Bouhoula et al (2024) Automated Large-Scale Analysis of Cookie Notice Compliance

flavoursofopenscience's bookmarks 2024-04-09

Summary:

Privacy regulations such as the General Data Protection Regulation (GDPR) require websites to inform EU-based users about non-essential data collection and to request their consent to this practice. Previous studies have documented widespread violations of these regulations. However, these studies provide a limited view of the general compliance picture: they are either restricted to a subset of notice types, detect only simple violations using prescribed patterns, or analyze notices manually. Thus, they are restricted both in their scope and in their ability to analyze violations at scale. We present the first general, automated, large-scale analysis of cookie notice compliance. Our method interacts with cookie notices, e.g., by navigating through their settings. It observes declared processing purposes and available consent options using Natural Language Processing and compares them to the actual use of cookies. By virtue of the generality and scale of our analysis, we correct for the selection bias present in previous studies focusing on specific Consent Management Platforms (CMP). We also provide a more general view of the overall compliance picture using a set of 97k web-sites popular in the EU. We report, in particular, that 65.4% of websites offering a cookie rejection option likely collect user data despite explicit negative consent.

 

Link:

https://www.usenix.org/system/files/sec23winter-prepub-107-bouhoula.pdf

From feeds:

Open Access Tracking Project (OATP) » flavoursofopenscience's bookmarks

Tags:

oa.new oa.surveillance oa.gdpr oa.privacy oa.europe

Date tagged:

04/09/2024, 09:52

Date published:

04/09/2024, 05:52