Are cookie banners indeed compliant with the law? Deciphering EU legal requirements on consent and technical means to verify compliance of cookie banners
Cristiana Santos, Nataliia Bielova, C\'elestin Matte

TL;DR
This paper defines seventeen detailed legal and technical requirements for cookie banners to ensure compliance with EU laws, and assesses the feasibility of verifying these requirements using current web technologies.
Contribution
It introduces a comprehensive set of operational requirements for cookie banners and evaluates their verifiability, bridging legal standards with technical implementation.
Findings
Seventeen operational requirements for compliance identified
Some requirements are verifiable with current tools, others are not
Guidelines for implementing revocable consent and compliance verification
Abstract
In this work, we analyze the legal requirements on how cookie banners are supposed to be implemented to be fully compliant with the e-Privacy Directive and the General Data Protection Regulation. Our contribution resides in the definition of seventeen operational and fine-grained requirements on cookie banner design that are legally compliant, and moreover, we define whether and when the verification of compliance of each requirement is technically feasible. The definition of requirements emerges from a joint interdisciplinary analysis composed of lawyers and computer scientists in the domain of web tracking technologies. As such, while some requirements are provided by explicitly codified legal sources, others result from the domain-expertise of computer scientists. In our work, we match each requirement against existing cookie banners design of websites. For each requirement, we…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsPrivacy, Security, and Data Protection · Hate Speech and Cyberbullying Detection · Sexuality, Behavior, and Technology
