Third-party tracking raises privacy concerns due to the covert collection, aggregation, and potential misuse of users’ personal data, undermining individuals’ sense of control and privacy online. In Europe, tracking is regulated by the GDPR and ePrivacy Directive (ePD), which require explicit user consent. In contrast, US websites, governed by a patchwork of state and federal laws, often rely on opt-out mechanisms. However, when dealing with EU residents’ data, US companies must comply with the GDPR. We present an empirical study assessing compliance with GDPR and ePD consent requirements in EU and US websites through their cookie banner implementations. We identified 19 potential violations of these regulations and developed a systematic method to detect them. Our key findings are: a) none of the examined EU or US websites fully comply with GDPR and ePD consent standards; b) both EU and US websites engage in user tracking before a choice is made and even after consent is denied; c) websites that use Consent Management Platforms (CMPs) are generally more compliant than those that do not. These findings highlight widespread non-compliance and the need for stronger enforcement and clearer guidance on valid consent mechanisms.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

An Empirical Measurement of Cookie Banners Potential Legal Violations in EU vs US Websites

  • Federica Paci,
  • Matteo Cristani,
  • Armando de Berti

摘要

Third-party tracking raises privacy concerns due to the covert collection, aggregation, and potential misuse of users’ personal data, undermining individuals’ sense of control and privacy online. In Europe, tracking is regulated by the GDPR and ePrivacy Directive (ePD), which require explicit user consent. In contrast, US websites, governed by a patchwork of state and federal laws, often rely on opt-out mechanisms. However, when dealing with EU residents’ data, US companies must comply with the GDPR. We present an empirical study assessing compliance with GDPR and ePD consent requirements in EU and US websites through their cookie banner implementations. We identified 19 potential violations of these regulations and developed a systematic method to detect them. Our key findings are: a) none of the examined EU or US websites fully comply with GDPR and ePD consent standards; b) both EU and US websites engage in user tracking before a choice is made and even after consent is denied; c) websites that use Consent Management Platforms (CMPs) are generally more compliant than those that do not. These findings highlight widespread non-compliance and the need for stronger enforcement and clearer guidance on valid consent mechanisms.