REVIEW 3 major objections 5 minor 70 references
Multiple Purposes, Multiple Problems: A User Study of Consent Dialogs after GDPR
T0 review · 3 major / 5 minor · reviewed 2026-08-14 · deepseek-v4-flash
Pith's one-line read A highlighted 'select all and confirm' default button in a GDPR consent dialog makes users accept significantly more purposes, recall fewer of their choices, and later regret and distrust the dialog.
desk verdict Solid behavioral evidence on deceptive 'select all' buttons; the perceived-deception claim is not supported across both sites. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing object is the experimental consent dialog itself: a blocking pop-up, copied from a real airline website, that lists three purposes (statistics, comfort, personalization) with initially unchecked checkboxes, plus a highlighted yellow button 'Select all and confirm' that grants all three purposes regardless of checkbox state and a colorless 'Confirm selection' button that grants only what was actively selected. The paper's central comparison is between this T1 dialog, a T2 dialog with only the personalization purpose, and a control dialog with the same three purposes but no highlighted button. The outcome is 'effective consent,' a score from 0 to 3 counting the purposes the site records as agreed to, independent of the user's intention; this is measured alongside free recall of the choice and multi-item scales for perceived deception, perceived difficulty, regret (measured before and after the user is informed of the effective choice), and privacy attitudes.
What would settle it
Run the same three-dialog experiment with balanced group sizes at several independent sites and pre-registered analyses that report the treatment-versus-control comparison separately for each site. The central consent effect would fail if the treatment group's count of consented purposes is not significantly higher than control ($\chi^2(1)$, $p<0.05$); the deception claim would fail specifically if the perceived-deception difference is significant only in a minority of sites.
Extended reading notes
Core claim
The paper's central discovery is that a highlighted 'select all and confirm' button in a blocking multi-purpose consent dialog is not a neutral shortcut: it changes what users effectively consent to and how they feel about it afterward. In the treatment group, 54% ended up consenting to all three purposes versus 23.1% in the control group, a significant difference in the count of consented purposes ($\chi^2(1)=7.2$, $p<0.01$). The accuracy of recall also dropped: 73.5% of the treatment group could correctly report their choice, versus 90.0% of the control group; among those who actually clicked the default button, correct recall fell to 55.6%. After being shown what they had effectively agreed to, treatment-group participants reported a significant increase in regret (paired $t(49)=2.81$, $p<0.01$, effect size $d=0.40$), and their perceived-deception score was significantly higher than control ($t(96.83)=2.24$, $p<0.05$, effect size $d=0.44$). In contrast, reducing the dialog from three purposes to one produced no significant difference in consented purposes or perceived difficulty, only a shorter response time.
Load-bearing premise
The result that users see the dialog as more deceptive depends on pooling the two study sites: in the site-by-site breakdown the effect is significant in Austria ($p=0.019$) but not in Germany ($p=0.564$), so if the samples are not combined, the deception claim does not robustly generalize.
Editorial extensions
If this is right
- Designs that pair a highlighted select-all button with initially unchecked checkboxes can record consent that users themselves do not accurately remember, so such recorded consent should not be treated as evidence of informed, freely given agreement.
- If regulators adopt recall as a proxy for consent quality, consent dialogs with accurate recall rates around 90% (control) versus 55–74% (treatment) would be distinguishable in audits.
- Presenting up to three purposes in one dialog does not produce the choice-overload effects predicted by choice proliferation: perceived difficulty was not significantly higher, so multi-purpose dialogs can be designed without unavoidable overload.
- Response time does increase with the number of purposes, so extending the result to dialogs with many more than three purposes is not supported by this study.
- The default-button effect in a multi-purpose dialog is about four times larger than the previously reported binary default effect, so bundling purposes amplifies the nudge.
Reading between the lines
- The paper's own per-site breakdown leaves the perceived-deception effect open: because it reached significance in only one of the two locations, a pre-registered multi-site replication with per-site power is needed before treating 'users feel deceived' as a settled consequence of this dialog design.
