GDPR cookie横幅合规历史中的三方角色
SOURCE / arXiv cs.CY · A history of GDPR cookie banner compliance: the roles of publishers, regulators and CMPs
原文
A history of GDPR cookie banner compliance: the roles of publishers, regulators and CMPs
完整原文
arXiv:2606.31485v1 Announce Type: new Abstract: Since the introduction of the GDPR in 2018, cookie banners have become the primary mechanism for users to express preferences on online tracking and advertising. Consequently, their visual design and the options they present significantly influence user choice. Over time, the cookie banner landscape has evolved under the influence of key players, including publishers (website owners), regulators, and Consent Management Platforms (CMPs). This paper presents an in-depth analysis of the roles of these three key actors and an examination of their impact on cookie banners' design and implementation within the context of EU law. Our results, based on a historical evaluation of 11364 websites across 30 countries, indicate a positive evolution in the privacy landscape, with the compliance rate for websites featuring a "reject all" button increasing from 2.94% in 2018 to 30.66% in 2024. We analyze Data Protection Authority (DPA) activity and find a clear correlation between higher compliance rates and stronger regulatory action and guidance. Our experiments further show that compliance improvements are primarily driven by website owners, with CMPs showing little response to regulatory action or (indirect) influence on compliance rates. Our findings highlight the importance of more uniform collaboration and guidance among EU-level regulators to reduce interpretive divergence and simplify cookie banner compliance, as well as the need for regulatory oversight of CMPs, which in turn could significantly enhance privacy for many websites and users. Our work provides a foundation for academics, regulators, and industry to develop more effective strategies to motivate key players and promote greater user privacy.
归纳
自2018年GDPR实施以来,cookie横幅成为用户表达在线追踪偏好的主要机制。本研究分析了发布者、监管机构与同意管理平台(CMP)三方对cookie横幅设计与实施的影响。基于对30个国家11364个网站的历史评估,结果显示合规率从2018年的2.94%提升至2024年的30.66%。数据保护机构(DPA)的监管行动与合规率呈正相关。实验进一步表明,合规改善主要由网站所有者驱动,而CMP对监管行动反应微弱。研究建议欧盟层面加强统一协作与监管,以减少解释分歧并简化合规流程。
点评
GDPR cookie合规率虽从2.94%升至30.66%,但同意管理平台(CMP)对监管行动反应微弱,暴露出中间层合规传导失灵的风险。
法律视角点评
AI 生成 · 人工审核核心关切
GDPR cookie合规率虽从2.94%升至30.66%,但同意管理平台(CMP)对监管行动反应微弱,暴露出中间层合规传导失灵的风险。
实务启示
中国法律人应警惕《个人信息保护法》下同意管理平台(如SDK、CMP)的合规责任,避免监管要求被技术中间层稀释。