User Tracking in the Post-cookie Era: How Websites Bypass GDPR Consent to Track Users
Emmanouil Papadogiannakis, Panagiotis Papadopoulos, Nicolas Kourtellis, Evangelos P. Markatos
Abstract
During the past few years, mostly as a result of the GDPR and the CCPA, websites have started to present users with cookie consent banners. These banners are web forms where the users can state their preference and declare which cookies they would like to accept, if such option exists. Although requesting consent before storing any identifiable information is a good start towards respecting the user privacy, yet previous research has shown that websites do not always respect user choices. Furthermore, considering the ever decreasing reliance of trackers on cookies and actions browser vendors take by blocking or restricting third-party cookies, we anticipate a world where stateless tracking emerges, either because trackers or websites do not use cookies, or because users simply refuse to accept any. In this paper, we explore whether websites use more persistent and sophisticated forms of tracking in order to track users who said they do not want cookies. Such forms of tracking include first-party ID leaking, ID synchronization, and browser fingerprinting. Our results suggest that websites do use such modern forms of tracking even before users had the opportunity to register their choice with respect to cookies. To add insult to injury, when users choose to raise their voice and reject all cookies, user tracking only intensifies. As a result, users’ choices play very little role with respect to tracking: we measured that more than 75% of tracking activities happened before users had the opportunity to make a selection in the cookie consent banner, or when users chose to reject all cookies.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4d2a1237-01df-44c0-8660-09345d241728Cited by top-tier papers20
- Who Funds Misinformation? A Systematic Analysis of the Ad-related Profit Routines of Fake News SitesEmmanouil Papadogiannakis, Panagiotis Papadopoulos, Evangelos P. Markatos, Nicolas KourtellisWWW 2023 · 39 citations
- The Hitchhiker's Guide to Facebook Web Tracking with Invisible Pixels and Click IDsPaschalis Bekos, Panagiotis Papadopoulos, Evangelos P. Markatos, Nicolas KourtellisWWW 2023 · 24 citations
- SoK: Technical Implementation and Human Impact of Internet Privacy RegulationsEleanor Birrell, Jay Rodolitz, Angel Ding, Jenna Lee et al.S&P 2024 · 11 citations
- A Study of GDPR Compliance under the Transparency and Consent FrameworkMichael Smith, Antonio Torres-Agüero, Riley Grossman, Pritam Sen et al.WWW 2024 · 9 citations
- A Cross-Country Analysis of GDPR Cookie Banners and Flexible Methods For Scraping ThemMidas Nouwens, Janus Bager Kristensen, Kristjan Maalt, Rolf BaggeCHI 2025 · 7 citations
Builds on6
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski et al.NDSS 2019 · 826 citations
- Online Tracking: A 1-million-site Measurement and AnalysisSteven Englehardt, Arvind NarayananCCS 2016 · 798 citations
- (Un)informed Consent: Studying GDPR Consent Notices in the FieldChristine Utz, Martin Degeling, Sascha Fahl, Florian Schaub et al.CCS 2019 · 429 citations
- Beauty and the Beast: Diverting Modern Web Browsers to Build Unique Browser FingerprintsPierre Laperdrix, Walter Rudametkin, Benoit BaudryS&P 2016 · 279 citations
- Do Cookie Banners Respect my Choice? : Measuring Legal Compliance of Banners from IAB Europe's Transparency and Consent FrameworkCélestin Matte, Nataliia Bielova, Cristiana Teixeira SantosS&P 2020 · 212 citations
Related papers
- Cookie Swap Party: Abusing First-Party Cookies for Web TrackingQuan Chen, Panagiotis Ilia, Michalis Polychronakis, Alexandros KapravelosWWW 2021 · 57 citations
- Measuring the Privacy vs. Compatibility Trade-off in Preventing Third-Party Stateful TrackingJordan Jueckstock, Peter Snyder, Shaown Sarker, Alexandros Kapravelos et al.WWW 2022 · 15 citations
- Leaky Forms: A Study of Email and Password Exfiltration Before Form SubmissionAsuman Senol, Gunes Acar, Mathias Humbert, Frederik J. Zuiderveen BorgesiusUSENIX Security 2022
- Navigating Cookie Consent Violations Across the GlobeBrian Tang, Duc Bui, Kang G. ShinUSENIX Security 2025
- CookieGraph: Understanding and Detecting First-Party Tracking CookiesShaoor Munir, Sandra Deepthy Siby, Umar Iqbal, Steven Englehardt et al.CCS 2023 · 22 citations