- The recall measure could be developed into an audit test for consent dialogs: if users who click the main button cannot correctly state what they agreed to, the dialog likely fails the GDPR's informed-consent requirement; validating that test against actual browsing behavior is the natural next step.
- The study's convenience sample of computer-literate students makes the consent effect a lower-bound estimate for the general public; a field experiment on a live website with a non-student population could test whether susceptibility is even larger.
- A design change already observed in practice — relabeling the button once a checkbox is selected — can be tested as a remedy: a follow-up experiment could compare uninformed consent and post-hoc regret between the static label and the dynamic label.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. This paper reports a controlled classroom experiment (N=150 German-speaking university students in Austria and Germany) testing how two design features of GDPR consent dialogs affect users' consent decisions and perceptions. The three conditions are: a "deceptive" dialog with a highlighted "Select all and confirm" default button (T1), a reduced-choice dialog with only one purpose (T2), and a control dialog with three purposes and no highlighted default button. The authors hypothesize that the default button increases effective consent (H1), increases regret and perceived deception after users are informed of their choice (H2a, H2b), that multiple purposes increase response time (H3), and that multiple purposes increase perceived difficulty (H4). Results support H1 (T1 participants consented to significantly more purposes), H2a (regret increased after being informed in T1), and H3 (response time was longer for three purposes than one), while H4 is rejected. The paper interprets these findings as evidence that a highlighted default button can mislead users into accepting more data processing than intended, with policy implications for GDPR consent design.
Significance. The study addresses a timely and practically important question: whether specific design elements in GDPR consent dialogs distort users' consent decisions. The main behavioral result (H1) is important and appears well supported: participants who saw the highlighted default button accepted significantly more purposes, and the effect size is large relative to prior default-effect results. The paper also contributes a detailed, transparently described instrument with an attempt at cross-site replication, and it appropriately discusses ethical considerations and limitations. However, the headline claim about perceived deception (H2b) is fragile: the pooled effect is only marginally significant and the site-specific robustness analysis contradicts the paper's own claim of replication. Because the abstract and Section 6.1 present perceived deception as a central outcome, the generalization of this particular result needs to be qualified or substantiated with additional analysis before the paper can be considered robust.
major comments (3)
- [Section 6.2, Table 6] The sentence "Table 6 confirms that H1–H3 are supported in both populations" is incorrect for H2b. Table 6 shows the perceived-deception effect is significant in Austria (p=0.019) but clearly absent in Germany (p=0.564). Even applying the authors' stated remedy of halving the two-sided p-value for the smaller German subsample yields p=0.282, not a significant effect. The abstract and Section 6.1 list perceived deception as a headline finding, so this is an internal inconsistency in the robustness argument rather than a minor caveat. The paper should either remove the generalizable deception claim, report the site-specific nature of the effect, or provide a formal location-by-treatment interaction test to demonstrate that the site difference is not meaningful. At minimum, the claim that Table 6 confirms support for H1–H3 in both populations must be corrected.
- [Section 5.1, H2b] The pooled support for H2b rests on a marginally significant t-test (t(96.8279)=2.24, p<0.05, d=0.44) conducted after several other hypothesis tests on the same data. The paper does not apply any multiple-comparison correction, and the normality justification for PDE is the weakest among the constructs (Kolmogorov–Smirnov p=0.10 in Table 4). Given the site-specific null result in Germany, the perceived-deception finding is fragile. I recommend reporting a non-parametric Mann-Whitney U test as a robustness check and explicitly discussing the false-positive risk, or softening the conclusion to indicate the effect is suggestive and requires replication.
- [Section 4.1, H3] The H3 comparison between T1 and T2 confounds the number of purposes with the specific purpose content: T2 presents only "personalization", which the authors themselves note is the most sensitive purpose, whereas T1 presents three purposes including personalization. The observed response-time difference (median 5.36s vs 3.16s) may therefore be due to the particular purpose shown rather than to choice proliferation per se. This is acknowledged only indirectly by calling T2 "somewhat artificial". Since H4 is rejected and the choice-proliferation contribution is secondary to the main H1 result, the paper should explicitly acknowledge this confound as a limitation of the H3 evidence.
minor comments (5)
- [Section 5.1, H2b] The t-test for H2b uses unpooled (Welch) degrees of freedom (t(96.8279)); please state explicitly that Welch's correction is used, as it affects the interpretation of the test.
