USENIX Security2024Top-tier venue
Automated Large-Scale Analysis of Cookie Notice Compliance
Ahmed Bouhoula, Karel Kubicek, Amit Zac, Carlos Cotrini, David A. Basin
Abstract
Privacy regulations such as the General Data Protection Regulation (GDPR) require websites to inform EU-based users about non-essential data collection and to request their consent to this practice. Previous studies have documented widespread violations of these regulations. However, these studies provide a limited view of the general compliance picture: they are either restricted to a subset of notice types, detect only simple violations using prescribed patterns, or analyze notices manually. Thus, they are restricted both in their scope and in their ability to analyze violations at scale. We present the first general, automated, large-scale analysis of cookie notice compliance. Our method interacts with cookie notices, e.g., by navigating through their settings. It observes declared processing purposes and available consent options using Natural Language Processing and compares them to the actual use of cookies. By virtue of the generality and scale of our analysis, we correct for the selection bias present in previous studies focusing on specific Consent Management Platforms (CMP). We also provide a more general view of the overall compliance picture using a set of 97k websites popular in the EU. We report, in particular, that 65.4% of websites offering a cookie rejection option likely collect user data despite explicit negative consent.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 34ef73ed-4033-416c-b9f8-7a766abb3573Cited by top-tier papers11
- An Ontology of Dark Patterns Knowledge: Foundations, Definitions, and a Pathway for Shared Knowledge-BuildingColin M. Gray, Cristiana Teixeira Santos, Nataliia Bielova, Thomas MildnerCHI 2024 · 113 citations
- Getting Trapped in Amazon's "Iliad Flow": A Foundation for the Temporal Analysis of Dark PatternsColin M. Gray, Thomas Mildner, Ritika GairolaCHI 2025 · 34 citations
- Automating Website Registration for Studying GDPR ComplianceKarel Kubicek, Jakob Merane, Ahmed Bouhoula, David A. BasinWWW 2024 · 9 citations
- A Cross-Country Analysis of GDPR Cookie Banners and Flexible Methods For Scraping ThemMidas Nouwens, Janus Bager Kristensen, Kristjan Maalt, Rolf BaggeCHI 2025 · 7 citations
- Setting the Course, but Forgetting to Steer: Analyzing Compliance with GDPR's Right of Access to Data by Instagram, TikTok, and YoutubeSai Keerthana Karnam, Abhisek Dash, Antariksh Das, Sepehr Mousavi et al.S&P 2026 · 3 citations
Builds on11
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski et al.NDSS 2019 · 826 citations
- Online Tracking: A 1-million-site Measurement and AnalysisSteven Englehardt, Arvind NarayananCCS 2016 · 798 citations
- Dark Patterns after the GDPR: Scraping Consent Pop-ups and Demonstrating their InfluenceMidas Nouwens, Ilaria Liccardi, Michael Veale, David R. Karger et al.CHI 2020 · 491 citations
- (Un)informed Consent: Studying GDPR Consent Notices in the FieldChristine Utz, Martin Degeling, Sascha Fahl, Florian Schaub et al.CCS 2019 · 429 citations
- Do Cookie Banners Respect my Choice? : Measuring Legal Compliance of Banners from IAB Europe's Transparency and Consent FrameworkCélestin Matte, Nataliia Bielova, Cristiana Teixeira SantosS&P 2020 · 212 citations
Related papers
- A US-UK Usability Evaluation of Consent Management Platform Cookie Consent Interface Design on Desktop and MobileElijah Robert Bouma-Sims, Megan Li, Yanzi Lin, Adia Sakura-Lemessy et al.CHI 2023 · 23 citations
- Automating Cookie Consent and GDPR Violation DetectionDino Bollinger, Karel Kubicek, Carlos Cotrini, David A. BasinUSENIX Security 2022
- Navigating Cookie Consent Violations Across the GlobeBrian Tang, Duc Bui, Kang G. ShinUSENIX Security 2025
- We Value Your Privacy ... Now Take Some Cookies: Measuring the GDPR's Impact on Web PrivacyMartin Degeling, Christine Utz, Christopher Lentzsch, Henry Hosseini et al.NDSS 2019
- Dissecting Privacy Perspectives of Websites Around the World: "Aceptar Todo, Alle Akzeptieren, Accept All..."Aysun Ogut, Berke Turanlioglu, Doruk Can Metiner, Albert Levi et al.USENIX Security 2024 · 2 citations
