skip to main content
10.1145/3589334.3645618acmconferencesArticle/Chapter ViewAbstractPublication PagesthewebconfConference Proceedingsconference-collections
research-article
Open access

A Study of GDPR Compliance under the Transparency and Consent Framework

Published: 13 May 2024 Publication History

Abstract

This paper presents a study of GDPR compliance under the Interactive Advertising Bureau Europe's Transparency and Consent Framework (TCF). This framework provides digital advertising market participants a standard for sharing users' privacy consent choices. TCF is widely used across the Internet, and this paper presents a thorough experimental evaluation of both the compliance of websites with TCF and its impact on user privacy. We reviewed 2,230 websites that use TCF and accepted the automatic decline of user consent by our data collection system. Unlike previous work on GDPR compliance, we found that most websites using TCF properly record the user's consent choice. However, we found that 72.8% of the websites that were TCF compliant claimed legitimate interest as a rationale for overriding the consent choice. While legitimate interest is legal under GDPR, previous studies have shown that most users disagreed with how it is being used to collect data. Additionally, analysis of cookies set to the browsers indicates that TCF may not fully protect user privacy even when websites are compliant. Our research provides regulators and publishers with a data collection and analysis system to monitor compliance, detect non-compliance, and examine questionable practices of circumventing user consent choices using legitimate interest.

