CSChecker: Revisiting GDPR and CCPA Compliance of Cookie Banners on the Web
Mingxue Zhang, Wei Meng, You Zhou, Kui Ren
摘要
Privacy regulations like GDPR and CCPA have greatly affected online advertising and tracking strategies. To comply with the regulations, websites need to display consent management UIs (i.e., cookie banners) implemented under the corresponding technical frameworks, allowing users to specify consents regarding their personal data processing. Although prior works have investigated the cookie banner compliance problems with GDPR, the technical specification has significantly changed. The compliance status under the latest framework remains unclear. There also lacks a systematic study of CCPA banner compliance. More importantly, most work have focused on detecting the regulation violations, whereas little is known about the possible culprits and causes. In this paper, we develop CSChecker, a browser-based tool that monitors and records consent strings on websites. We use CSChecker to analyze the GDPR and CCPA cookie banners, and reveal previously unknown compliance problems under both frameworks. We also discover and analyze possible miscreants leading to the violations, e.g., consent management providers that return wrong consent data. The comparison of the two frameworks inspires several suggestions about the design of cookie banners, the implementation of opt-out mechanisms, and the enforcement of user consent choices. CCS CONCEPTS • Security and privacy → Privacy protections.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- A Cross-Country Analysis of GDPR Cookie Banners and Flexible Methods For Scraping ThemMidas Nouwens, Janus Bager Kristensen, Kristjan Maalt, Rolf BaggeCHI 2025 · 被引用 7 次
- Websites' Global Privacy Control Compliance at Scale and over TimeKatherine Hausladen, Oliver Wang, Sophie Eng, Jocelyn Wang 等USENIX Security 2025 · 被引用 5 次
- Papers, Please: A First Look at Age Verification on the WebShreyas Minocha, Isaac Sheridan, Harry Oppenheimer, Paul Pearce 等S&P 2026 · 被引用 1 次
- PrivAudit: A Dual-Lens Auditing Framework for Website Privacy Practices under the CCPAMohamed Moustafa Dawoud, Riya Aggarwal, Likith Rahul Krishnamurthy, Ram Sundara RamanCCS 2026
它引用的顶会 Paper13
- Dark Patterns after the GDPR: Scraping Consent Pop-ups and Demonstrating their InfluenceMidas Nouwens, Ilaria Liccardi, Michael Veale, David R. Karger 等CHI 2020 · 被引用 491 次
- (Un)informed Consent: Studying GDPR Consent Notices in the FieldChristine Utz, Martin Degeling, Sascha Fahl, Florian Schaub 等CCS 2019 · 被引用 429 次
- Polisis: Automated Analysis and Presentation of Privacy Policies Using Deep LearningHamza Harkous, Kassem Fawaz, Rémi Lebret, Florian Schaub 等USENIX Security 2018 · 被引用 400 次
- Do Cookie Banners Respect my Choice? : Measuring Legal Compliance of Banners from IAB Europe's Transparency and Consent FrameworkCélestin Matte, Nataliia Bielova, Cristiana Teixeira SantosS&P 2020 · 被引用 212 次
- Privacy Policies over Time: Curation and Analysis of a Million-Document DatasetRyan Amos, Gunes Acar, Elena Lucherini, Mihir Kshirsagar 等WWW 2021 · 被引用 135 次
相关 Paper
- Navigating Cookie Consent Violations Across the GlobeBrian Tang, Duc Bui, Kang G. ShinUSENIX Security 2025
- Breaking the Illusion: Automated Reasoning of GDPR Consent ViolationsYing Li, Wenjun Qiu, Faysal Hossain Shezan, Kunlin Cai 等S&P 2026 · 被引用 1 次
- Automated Large-Scale Analysis of Cookie Notice ComplianceAhmed Bouhoula, Karel Kubicek, Amit Zac, Carlos Cotrini 等USENIX Security 2024 · 被引用 25 次
- Automated Cookie Notice Analysis and EnforcementRishabh Khandelwal, Asmit Nayak, Hamza Harkous, Kassem FawazUSENIX Security 2023
- Do Opt-Outs Really Opt Me Out?Duc Bui, Brian Tang, Kang G. ShinCCS 2022 · 被引用 9 次
