Dark Patterns after the GDPR: Scraping Consent Pop-ups and Demonstrating their Influence

01/08/2020
by   Midas Nouwens, et al.
0

New consent management platforms (CMPs) have been introduced to the web to conform with the EU's General Data Protection Regulation, particularly its requirements for consent when companies collect and process users' personal data. This work analyses how the most prevalent CMP designs affect people's consent choices. We scraped the designs of the five most popular CMPs on the top 10,000 websites in the UK (n=680). We found that dark patterns and implied consent are ubiquitous; only 11.8 based on European law. Second, we conducted a field experiment with 40 participants to investigate how the eight most common designs affect consent choices. We found that notification style (banner or barrier) has no effect; removing the opt-out button from the first page increases consent by 22–23 percentage points; and providing more granular controls on the first page decreases consent by 8–20 percentage points. This study provides an empirical basis for the necessary regulatory action to enforce the GDPR, in particular the possibility of focusing on the centralised, third-party CMP services as an effective way to increase compliance.

READ FULL TEXT

page 1

page 6

research
04/19/2018

A spark is enough in a straw world: a study of websites password management in the wild

With the entry into force of the General Data Protection Regulation (GDP...
research
08/15/2018

We Value Your Privacy ... Now Take Some Cookies: Measuring the GDPR's Impact on Web Privacy

The European Union's General Data Protection Regulation (GDPR) went into...
research
02/02/2022

Opted Out, Yet Tracked: Are Regulations Enough to Protect Your Privacy?

Data protection regulations, such as GDPR and CCPA, require websites and...
research
04/26/2021

I am Definitely Manipulated, Even When I am Aware of it. It s Ridiculous! – Dark Patterns from the End-User Perspective

Online services pervasively employ manipulative designs (i.e., dark patt...
research
07/15/2023

Privately Policing Dark Patterns

Lawmakers around the country are crafting new laws to target "dark patte...
research
05/22/2022

rgpdOS: GDPR Enforcement By The Operating System

The General Data Protection Regulation (GDPR) forces IT companies to com...

Please sign up or login with your details

Forgot password? Click here to reset