Supplemental Material

MP4 File
video presentation
MP4 File
Supplemental video

References

[1]
European Court of Justice [n. d.]. Opinion of Advocate General Szpunar delivered on 21 March 2019. Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband e.V. v Planet49 GmbH. Request for a preliminary ruling from the Bundesgerichtshof. Reference for a preliminary ruling - Directive 95/46/EC - Directive 2002/58/EC - Regulation (EU) 2016/679 - Processing of personal data and protection of privacy in the electronic communications sector - Cookies - Concept of consent of the data subject - Declaration of consent by means of a pre-ticked checkbox. Case C-673/17. European Court of Justice. Retrieved May 29th, 2023 from https://eur-lex.europa.eu/legal-content/en/TXT/?uri=CELEX: 62017CC0673
[2]
Article 29 Data Protection Working Party 2014. Opinion 06/2014 on the notion of legitimate interests of the data controller under Article 7 of Directive 95/46/EC. Article 29 Data Protection Working Party. Retrieved May 28th, 2023 from https://ec.europa.eu/justice/article-29/documentation/opinionrecommendation/ files/2014/wp217_en.pdf
[3]
Official Journal of the European Union 2016. Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (Text with EEA relevance). Official Journal of the European Union. Retrieved May 23rd, 2023 from http://data.europa.eu/eli/reg/2016/679/oj
[4]
European Data Protection Supervisor 2018. The History of the General Data Protection Regulation. European Data Protection Supervisor. Retrieved May 24th, 2023 from https://edps.europa.eu/data-protection/data-protection/legislation/ history-general-data-protection-regulation_en
[5]
IAB Europe 2019. The Transparency and Consent Framework TCF v2.0 Release for Public Comment A full overview for Publishers. IAB Europe. Retrieved May 31st, 2023 from https://old.iabeurope.eu/wp-content/uploads/2019/05/IAB-EUROPETCF- v2.0-PUBLISHER-WEBINAR-MAY-2019.pdf
[6]
IAB Europe 2022. Belgian Market Court Refers IAB Europe Ruling on TCF to The European Court of Justice: IAB Europe Statement. IAB Europe. Retrieved May 23rd, 2023 from https://iabeurope.eu/all-news/belgian-market-courtrefers- iab-europe-ruling-on-tcf-to-the-european-court-of-justice-iab-europestatement/
[7]
CNIL 2022. Cookies: GOOGLE fined 150 million euros. CNIL. Retrieved May 28th, 2023 from https://www.cnil.fr/en/cookies-google-fined-150-million-euros
[8]
Belgian Data Protection Authority (Litigation Chamber) 2022. Decision on the merits 21/2022 of 2 February 2022: Complaint relating to Transparency & Consent Frame-work. Belgian Data Protection Authority (Litigation Chamber). Retrieved May 23rd, 2023 from https://www.autoriteprotectiondonnees.be/publications/ decision-quant-au-fond-n-21--2022-english.pdf
[9]
Belgian Data Protection Authority 2023. The BE DPA to restore order to the online advertising industry: IAB Europe held responsible for a mechanism that infringes the GDPR. Belgian Data Protection Authority. Retrieved May 23rd, 2023 from https://www.dataprotectionauthority.be/iab-europe-held-responsiblefor- a-mechanism-that-infringes-the-gdpr
[10]
IAB Tech Lab 2023. Consent Management Platform API. IAB Tech Lab. Retrieved May 23rd, 2023 from https://github.com/InteractiveAdvertisingBureau/GDPRTransparency- and-Consent-Framework/blob/master/TCFv2/IAB%20Tech% 20Lab%20-%20CMP%20API%20v2.md#introduction
[11]
IAB Tech Lab 2023. Global-Privacy-Platform. IAB Tech Lab. Retrieved May 23rd, 2023 from https://github.com/InteractiveAdvertisingBureau/Global- Privacy-Platform
[12]
IAB Europe 2023. IAB Europe & IAB Tech Lab release updated Transparency & Consent Framework. IAB Europe. Retrieved May 29th, 2023 from https://iabeurope.eu/press-releases/iab-europe-iab-tech-lab-releaseupdated- transparency-consent-framework/
[13]
IAB Europe 2023. IAB Europe Seeks Court Decision on Validation Of The Action Plan as it Moves Forward With TCF Evolutions. IAB Europe. Retrieved May 23rd, 2023 from https://iabeurope.eu/all-news/iab-europe-seeks-court-decision-onvalidation- of-the-action-plan-as-it-moves-forward-with-tcf-evolutions/
[14]
IAB Europe 2023. TCF - Transparency & Consent Framework. IAB Europe. Retrieved May 23rd, 2023 from https://iabeurope.eu/transparency-consentframework/
[15]
IAB Europe 2023. TCF 2.2 Launches! All You Need To Know. IAB Europe. Retrieved October 11th, 2023 from https://iabeurope.eu/all-news/tcf-2--2-launches-all-youneed- to-know/
[16]
IAB Tech Lab 2023. Transparency and Consent String with Global Vendor & CMP List Formats. IAB Tech Lab. Retrieved May 23rd, 2023 from https://github.com/InteractiveAdvertisingBureau/GDPR-Transparencyand- Consent-Framework/blob/master/TCFv2/IAB%20Tech%20Lab%20- %20Consent%20string%20and%20vendor%20list%20formats%20v2.md#howshould- a-transparency--consent-string-be-stored
[17]
Rediet Abebe, Solon Barocas, Jon Kleinberg, Karen Levy, Manish Raghavan, and David G. Robinson. 2020. Roles for Computing in Social Change. Association for Computing Machinery (2020). https://doi.org/10.1145/3351095.3372871
[18]
Ryan Amos, Gunes Acar, Eli Lucherini, Mihir Kshirsagar, Arvind Narayanan, and Jonathan Mayer. [n. d.]. Privacy Policies over Time: Curation and Analysis of a Million-Document Dataset. In Proceedings of The Web Conference 2021 (Ljubljana, Slovenia, 2021-04--19) (WWW '21). Association for Computing Machinery, 22. https://doi.org/10.1145/3442381.3450048
[19]
Paschalis Bekos, Panagiotis Papadopoulos, Evangelos P. Markatos, and Nicolas Kourtellis. 2023. The Hitchhiker's Guide to FacebookWeb Tracking with Invisible Pixels and Click IDs. Proceedings of the ACM Web Conference 2023 (April 2023), 2132--2143. https://doi.org/10.1145/3543507.3583311
[20]
Dino Bollinger, Karel Kubicek, Carlos Cotrini, and David Basin. 2022. Automating Cookie Consent and GDPR Violation Detection. Proceedings of the 31st USENIX Security Symposium (2022).
[21]
BrowserStack. 2023. What is Headless Browser and Headless Browser Testing? https://www.browserstack.com/guide/what-is-headless-browser-testing.
[22]
Róisín Áine Costello. 2020. The Impacts of AdTech on Privacy Rights and the Rule of Law. Technology and Regulation (2020).
[23]
Martin Degeling, Christine Utz, Christopher Lentzsch, Henry Hosseini, Florian Schaub, and Thorsten Holz. 2019. We Value Your Privacy ... Now Take Some Cookies: Measuring the GDPR's Impact onWeb Privacy. Proceedings 2019 Network and Distributed System Security Symposium (2019).
[24]
C. Denison, B. Ghazi, Kumar R. Kamath, P., P. Manurangsi, K. G. Narra, and C. Zhang. 2023. Private Ad Modeling with DP-SGD. arXiv preprint (October 2023). https://doi.org/arXiv:2211.11896
[25]
