(Un)informed Consent: Studying GDPR Consent Notices in the Field
Christine Utz, Martin Degeling, Sascha Fahl, Florian Schaub, Thorsten Holz
Abstract
Since the adoption of the General Data Protection Regulation (GDPR) in May 2018 more than 60 % of popular websites in Europe display cookie consent notices to their visitors. This has quickly led to users becoming fatigued with privacy notifications and contributed to the rise of both browser extensions that block these banners and demands for a solution that bundles consent across multiple websites or in the browser. In this work, we identify common properties of the graphical user interface of consent notices and conduct three experiments with more than 80,000 unique users on a German website to investigate the influence of notice position, type of choice, and content framing on consent. We find that users are more likely to interact with a notice shown in the lower (left) part of the screen. Given a binary choice, more users are willing to accept tracking compared to mechanisms that require them to allow cookie use for each category or company individually. We also show that the widespread practice of nudging has a large effect on the choices users make. Our experiments show that seemingly small implementation decisions can substantially impact whether and how people interact with consent notices. Our findings demonstrate the importance for regulation to not just require consent, but also provide clear requirements or guidance for how this consent has to be obtained in order to ensure that users can make free and informed choices. CCS CONCEPTS • Security and privacy → Usability in security and privacy; • Human-centered computing → Empirical studies in interaction design; • Social and professional topics → Governmental regulations.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4affaad6-9d45-4d7f-9dfd-cd80c15a6399Cited by top-tier papers46
- Dark Patterns after the GDPR: Scraping Consent Pop-ups and Demonstrating their InfluenceMidas Nouwens, Ilaria Liccardi, Michael Veale, David R. Karger et al.CHI 2020 · 491 citations
- What Makes a Dark Pattern... Dark?: Design Attributes, Normative Considerations, and Measurement MethodsArunesh Mathur, Mihir Kshirsagar, Jonathan R. MayerCHI 2021 · 327 citations
- Do Cookie Banners Respect my Choice? : Measuring Legal Compliance of Banners from IAB Europe's Transparency and Consent FrameworkCélestin Matte, Nataliia Bielova, Cristiana Teixeira SantosS&P 2020 · 212 citations
- User Tracking in the Post-cookie Era: How Websites Bypass GDPR Consent to Track UsersEmmanouil Papadogiannakis, Panagiotis Papadopoulos, Nicolas Kourtellis, Evangelos P. MarkatosWWW 2021 · 99 citations
- Are Privacy Dashboards Good for End Users? Evaluating User Perceptions and Reactions to Google's My ActivityFlorian M. Farke, David G. Balash, Maximilian Golla, Markus Dürmuth et al.USENIX Security 2021 · 48 citations
Related papers
- This Website Uses Nudging: MTurk Workers' Behaviour on Cookie Consent NoticesCarlos Bermejo Fernandez, Dimitris Chatzopoulos, Dimitrios Papadopoulos, Pan HuiCSCW 2021 · 47 citations
- We Value Your Privacy ... Now Take Some Cookies: Measuring the GDPR's Impact on Web PrivacyMartin Degeling, Christine Utz, Christopher Lentzsch, Henry Hosseini et al.NDSS 2019
- The Effect of Design Patterns on (Present and Future) Cookie Consent DecisionsNataliia Bielova, Laura Litvine, Anysia Nguyen, Mariam Chammat et al.USENIX Security 2024 · 34 citations
- "Okay, whatever": An Evaluation of Cookie Consent InterfacesHana Habib, Megan Li, Ellie Young, Lorrie Faith CranorCHI 2022 · 103 citations
- Automated Large-Scale Analysis of Cookie Notice ComplianceAhmed Bouhoula, Karel Kubicek, Amit Zac, Carlos Cotrini et al.USENIX Security 2024 · 25 citations
