Cookie Banners, What's the Purpose? Analyzing Cookie Banner Text Through a Legal Lens

10/06/2021
by   Cristiana Santos, et al.
0

A cookie banner pops up when a user visits a website for the first time, requesting consent to the use of cookies and other trackers for a variety of purposes. Unlike prior work that has focused on evaluating the user interface (UI) design of cookie banners, this paper presents an in-depth analysis of what cookie banners say to users to get their consent. We took an interdisciplinary approach to determining what cookie banners should say. Following the legal requirements of the ePrivacy Directive (ePD) and the General Data Protection Regulation (GDPR), we manually annotated around 400 cookie banners presented on the most popular English-speaking websites visited by users residing in the EU. We focused on analyzing the purposes of cookie banners and how these purposes were expressed (e.g., any misleading or vague language, any use of jargon). We found that 89 of banners violated the purpose specificity requirement by mentioning vague purposes, including "user experience enhancement". Further, 30 positive framing, breaching the freely given and informed consent requirements. Based on these findings, we provide recommendations that regulators can find useful. We also describe future research directions.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
11/22/2019

Do Cookie Banners Respect my Choice? Measuring Legal Compliance of Banners from IAB Europe's Transparency and Consent Framework

As a result of the GDPR and the ePrivacy Directive, European users encou...
research
09/20/2023

Legitimate Interest is the New Consent – Large-Scale Measurement and Legal Compliance of IAB TCF Paywalls

Cookie paywalls allow visitors of a website to access its content only a...
research
08/27/2019

Multiple Purposes, Multiple Problems: A User Study of Consent Dialogs after GDPR

The European Union's General Data Protection Regulation (GDPR) requires ...
research
09/21/2020

Dark Patterns and the Legal Requirements of Consent Banners: An Interaction Criticism Perspective

User engagement with data privacy and security through consent banners h...
research
03/09/2022

Usage Control Specification, Enforcement, and Robustness: A Survey

The management of data and digital assets poses various challenges, incl...
research
09/05/2019

(Un)informed Consent: Studying GDPR Consent Notices in the Field

Since the adoption of the General Data Protection Regulation (GDPR) in M...
research
09/02/2023

Data Repurposing through Compatibility: A Computational Perspective

Reuse of data in new contexts beyond the purposes for which it was origi...

Please sign up or login with your details

Forgot password? Click here to reset