Do Cookie Banners Respect my Choice? : Measuring Legal Compliance of Banners from IAB Europe's Transparency and Consent Framework
Célestin Matte, Nataliia Bielova, Cristiana Teixeira Santos
Abstract
As a result of the GDPR and the ePrivacy Directive, European users encounter cookie banners on almost every website. Many of such banners are implemented by Consent Management Providers (CMPs), who respect IAB Europe’s Transparency and Consent Framework (TCF). Via cookie banners, CMPs collect and disseminate user consent to third parties. In this work, we systematically study IAB Europe’s TCF and analyze consent stored behind the user interface of TCF cookie banners. We analyze the GDPR and the ePrivacy Directive to identify potential legal violations in implementations of cookie banners based on the storage of consent and detect such suspected violations by crawling 1 426 websites that contains TCF banners, found among 28 257 crawled European websites. With two automatic and semi-automatic crawl campaigns, we detect suspected violations, and we find that: 141 websites register positive consent even if the user has not made their choice; 236 websites nudge the users towards accepting consent by pre-selecting options; and 27 websites store a positive consent even if the user has explicitly opted out. Performing extensive tests on 560 websites, we find at least one suspected violation in 54% of them. Finally, we provide a browser extension to facilitate manual detection of suspected violations for regular users and Data Protection Authorities.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c873a1e0-71b2-4f02-8783-e77168907a4fCited by top-tier papers38
- Dark Patterns and the Legal Requirements of Consent Banners: An Interaction Criticism PerspectiveColin M. Gray, Cristiana Teixeira Santos, Nataliia Bielova, Michael Toth et al.CHI 2021 · 175 citations
- "Okay, whatever": An Evaluation of Cookie Consent InterfacesHana Habib, Megan Li, Ellie Young, Lorrie Faith CranorCHI 2022 · 103 citations
- User Tracking in the Post-cookie Era: How Websites Bypass GDPR Consent to Track UsersEmmanouil Papadogiannakis, Panagiotis Papadopoulos, Nicolas Kourtellis, Evangelos P. MarkatosWWW 2021 · 99 citations
- Share First, Ask Later (or Never?) Studying Violations of GDPR's Explicit Consent in Android AppsTrung Tin Nguyen, Michael Backes, Ninja Marnau, Ben StockUSENIX Security 2021 · 70 citations
- Are Privacy Dashboards Good for End Users? Evaluating User Perceptions and Reactions to Google's My ActivityFlorian M. Farke, David G. Balash, Maximilian Golla, Markus Dürmuth et al.USENIX Security 2021 · 48 citations
Builds on6
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski et al.NDSS 2019 · 826 citations
- Online Tracking: A 1-million-site Measurement and AnalysisSteven Englehardt, Arvind NarayananCCS 2016 · 798 citations
- Dark Patterns after the GDPR: Scraping Consent Pop-ups and Demonstrating their InfluenceMidas Nouwens, Ilaria Liccardi, Michael Veale, David R. Karger et al.CHI 2020 · 491 citations
- (Un)informed Consent: Studying GDPR Consent Notices in the FieldChristine Utz, Martin Degeling, Sascha Fahl, Florian Schaub et al.CCS 2019 · 429 citations
- Internet Jones and the Raiders of the Lost Trackers: An Archaeological Study of Web Tracking from 1996 to 2016Ada Lerner, Anna Kornfeld Simpson, Tadayoshi Kohno, Franziska RoesnerUSENIX Security 2016 · 273 citations
Related papers
- Navigating Cookie Consent Violations Across the GlobeBrian Tang, Duc Bui, Kang G. ShinUSENIX Security 2025
- CSChecker: Revisiting GDPR and CCPA Compliance of Cookie Banners on the WebMingxue Zhang, Wei Meng, You Zhou, Kui RenICSE 2024 · 5 citations
- Automated Large-Scale Analysis of Cookie Notice ComplianceAhmed Bouhoula, Karel Kubicek, Amit Zac, Carlos Cotrini et al.USENIX Security 2024 · 25 citations
- A Cross-Country Analysis of GDPR Cookie Banners and Flexible Methods For Scraping ThemMidas Nouwens, Janus Bager Kristensen, Kristjan Maalt, Rolf BaggeCHI 2025 · 7 citations
- A Study of GDPR Compliance under the Transparency and Consent FrameworkMichael Smith, Antonio Torres-Agüero, Riley Grossman, Pritam Sen et al.WWW 2024 · 9 citations