- [Table 4] The Q-Q plots do not render as figures in the text; consider replacing them with a single combined figure or a verbal summary, since the current table is not informative to readers.
- [Section 6.2, footnote 6] The footnote stating that some p-values for Germany are above 5% only because two-sided tests are used is itself a form of one-sided reasoning applied post hoc. The one-sided correction is not applied consistently (it was not pre-registered), and for H2b it does not rescue the null result. Please revise the footnote for accuracy.
- [Section 4.2] In the description of pretests, the sentence "During the test, we observed that several test subjects glanced at their neighbors' screens" is informal; "several" would be better expressed as a count or proportion for precision.
- [Section 6.1] The phrase "our experimental results confirm the common conjecture" is a bit strong given that one of the four hypotheses was rejected and another is site-dependent; consider "provide evidence consistent with" instead.
Circularity Check
No circularity: the study is an externally motivated controlled experiment whose conclusions rest on new behavioral and self-report data, not on fitted parameters or self-referential derivations.
full rationale
The paper reports a controlled classroom experiment with one control and two treatment groups (N=150) and tests four pre-registered-style hypotheses (H1–H4) derived from established literature on choice proliferation, social norms, and deception. The dependent variables (number of effectively consented purposes, response time, recall accuracy, perceived deception, regret, perceived difficulty) are measured independently of the independent variables (presence of a highlighted 'select all' default button and number of presented purposes), and the statistical tests (Kruskal-Wallis, t-tests, chi-squared tests) compare observed group differences rather than recovering inputs from outputs. There is no fitted parameter later renamed as a prediction, no equation whose target quantity is defined in terms of the predicted quantity, and no reliance on a self-citation as the sole justification for a central claim. The authors do cite their own prior work (e.g., Böhme and Köpsell 2010; Korff and Böhme 2014), but only as background literature or as a comparative effect-size benchmark, not as evidence that replaces the present experiment. The site-level robustness table (Table 6) actually weakens the generality of H2b, and the text's assertion that 'Table 6 confirms that H1–H3 are supported in both populations' is contradicted by the German subsample for H2b (p=0.564). That is a correctness and generalizability concern about the perceived-deception claim, not a circularity concern, because the claim is still an empirical outcome subject to replication rather than a construct that is true by definition. The paper's main behavioral result (H1) and the recall and regret results are supported by direct measurement with no circular reduction. Therefore the appropriate circularity score is 0.
Assumptions & free parameters
assumptions (4)
- domain assumption The adapted Perceived Deception scale from Román (2010) measures perceived deception in the cookie consent context.
- domain assumption Response time from dialog display to button click is a valid measure of cognitive effort.
- domain assumption Participants did not guess the study's real focus on cookie consent.
- domain assumption Random assignment produced comparable experimental groups.
Cite this review
Pith. "Pith review of Multiple Purposes, Multiple Problems: A User Study of Consent Dialogs after GDPR." pith.science (2026). https://pith.science/paper/GB2LFWME
@misc{pith2026190810048,
author = {Pith},
title = {Pith review of: Multiple Purposes, Multiple Problems: A User Study of Consent Dialogs after GDPR},
year = {2026},
howpublished = {\url{https://pith.science/paper/GB2LFWME}},
note = {Machine review of arXiv:1908.10048}
}
abstract
The European Union's General Data Protection Regulation (GDPR) requires websites to ask for consent to the use of cookies for \emph{specific purposes}. This enlarges the relevant design space for consent dialogs. Websites could try to maximize click-through rates and positive consent decision, even at the risk of users agreeing to more purposes than intended. We evaluate a practice observed on popular websites by conducting an experiment with one control and two treatment groups ($N=150$ university students in two countries). We hypothesize that users' consent decision is influenced by (1) the number of options, connecting to the theory of choice proliferation, and (2) the presence of a highlighted default button (``select all''), connecting to theories of social norms and deception in consumer research. The results show that participants who see a default button accept cookies for more purposes than the control group, while being less able to correctly recall their choice. After being reminded of their choice, they regret it more often and perceive the consent dialog as more deceptive than the control group. Whether users are presented one or three purposes has no significant effect on their decisions and perceptions. We discuss the results and outline policy implications.