Didomi. 2023. Didomi IAB TCF. https://support.didomi.io/iab-tcf-v2-newpurposes/ features-summary.
[26]
IAB Europe. 2022. IAB Europe Transparency & Consent Framework -- Policies Version 2022-06--21.3.5. https://iabeurope.eu/wpcontent/ uploads/2022/06/TransparencyConsentFramework_Policies_version_TCFv2.0- 2022-06--20.3.5_FINAL-1.pdf.
[27]
IAB Europe. 2023. Belgian Market Court Agrees That CJEU Decision is Needed Before Further Assessment of Action Plan Validation. (September 2023).
[28]
IAB Europe. 2023. IAB Europe. https://iabeurope.eu/iab-europe-transparencyconsent- framework-policies/.
[29]
Pietro Ferrara and Fausto Spoto. 2018. Static Analysis for GDPR Compliance. ITASEC (2018).
[30]
Maria Da Conceição Freitas and Miguel Mira Da Silva. 2018. GDPR Compliance in SMEs: There is much to be done. Journal of Information Systems Engineering & Management 3 (2018). Issue 4.
[31]
Hana Habib, Sarah Pearman, Jiamin Wang, Yixin Zou, Alessandro Acquisti, Lorrie Faith Cranor, Norman Sadeh, and Florian Schaub. 2020. "It's a scavenger hunt": Usability of Websites' Opt-Out and Data Deletion Choices. Proceedings of the 2020 CHI Conference on Human Factors in Computing Systems (2020), 1--12.
[32]
Maximilian Hils, Daniel W. Woods, and Rainer Böhme. 2020. Measuring the Emergence of Consent Management on the Web. Proceedings of the ACM Internet Measurement Conference (2020), 317--332.
[33]
Maximilian Hils, Daniel W. Woods, and Rainer Böhme. 2021. Privacy Preference Signals: Past, Present and Future. Proceedings on Privacy Enhancing Technologies 4 (2021), 249--269.
[34]
IAB. 2023. IABTCF/Core. https://www.npmjs.com/package/@iabtcf/core.
[35]
Jordan Jueckstock, Peter Snyder, Shaown Sarker, Alexandros Kapravelos, and Benjamin Livshits. 2022. Measuring the Privacy vs. Compatibility Trade-off in Preventing Third-Party Stateful Tracking. Proceedings of the ACMWeb Conference 2022 (April 2022), 710--720. https://doi.org/10.1145/3485447.3512231
[36]
Georgios Kampanos and Siamak F. Shahandashti. 2021. Accept All: The Landscape of Cookie Banners in Greece and the UK. ICT Systems Security and Privacy Protection (2021).
[37]
Lin Kyi, Christiana Santos, Franziska Roesner, Frederike Zufall, and Asia J. Biega. 2023. Investigating Deceptive Design in GDPR's Legitimate Interest. Proceedings of the 2023 CHI Conference on Human Factors in Computing Systems (2023), 1--16.
[38]
Victor Le Pochat, Tom Van Goethem, Maciej Tajalizadehkhoob, Samaneh Korczy'ski, and Wouter Joosen. 2019. Tranco: A Research-Oriented Top Sites Ranking Hardened Against Manipulation. In Proceedings of the 26th Annual Network and Distributed System Security Symposium (NDSS 2019). https: //doi.org/10.14722/ndss.2019.23386
[39]
Su-Chin Lin, Kai-Hsiang Chou, Yen Chen, Hsu-Chun Hsiao, Darion Cassel, Lujo Bauer, and Limin Jia. 2022. (2022).
[40]
Shuang Liu, Baiyang Zhao, Renjie Guo, Guozhu Meng, Fan Zhang, and Meishan Zhang. 2021. Have You been Properly Notified? Automatic Compliance Analysis of Privacy Policy Text with GDPR Article 13. Proceedings of the Web Conference 2021 (April 2021), 2154--2164. https://doi.org/10.1145/3442381.3450022
[41]
Célestin Matte, Nataliia Bielova, and Cristiana Santos. 2020. Do Cookie Banners Respect my Choice? : Measuring Legal Compliance of Banners from IAB Europe's Transparency and Consent Framework. 2020 IEEE Symposium on Security and Privacy (SP) (2020), 791--809.
[42]
Microsoft. 2020. Playwright. https://github.com/microsoft/playwright.
[43]
Shaoor Munir, Sandra Siby, Umar Iqbal, Steven Englehardt, Zubair Shafiq, and Carmela Troncoo. 2023. COOKIEGRAPH: Understanding and Detecting First- Party Tracking Cookies. 2023 ACM Conference on Computer and Communications Security (2023).
[44]
Midas Nouwens, Ilaria Liccardi, Michael Veale, David Karger, and Lalana Kagal. 2020. Dark Patterns after the GDPR: Scraping Consent Pop-ups and Demonstrating their Influence. Proceedings of the 2020 CHI Conference on Human Factors in Computing Systems (2020), 1--13.
[45]
OneTrust. 2023. Cookiepedia. https://cookiepedia.co.uk.
[46]
Emmanouil Papadogiannakis, Panagiotis Papadopoulos, Nicolas Kourtellis, and Evangelos P. Markatos. 2021. User Tracking in the Post-cookie Era: HowWebsites Bypass GDPR Consent to Track Users. Association for Computing Machinery (April 2021), 2130--2141. https://doi.org/10.1145/3442381.3450056
[47]
Johnny Ryan and Cristiana Santos. 2022. An Unending Data Breach Immune to Audit? Can the TCF and RTB Be Reconciled with the GDPR? SSRN Electronic Journal (03 2022). https://doi.org/10.2139/ssrn.4064729
[48]
Iskander Sanchez-Rola, Matteo Dell'Amico, Platon Kotzias, Davide Balzarotti, Leyla Bilge, Pierre-Antoine Vervier, and Igor Santos. 2019. Can I Opt Out Yet?: GDPR and the Global Illusion of Cookie Control. Proceedings of the 2019 ACM Asia Conference on Computer and Communications Security (2019), 340--351.
[49]
Cristiana Santos, Nataliia Bielova, and Célestin Matte. 2020. Are cookie banners indeed compliant with the law? : Deciphering EU legal requirements on consent and technical means to verify compliance of cookie banners. Technology and Regulation (2020), 91--135.
[50]
Cristiana Santos, Midas Nouwens, Michael Toth, Nataliia Bielova, and Vincent Roca. 2021. Consent Management Platforms under the GDPR: processors and/or controllers? APF 2021 - 9th Annual Privacy Forum (2021), 47--69.
[51]
Michael Toth, Nataliia Bielova, and Vincent Roca. 2022. On dark patterns and manipulation of website publishers by CMPs. Proceedings on Privacy Enhancing Technologies (2022), 478--497.
[52]
Christine Utz, Sabrina Amft, Martin Degeling, Thorsten Holz, Sascha Fahl, and Florian Schaub. 2023. Privacy Rarely Considered: Exploring Considerations in the Adoption of Third-Party Services by Websites. Proceedings on Privacy Enhancing Technologies (2023), 5--28.
[53]
Michael Veale, Midas Nouwens, and Cristiana Santos. 2022. Impossible Asks: Can the Transparency and Consent Framework Ever Authorise Real-Time Bidding after the Belgian DPA Decision? Technology and Regulation (2022).
[54]
Michael Veale and Frederik Zuiderveen Borgesius. 2022. Adtech and Real-Time Bidding under European Data Protection Law. German Law Journal 23 (2022), 226--256. Issue 2.
[55]
Carlos Villarán and Marta Beltrán. 2021. Protecting End User's Privacy When using Social Login through GDPR Compliance. Proceedings of the 18th International Conference on Security and Cryptography (2021), 428--435.
[56]
Sebastian Zimmeck, Oliver Wang, Kuba Alicki, Jocelyn Wang, and Sophie Eng. 2023. Usability and Enforceability of Global Privacy Control. Proceedings on Privacy Enhancing Technologies (2023), 265--281.

