A Cross-Country Analysis of GDPR Cookie Banners and Flexible Methods for Scraping Them
Authors
Research Background and Issues
- Issues and Challenges: The authors focus on the problems associated with cookie consent interfaces in the online tracking industry, which have emerged due to the General Data Protection Regulation (GDPR) and the ePrivacy Directive. These interfaces often serve as hubs for online behavioral tracking but are commonly characterized by low compliance, lack of rejection options, and unequal visual design. Despite legal requirements and guidelines, many websites fail to meet even the minimum compliance standards.
- Importance of the Issue: Collecting user data through cookie consent interfaces poses a threat to user privacy and may violate legal regulations. Furthermore, the so-called "dark patterns" in these designs can manipulate users into making involuntary choices.
- Research Motivation and Related Work: Previous research has focused on the impact of consent interfaces on user behavior and their legal compliance. However, existing methods are limited in scope and fail to cover the broader ecosystem. Additionally, comparative studies on the effectiveness of policy enforcement across different countries are scarce, and the critical intermediary role of Consent Management Platforms (CMPs) remains underexplored.
Solution
- Proposed Approach: The authors propose an efficient and flexible automated method to detect, analyze, and measure the design and providers of cookie consent interfaces (CMPs). They also developed an online service called "consent-observatory.eu" to facilitate research on cookie consent interfaces for academia and regulatory bodies.
- Innovations:
- Methodologically, the approach significantly improves the accuracy of detecting user options, visual layouts, and internal mechanisms.
- In terms of coverage, the study spans the top 10,000 websites across 31 countries.
- Open-sourcing the technical tools makes the detection process more accessible and customizable.
- Implementation Steps:
- Country and Website Selection: Based on traffic rankings, the study selected the top 10,000 websites from 31 European countries implementing the GDPR and ePrivacy Directive.
- Technical Implementation: Automated crawlers combined with text parsing, visual assessment, and multilingual corpus classification were used to accurately identify cookie interfaces and user options.
- Validation and Analysis: A benchmark database with manual evaluations was established to monitor the accuracy of algorithmic detection.
Research Findings
-
Specific Findings:
- Current Coverage Statistics: 67% of websites have cookie consent interfaces, but only 15% meet the minimum compliance standards. CMP technology is used by 67% of these interfaces.
- Unequal Option Distribution: 88% of interfaces include an "accept" option, but only 45% offer a "reject" option. Moreover, the visual design of the reject button is often less prominent.
- Market Analysis: The CMP market is highly concentrated, with three major providers (Usercentrics, CookieYes, and OneTrust) controlling 37% of the market share.
- Factors Influencing Compliance: The primary factor affecting compliance is the CMP provider, accounting for 18% of the variance. National regulatory guidance has a slight positive effect on compliance, while the impact of regulatory fines is negligible.
-
Advantages:
- Compared to existing studies, this research offers broader coverage and a more comprehensive methodology.
- The study provides a tool for generating fine-grained data (consent-observatory.eu), which can effectively support future research and policy implementation.
-
Experimental or Evaluation Results:
- The accuracy of automated detection for various options reached 99% (F1 score).
- Quantitative analysis revealed significant differences in the positive or negative effects of different CMP platforms on compliance—for example, some CMPs significantly improved compliance, while others had minimal impact.
-
Limitations and Future Directions:
- Limitations:
- The study's definition of minimum compliance may be too lenient and does not include deeper legal analyses.
- Data from some countries may not fully represent their website ecosystems due to limited samples.
- The detection method does not fully cover potential deeper non-compliance behaviors, such as data processing after interface settings.
- Future Directions:
- Further analyze the role of CMPs in monitoring and compliance, and explore their legal responsibilities as "joint controllers."
- Develop more user studies to analyze the broader impact of different interface designs on user behavior.
- Explore technical alternatives, such as browser-level unified privacy signals or a shift to context-based advertising models.
- Limitations:
Conclusion
This study provides significant insights into the design issues and industry structure of cookie consent interfaces through robust technical tools and extensive data coverage. The research not only clarifies the current state of the cookie ecosystem but also highlights critical areas for improvement in privacy management, such as unfair designs, low compliance rates, and systemic obfuscation. By advocating for systematic regulation of CMPs and policy interventions, this study offers practical pathways for improving online data privacy protection in the future.
Research Questions / Practical Problems
Question signals indexed for this paper.
Research Questions
3- What design and compliance problems exist in current cookie consent interfaces?Category: Cookie, Permission, and Consent ControlsSimilar questionsarrow_forward
- What factors affect cookie consent interface compliance and presentation of user options?Category: Cookie, Permission, and Consent ControlsSimilar questionsarrow_forward
- How do policy enforcement outcomes differ across countries and consent management platforms (CMPs)?Category: Cookie, Permission, and Consent ControlsSimilar questionsarrow_forward
Practical Problems
1- Users are unknowingly manipulated into consenting to cookie settings, threatening privacy rights.Category: Cookie, Permission, and Consent ControlsSimilar questionsarrow_forward
- 80%
The Annoying, the Disturbing, and the Weird: Challenges with Phone Numbers as Identifiers and Phone Number Recycling
CHI '21· Privacy by Design & User Control +1
- 80%
A US-UK Usability Evaluation of Consent Management Platform Cookie Consent Interface Design on Desktop and Mobile
CHI '23· Privacy by Design & User Control +1
- 80%
Exploring User Motivations Behind iOS App Tracking Transparency Decisions
CHI '23· Privacy by Design & User Control +1
- 80%
Measuring Compliance with the California Consumer Privacy Act Over Space and Time
CHI '24· Privacy by Design & User Control +1
- 80%
Bystander Privacy in Video Sharing Era: Automated Consent Compliance through Platform Censorship
CHI '25· Privacy by Design & User Control +1
- 67%
Evaluating 'Prefer not to say' Around Sensitive Disclosures
CHI '20· Privacy by Design & User Control +1
- 67%
Investigating Deceptive Design in GDPR's Legitimate Interest
CHI '23· Algorithmic Transparency & Auditability +2
- 67%
Analyzing Security and Privacy Advice During the 2022 Russian Invasion of Ukraine on Twitter
CHI '24· Privacy by Design & User Control +2
- 67%
A Data-Driven Approach to Developing IoT Privacy-Setting Interfaces
IUI '18· Algorithmic Transparency & Auditability +2
- 60%
SIGCHI Social Impact Award Talk – Making Privacy and Security More Usable
CHI '18· Privacy by Design & User Control +1
Based on Jaccard similarity of research subtopics & professions (≥60%)