Figures
Figures from the paper (7 more)
Reference graph
Works this paper leans on
-
[1]
European Parliament and the Council of the European Union. Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (2016)
work page 2016
-
[2]
European Parliament and the Council of the European Union. Directive 2002/58/EC of 12 July 2002 concerning the processing of personal data and the protection of pri- vacy in the electronic communications sector (Directive on privacy and electronic communications) (2002)
work page 2002
-
[3]
European Parliament and the Council of the European Union. Directive 2009/136/EC of 25 November 2009 amending Directive 2002/22/EC universal service and users’ rights relating to electronic communications networks and services, Directive 2002/58/EC concerning the processing of personal data and the protection of privacy in the electronic communications se...
work page 2009
- [4]
-
[5]
M. Trevisan, B. E. Traverso, Stefano, M. Mellia. 4 years of EU cookie law: Results and lessons learned. In: Proceedings on Privacy Enhancing Technologies (PoPETs) (De Gruyter Open, 2019) 126–145
work page 2019
-
[6]
R. van Eijk, H. Asghari, P. Winter, A. Narayanan. The impact of user location on cookie notices (inside and outside of the European Union). In: Workshop on Technology and Consumer Protection (ConPro) (2019)
work page 2019
-
[7]
S. Englehardt, A. Narayanan. Online tracking: A 1-million- site measurement and analysis. In: Conference on Computer and Communications Security (CCS) (ACM, 2016) 1388– 1401
work page 2016
-
[8]
M. Degeling, C. Utz, C. Lentzsch, H. Hosseini, F. Schaub, T. Holz. Measuring the GDPR’s impact on web privacy. In: Network and Distributed System Security Symposium (NDSS) (Internet Society, 2019)
work page 2019
Show all 70 references
-
[9]
C. Utz, M. Degeling, S. Fahl, F. Schaub, T. Holz. (Un)informed consent: Studying GDPR consent notices in the field. In: Conference on Computer and Communications Security (CCS) (ACM, 2019) 973–990
2019
-
[10]
Sánchez-Rola, M
I. Sánchez-Rola, M. Dell’Amico, P. Kotzias, D. Balzarotti, L. Bilge, P. Vervier, et al. Can I opt out yet?: GDPR and the global illusion of cookie control. In: Conference on Computer and Communications Security (AsiaCCS) (ACM,
-
[11]
J. R. Kling, S. Mullainathan, E. Shafir, L. Vermeulen, M. V. Wrobel. Misperception in choosing medicare drug plans. Harvard University working paper (2008) A User Study of Consent Dialogs after GDPR 496
2008
-
[12]
Cronqvist, R
H. Cronqvist, R. H. Thaler. Design choices in privatized social-security systems: Learning from the Swedish experi- ence. American Economic Review (2004) 94, 2, 424—428
2004
-
[13]
S. Korff, R. Böhme. Too much choice: End-user privacy de- cisions in the context of choice proliferation. In: Symposium On Usable Privacy and Security (SOUPS) (USENIX, 2014) 69–87
2014
-
[14]
The GDPR: New opportunities, new obligations
European Commission. The GDPR: New opportunities, new obligations. Tech. rep., Publications Office of the European Union, Brussels, Luxembourg (2018)
2018
-
[15]
Judgement in Case C-673/17 in the proceedings Bundesverband der Verbraucherzentralen und Verbraucherverbände vs Planet49 GmbH (2019)
European Court of Justice. Judgement in Case C-673/17 in the proceedings Bundesverband der Verbraucherzentralen und Verbraucherverbände vs Planet49 GmbH (2019)
2019
-
[16]
WordPress and GDPR, and how to deal with cookies and plugins