Cited By

View all
  • (2025)General Data Protection Regulation and Adaptive Educational GamesArtificial Intelligence—Based Games as Novel Holistic Educational Environments to Teach 21st Century Skills10.1007/978-3-031-77464-5_9(253-275)Online publication date: 21-Jan-2025

Recommendations

Comments

Information & Contributors

Information

Published In

cover image ACM Conferences
WWW '24: Proceedings of the ACM Web Conference 2024
May 2024
4826 pages
ISBN:9798400701719
DOI:10.1145/3589334
This work is licensed under a Creative Commons Attribution International 4.0 License.

Sponsors

Publisher

Association for Computing Machinery

New York, NY, United States

Publication History

Published: 13 May 2024

Check for updates

Badges

Author Tags

  1. ad tech
  2. consent management platforms
  3. gdpr compliance
  4. privacy regulation
  5. transparency and consent framework

Qualifiers

  • Research-article

Funding Sources

Conference

WWW '24
Sponsor:
WWW '24: The ACM Web Conference 2024
May 13 - 17, 2024
Singapore, Singapore

Acceptance Rates

Overall Acceptance Rate 1,899 of 8,196 submissions, 23%

Contributors

Other Metrics

Bibliometrics & Citations

Bibliometrics

Article Metrics

  • Downloads (Last 12 months)541
  • Downloads (Last 6 weeks)69
Reflects downloads up to 05 Mar 2025

Other Metrics

Citations

Cited By

View all
  • (2025)General Data Protection Regulation and Adaptive Educational GamesArtificial Intelligence—Based Games as Novel Holistic Educational Environments to Teach 21st Century Skills10.1007/978-3-031-77464-5_9(253-275)Online publication date: 21-Jan-2025

View Options

View options

PDF

View or Download as a PDF file.

PDF

eReader

View online with eReader.

eReader

Login options

Figures

Tables

Media

Share

Share

Share this Publication link

Share on social media