TL;DR
This study systematically evaluates the legal compliance of cookie banners based on IAB Europe's TCF by crawling nearly 23,000 websites, revealing widespread violations of GDPR and ePrivacy Directive requirements.
Contribution
It provides the first large-scale analysis of TCF cookie banners' compliance, introduces automated detection methods, and offers a browser extension for manual violation detection.
Findings
54% of websites had at least one violation
141 websites registered consent without user action
27 websites stored consent despite user opt-out
Abstract
As a result of the GDPR and the ePrivacy Directive, European users encounter cookie banners on almost every website. Many of such banners are implemented by Consent Management Providers (CMPs), who respect the IAB Europe's Transparency and Consent Framework (TCF). Via cookie banners, CMPs collect and disseminate user consent to third parties. In this work, we systematically study IAB Europe's TCF and analyze consent stored behind the user interface of TCF cookie banners. We analyze the GDPR and the ePrivacy Directive to identify legal violations in implementations of cookie banners based on the storage of consent and detect such violations by crawling 22 949 European websites. With two automatic and semi-automatic crawl campaigns, we detect violations, and we find that: 141 websites register positive consent even if the user has not made their choice; 236 websites nudge the users…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