Cybot A/S. WordPress and GDPR, and how to deal with cookies and plugins. Copenhagen, Denmark (2019). https: //www.cookiebot.com/en/wordpress-cookie-plugin/
2019
-
[17]
Ackerman, L
M. Ackerman, L. F. Cranor, J. Reagle. Privacy in e- commerce: Examining user scenarios and privacy prefer- ences. In: Conference on Electronic Commerce (EC) (ACM,
-
[18]
L. I. Millett, B. Friedman, E. Felten. Cookies and web browser design: Toward realizing informed consent online. In: Conference on Human Factors in Computing System (CHI) (ACM, 2001) 46–52
2001
-
[19]
Schaub, R
F. Schaub, R. Balebako, A. L. Durity, L. F. Cranor. A design space for effective privacy notices. In: Symposium On Usable Privacy and Security (SOUPS) (USENIX, 2015) 1–17
2015
-
[20]
Bergmann
M. Bergmann. Generic predefined privacy preferences for online applications. In: IFIP International Summer School on the Future of Identity in the Information Society (Springer,
-
[21]
J. S. Pettersson, S. Fischer-Hubner, M. C. Mont, S. Pear- son. How ordinary internet users can have a chance to influence privacy policies. In: Nordic conference on Human- computer interaction: Changing roles (NordiCHI) (ACM,
-
[22]
J. S. Pettersson, S. Fischer-Hübner, N. Danielsson, J. Nils- son, M. Bergmann, S. Clauss, et al. Making PRIME usable. In: Symposium on Usable Privacy and Security (SOUPS) (ACM, 2005) 53–64
2005
-
[23]
J. J. Borking. Privacy incorporated software agent (PISA): Proposal for building a privacy guardian for the electronic age. In: Designing Privacy Enhancing Technologies: In- ternational Workshop on Design Issues in Anonymity and Unobservability (Springer, 2001) 130–140
2001
-
[24]
Bergmann
M. Bergmann. Testing privacy awareness. In: IFIP Summer School on the Future of Identity in the Information Society (Springer, 2008) 237–253
2008
-
[25]
L. F. Cranor. P3P: Making privacy policies more useful. Security & Privacy (2003) 99, 6, 50–55
2003
-
[26]
Langheinrich, L
M. Langheinrich, L. Cranor, M. Marchiori. Appel: A P3P preference exchange language. W3C Working Draft (2002)
2002
-
[27]
Ulbricht, F
M.-R. Ulbricht, F. Pallas. YaPPL – a lightweight privacy preference language for legally sufficient and automated consent provision in IoT scenarios. In: J. García-Alfaro, J. Herrera-Joancomartí, G. Livraga, R. Rios (Eds.) Data Privacy Management, Cryptocurrencies and Blockchain...
2018
-
[28]
T. Vila, R. Greenstadt, D. Molnar. Why we can’t be both- ered to read privacy policies. In: Economics of Information Security (Springer, 2004), 143–153
2004
-
[29]
Grossklags, N
J. Grossklags, N. Good. Empirical studies on software no- tices to inform policy makers and usability designers. In: Financial Cryptography and Data Security (FC) (Springer,
-
[30]
Kulyk, A
O. Kulyk, A. Hilt, N. Gerber, M. Volkamer. Users’ percep- tions and reactions to the cookie disclaimer. In: European Workshop on Usable Security (EuroUSEC) (2018)
2018
-
[31]
Böhme, S
R. Böhme, S. Köpsell. Trained to accept?: A field experi- ment on consent dialogs. In: Conference on Human Factors in Computing System (CHI) (ACM, 2010) 2403–2406
2010
-
[32]
A. P. Felt, S. Egelman, M. Finifter, D. Akhawe, D. A. Wag- ner, et al. How to ask for permission. HotSec (2012)
2012
-
[33]
Spiekermann, A
S. Spiekermann, A. Acquisti, R. Böhme, K. L. Hui. The challenges of personal data markets and privacy. Electronic Markets (2015) 25, 2, 161–167
2015
-
[34]
Scheibehenne, R
