a valid TP value. These terms may describe an information flow involving data (attributes) without identifiers.
TPs define the conditions under which data about a subject may flow from a sender to a recipient: Commonly occurring TPs include with consent, reciprocally, with notice, in confidence, as required by law, and with a warrant.
Until now, the greatest obligation of data gatherers was either to anonymize data and pull it outside various privacy requirements or to inform and obtain consent. After charting the increasing difficulty of fulfilling these obligations in the face of big data, we presented the ultimate challenge: not of practical difficulty but of irrelevance. Where, for example, anonymizing data, adopting pseudonyms, or granting or withholding consent makes no difference to outcomes for an individual, we had better be sure that the outcomes in question can be defended as morally and politically legitimate. - Barocas, S., & Nissenbaum, H. (2014).
Reference
Barocas, S., & Nissenbaum, H. (2014). Big data’s end run around anonymity and consent.

Mistreating context

Context is treated as a localized setting focused on specific information flows rather than a broad social construct.


"Many of the canonical activities of a context are oriented around values-sometimes more aptly called goals, purposes, or ends; that is, the objectives around which a context is oriented, something akin to Schatzkis 'teleology.' Values are crucial, defining features of contexts." - Nissenbaum, 2009
Reference
Nissenbaum, H. (2009). Privacy in Context.

Invoking the "Context boundaries" metaphor

Invoking “contextual boundaries” is a misleading spatial metaphor that treats contexts as if they were discrete containers separated by clear borders.

“Contexts are structured social settings characterized by canonnonical activities, roles, relationships, power structures, norms (or rules), and internal values (goals, ends, purposes).” (Nissenbaum, 2009)
Reference
Nissenbaum, H. (2009). Privacy in Context.

Invoking "Context collapse"

Using “context collapse” as a general buzzword without analyzing which distinct social contexts, actors, or transmission principles are being structurally merged or disrupted.

"Contexts may overlap and possibly conflict with one another.”
...
"Overlaps need not necessarily involve conflicts. Thus, a community health center may collaborate with school authorities to promote health and nutrition within schools. It is not so much that contexts themselves conflict as that, occasionally, when and where they overlap the norms from one context prescribe actions that are proscribed by the norms of an overlapping context." (Nissenbaum, 2009)

"Statistical" context

Confusing computational or machine-learning “context” with socially defined informational contexts governed by privacy norms.

Reference
Nissenbaum, H. (2009). Privacy in Context.
Schatzki, T. R. (2005). Practice mind-ed orders. In The practice turn in contemporary theory (pp. 50-63). Routledge.