We Value Your Privacy ... Now Take Some Cookies: Measuring the GDPR's Impact on Web Privacy

08/15/2018
by   Martin Degeling, et al.
0

The European Union's General Data Protection Regulation (GDPR) went into effect on May 25, 2018. Its privacy regulations apply to any service and company collecting or processing personal data in Europe. Many companies had to adjust their data handling processes, consent forms, and privacy policies to comply with the GDPR's transparency requirements. We monitored this rare event by analyzing the GDPR's impact on popular websites in all 28 member states of the European Union. For each country, we periodically examined its 500 most popular websites - 6,579 in total - for the presence of and updates to their privacy policy. While many websites already had privacy policies, we find that in some countries up to 15.7 25, 2018, resulting in 84.5 websites with existing privacy policies updated them close to the date. Most visibly, 62.1 more than in January 2018. These notices inform users about a site's cookie use and user tracking practices. We categorized all observed cookie consent notices and evaluated 16 common implementations with respect to their technical realization of cookie consent. Our analysis shows that core web security mechanisms such as the same-origin policy pose problems for the implementation of consent according to GDPR rules, and opting out of third-party cookies requires the third party to cooperate. Overall, we conclude that the GDPR is making the web more transparent, but there is still a lack of both functional and usable mechanisms for users to consent to or deny processing of their personal data on the Internet.

READ FULL TEXT

page 4

page 5

page 9

page 11

research
10/13/2021

State of Security and Privacy Practices of Top Websites in the East African Community (EAC)

Growth in technology has resulted in the large-scale collection and proc...
research
10/19/2021

The Impact of User Location on Cookie Notices (Inside and Outside of the European Union)

The web is global, but privacy laws differ by country. Which set of priv...
research
01/23/2018

Whose Hands Are in the Finnish Cookie Jar?

Web cookies are ubiquitously used to track and profile the behavior of u...
research
01/08/2020

Dark Patterns after the GDPR: Scraping Consent Pop-ups and Demonstrating their Influence

New consent management platforms (CMPs) have been introduced to the web ...
research
04/12/2021

Accept All: The Landscape of Cookie Banners in Greece and the UK

Cookie banners are devices implemented by websites to allow users to man...
research
02/27/2022

Associating eHealth Policies and National Data Privacy Regulations

As electronic data becomes the lifeline of modern society, privacy conce...
research
08/27/2019

Multiple Purposes, Multiple Problems: A User Study of Consent Dialogs after GDPR

The European Union's General Data Protection Regulation (GDPR) requires ...

Please sign up or login with your details

Forgot password? Click here to reset