B. Scheibehenne, R. Greifeneder, P. M. Todd. Can there ever be too many options? A meta-analytic review of choice overload. Journal of Consumer Research (2010) 37, 3, 409– 425
2010
-
[35]
E. J. Johnson, S. B. Shu, B. G. Dellaert, C. Fox, D. G. Goldstein, G. Häubl, et al. Beyond nudges: Tools of a choice architecture. Marketing Letters (2012) 23, 2, 487–504
2012
-
[36]
B. P. Knijnenburg, A. Kobsa, H. Jin. Preference-based location sharing: Are more privacy options really better? In: Conference on Human Factors in Computing System (CHI) (ACM, 2013) 2667–2676
2013
-
[37]
K. Tang, J. Hong, D. Siewiorek. The implications of offer- ing more disclosure choices for social location sharing. In: Conference on Human Factors in Computing System (CHI) (ACM, 2012) 391–394
2012
-
[38]
Krasnova, N
H. Krasnova, N. Eling, O. Schneider, H. Wenninger, T. Wid- jaja, P. Buxmann, et al. Does this app ask for too much data? The role of privacy perceptions in user behavior to- wards Facebook applications and permission dialogs. In: Eu- ropean Conference on Information Systems (E...
2013
-
[39]
Anderson
C. Anderson. The long tail: Why the future of business is selling less of more (Hachette Books, London, UK, 2006)
2006
-
[40]
J. M. Hutchinson. Is more choice always desirable? Evidence and arguments from leks, food selection, and environmental enrichment. Biological Reviews (2005) 80, 1, 73–92
2005
-
[41]
Böhme, J
R. Böhme, J. Grossklags. The security cost of cheap user interaction. In: New Security Paradigms Workshop (NSPW) (ACM, 2011) 67–82
2011
-
[42]
S. Egelman. My profile is my password, verify me!: The privacy/convenience tradeoff of Facebook Connect. In: Conference on Human Factors in Computing System (CHI) (ACM, 2013) 2369–2378
2013
-
[43]
P. E. Johnson, S. Grazioli, K. Jamal, R. G. Berryman. De- tecting deception: Adversarial problem solving in a low base- rate world. Cognitive Science (2001) 25, 3, 355–392
2001
-
[44]
S. Román. Relational consequences of perceived deception in online shopping: The moderating roles of type of product, consumer’s attitude toward the internet and consumer’s demographics. Journal of Business Ethics (2010) 95, 3, 373–391
2010
-
[45]
B. Xiao, I. Benbasat. Product-related deception in e- commerce: A theoretical perspective. MIS Quarterly (2011) A User Study of Consent Dialogs after GDPR 497 35, 1, 169–196
2011
-
[46]
Nochenson, J
A. Nochenson, J. Grossklags. An online experiment on con- sumers’ susceptibility to fall for post-transaction marketing scams. In: European Conference on Information Systems (ECIS) (Association for Information Systems, 2014)
2014
-
[47]
D. M. Boush, M. Friestad, P. Wright. Deception in the mar- ketplace: The psychology of deceptive persuasion and con- sumer self-protection (Routledge/Taylor & Francis Group, 2015)
2015
-
[48]
Fleming, S
P. Fleming, S. C. Zyglidopoulos. The escalation of deception in organizations. Journal of Business Ethics (2008) 81, 4, 837–850
2008
-
[49]
K. A. Jehn, E. D. Scott. Perceptions of deception: Making sense of responses to employee deceit. Journal of Business Ethics (2008) 80, 2, 327–347
2008
-
[50]
K. Yoon, K. Knight, D. Martin. Deceiving team members about competence: Its motives and consequences. Western Journal of Communication (2018) 1–22
2018
-
[51]
Shneiderman, M
B. Shneiderman, M. Leavitt, et al. Research-based web design & usability guidelines (Department of Health and Human Services, Washington, DC, 2006)
2006
-
[52]
Watson, H
