Dark Patterns after the GDPR: Scraping Consent Pop-ups and Demonstrating their Influence
Midas Nouwens, Ilaria Liccardi, Michael Veale, David R. Karger, Lalana Kagal
Abstract
New consent management platforms (CMPs) have been introduced to the web to conform with the EU's General Data Protection Regulation, particularly its requirements for consent when companies collect and process users' personal data. This work analyses how the most prevalent CMP designs affect people's consent choices. We scraped the designs of the five most popular CMPs on the top 10,000 websites in the UK (n=680). We found that dark patterns and implied consent are ubiquitous; only 11.8% meet the minimal requirements that we set based on European law. Second, we conducted a field experiment with 40 participants to investigate how the eight most common designs affect consent choices. We found that notification style (banner or barrier) has no effect; removing the opt-out button from the first page increases consent by 22-23 percentage points; and providing more granular controls on the first page decreases consent by 8-20 percentage points. This study provides an empirical basis for the necessary regulatory action to enforce the GDPR, in particular the possibility of focusing on the centralised, third-party CMP services as an effective way to increase compliance.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 809b18ee-1659-4ef5-a9c1-f02c3b0848c0Cited by top-tier papers64
- What Makes a Dark Pattern... Dark?: Design Attributes, Normative Considerations, and Measurement MethodsArunesh Mathur, Mihir Kshirsagar, Jonathan R. MayerCHI 2021 · 327 citations
- Do Cookie Banners Respect my Choice? : Measuring Legal Compliance of Banners from IAB Europe's Transparency and Consent FrameworkCélestin Matte, Nataliia Bielova, Cristiana Teixeira SantosS&P 2020 · 212 citations
- Dark Patterns and the Legal Requirements of Consent Banners: An Interaction Criticism PerspectiveColin M. Gray, Cristiana Teixeira Santos, Nataliia Bielova, Michael Toth et al.CHI 2021 · 175 citations
- An Ontology of Dark Patterns Knowledge: Foundations, Definitions, and a Pathway for Shared Knowledge-BuildingColin M. Gray, Cristiana Teixeira Santos, Nataliia Bielova, Thomas MildnerCHI 2024 · 113 citations
- End User Accounts of Dark Patterns as Felt ManipulationColin M. Gray, Jingle Chen, Shruthi Sai Chivukula, Liyang QuCSCW 2021 · 108 citations
Builds on2
- (Un)informed Consent: Studying GDPR Consent Notices in the FieldChristine Utz, Martin Degeling, Sascha Fahl, Florian Schaub et al.CCS 2019 · 429 citations
- We Value Your Privacy ... Now Take Some Cookies: Measuring the GDPR's Impact on Web PrivacyMartin Degeling, Christine Utz, Christopher Lentzsch, Henry Hosseini et al.NDSS 2019
Related papers
- A US-UK Usability Evaluation of Consent Management Platform Cookie Consent Interface Design on Desktop and MobileElijah Robert Bouma-Sims, Megan Li, Yanzi Lin, Adia Sakura-Lemessy et al.CHI 2023 · 23 citations
- A Cross-Country Analysis of GDPR Cookie Banners and Flexible Methods For Scraping ThemMidas Nouwens, Janus Bager Kristensen, Kristjan Maalt, Rolf BaggeCHI 2025 · 7 citations
- Automated Large-Scale Analysis of Cookie Notice ComplianceAhmed Bouhoula, Karel Kubicek, Amit Zac, Carlos Cotrini et al.USENIX Security 2024 · 25 citations
- "Okay, whatever": An Evaluation of Cookie Consent InterfacesHana Habib, Megan Li, Ellie Young, Lorrie Faith CranorCHI 2022 · 103 citations
- The Effect of Design Patterns on (Present and Future) Cookie Consent DecisionsNataliia Bielova, Laura Litvine, Anysia Nguyen, Mariam Chammat et al.USENIX Security 2024 · 34 citations
