% % This file was created by the TYPO3 extension % bib % --- Timezone: CEST % Creation date: 2024-07-04 % Creation time: 07-16-27 % --- Number of references % 1 % @Article { 2021_kretschmer_cookies, title = {Cookie Banners and Privacy Policies: Measuring the Impact of the GDPR on the Web}, journal = {ACM Transactions on the Web}, year = {2021}, month = {11}, day = {1}, volume = {15}, number = {4}, abstract = {The General Data Protection Regulation (GDPR) is in effect since May of 2018. As one of the most comprehensive pieces of legislation concerning privacy, it sparked a lot of discussion on the effect it would have on users and providers of online services in particular, due to the large amount of personal data processed in this context. Almost three years later, we are interested in revisiting this question to summarize the impact this new regulation has had on actors in the World Wide Web. Using Scopus, we obtain a vast corpus of academic work to survey studies related to changes on websites since and around the time, the GDPR went into force. Our findings show that the emphasis on privacy increased w.r.t. online services, but plenty potential for improvements remains. Although online services are on average more transparent regarding data processing practices in their public data policies, a majority of these policies still either lack information required by the GDPR (e.g., contact information for users to file privacy inquiries), or do not provide this information in a user-friendly form. Additionally, we summarize that online services more often provide means for their users to opt out of data processing, but regularly obstruct convenient access to such means through unnecessarily complex and sometimes illegitimate interface design. Our survey further details that this situation contradicts the preferences expressed by users both verbally and through their actions, and researchers have proposed multiple approaches to facilitate GDPR-conform data processing without negatively impacting the user experience. Thus, we compiled reoccurring points of criticism by privacy researchers and data protection authorities into a list of four guidelines for service providers to consider.}, keywords = {Cookies; Privacy; GDPR; Web; Privacy Legislation; Fingerprinting}, url = {https://www.comsys.rwth-aachen.de/fileadmin/papers/2021/2021-kretschmer-tweb-cookies.pdf}, publisher = {ACM}, ISSN = {1559-1131}, DOI = {10.1145/3466722}, reviewed = {1}, author = {Kretschmer, Michael and Pennekamp, Jan and Wehrle, Klaus} }