J. Watson, H. R. Lipford, A. Besmer. Mapping user prefer- ence to privacy default settings. Transactions on Computer- Human Interaction (TOCHI) (ACM, 2015) 22, 32
2015
-
[53]
C. I. Hovland, I. L. Janis, H. H. Kelley. Communication and Persuasion: Psychological Studies of Opinion Change (Greenwood Press, 1953)
1953
-
[54]
C. M. Gray, Y. Kou, B. Battles, J. Hoggatt, A. L. Toombs. The dark (patterns) side of UX design. In: Conference on Human Factors in Computing System (CHI) (ACM, 2018) 534:1–14
2018
-
[55]
Brignull
H. Brignull. Dark patterns. Tech. rep. (2019). https: //darkpatterns.org
2019
-
[56]
Bösch, B
C. Bösch, B. Erb, F. Kargl, H. Kopp, S. Pfattheicher. Tales from the dark side: Privacy dark strategies and privacy dark patterns (De Gruyter Open, 2016), vol. 2016 237–254
2016
-
[57]
A. M. McDonald, L. F. Cranor. The cost of reading privacy policies. I/S: J. L (2008) 4, 3, 540–565
2008
-
[58]
Mathur, G
A. Mathur, G. Acar, M. J. Friedman, E. Lucherini, J. Mayer, M. Chetty, et al. Dark patterns at scale: Findings from a crawl of 11K shopping websites. Proceedings of the ACM on Human-Computer Interaction (2019) 3, 81
2019
-
[59]
J. M. Bland, D. G. Altman. Cronbach’s alpha. British Medical Journal (1997) 314, 7080, 570–572
1997
-
[60]
G. A. Miller. The magic number seven, plus or minus two: Some limits on our capacity for processing information. Psy- chological Review (1956) 63, 2, 81–97
1956
-
[61]
P. A. Norberg, D. R. Horne, D. A. Horne. The privacy para- dox: Personal information disclosure intentions versus behav- iors. Journal of Consumer Affairs (2007) 41, 1, 100–126
2007
-
[62]
S. S. Sundar, H. Kang, M. Wu, E. Go, B. Zhang. Unlocking the privacy paradox: Do cognitive heuristics hold the key? In: Extended Abstracts on Human Factors in Computing Systems (CHI EA) (ACM, 2013), 6 811–816
2013
-
[63]
Gerber, P
N. Gerber, P. Gerber, M. Volkamer. Explaining the privacy paradox: A systematic review of literature investigating pri- vacy attitude and behavior. Computers & Security (2018) 77, 226–261
2018
-
[64]
I. Ajzen. Models of human social behavior and their applica- tion to health psychology. Psychology and Health (1998) 13, 4, 735–739
1998
-
[65]
Dienlin, S
T. Dienlin, S. Trepte. Is the privacy paradox a relic of the past? An in-depth analysis of privacy attitudes and privacy behaviors. European Journal of Social Psychology (2015) 45, 3, 285–297
2015
-
[66]
M. T. Orne. On the social psychology of the psychological experiment: With particular reference to demand characteris- tics and their implications. American psychologist (1962) 17, 11, 776–783
1962
-
[67]
J. P. Walsh, S. Kiesler, L. S. Sproull, B. W. Hesse. Self- selected and randomly selected respondents in a computer network survey. Public Opinion Quarterly (1992) 56, 2, 241–244
1992
-
[68]
H. Cho, R. LaRose. Privacy issues in internet surveys. Social Science Computer Review (1999) 17, 4, 421–434
1999
-
[69]
Challenges and opportunities for EU cybersecurity start-ups (2019) 2019
European Union Agency for Network and Information Se- curity. Challenges and opportunities for EU cybersecurity start-ups (2019) 2019
2019
-
[70]
L. Olejni. A second life for the ‘do not track’ setting – with teeth. Wired (2019) https://www.wired.com/story/a- second-life-for-the-do-not-track-setting 8 Appendix Fig. 7. Pop-up with questionnaire. A User Study of Consent Dialogs after GDPR 498 Deception (T1) Reduced choice...
2019
Reviewed August 14, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.