Pith. sign in

REVIEW 3 major objections 5 minor 52 references

(Un)informed Consent: Studying GDPR Consent Notices in the Field

T0 review · 3 major / 5 minor · reviewed 2026-08-14 · deepseek-v4-flash

Pith's one-line read Seemingly cosmetic choices in cookie consent banners—position, pre-selection, and wording—decisively shape whether users consent, with accept-all rates ranging from under 0.1% to roughly 30%.

desk verdict Good field experiment on consent banners, but the famous 0.1% opt-in figure conflates default setting with click effort; the qualitative results hold up. read the letter →

arxiv 1909.02638 v2 pith:6RUN76X7 submitted 2019-09-05 cs.HC cs.CY

classification cs.HCcs.CY
keywords GDPRconsentnoticescookiebannersnudginganddarkpatternsprivacybydefaultfieldexperimentusablebehavioronlinetracking
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper tries to establish that how a website asks for consent matters as much as whether it asks. Across three field experiments with 82,890 real visitors to a German e-commerce website, the authors varied the banner's position, the number and framing of choices, and the wording, then logged every click. They find that placement alone changes interaction rates from about 3% to 37%, that pre-selecting cookie categories makes roughly 30% of mobile and 10% of desktop visitors accept all third parties, and that a strict opt-in banner draws under 0.1% accept-all decisions. If true, this means the ubiquity of cookie banners is not the real problem; the design choices embedded in them are, and regulation that ignores interface design cannot deliver the informed, free consent the GDPR promises.

What carries the argument

The load-bearing object is a set of consent-notice variants built from eight user-interface variables the authors first catalogued in 1,000 real notices: position, size, blocking, choices, text, nudging, formatting, and links. The experiments manipulate three of these—position; choice type and nudging; wording and privacy-policy link—while holding the rest constant. The mechanism that carries the argument is the comparison of interaction and accept/decline rates between otherwise identical notices, especially the contrast between pre-selected checkboxes (nudging) and unchecked, privacy-by-default checkboxes. That contrast isolates the effect of default framing from everything else about the notice.

What would settle it

Run the same nine-condition experiment on a site with a different audience, such as a desktop-heavy news site, and compare accept-all rates in the opt-in and pre-selected conditions: if the opt-in accept-all share approaches the pre-selected share, or if pre-selection raises acceptance only slightly, then the paper's central claim that design defaults dominate consent would not hold in that context.

Watch

Extended reading notes

Core claim

The central claim is that seemingly small implementation decisions in consent-notice interfaces substantially change whether and how visitors consent, and that most current notices are built to manufacture consent rather than record it. In the sharpest result, a privacy-by-default (opt-in) notice led fewer than 0.1% of visitors to allow cookies for all purposes, while pre-selecting all checkboxes led around 30% of mobile and 10% of desktop users to accept all third parties; 1 to 4% of opt-in users still selected some parties. A dialog in the lower-left corner drew interactions from 37.1% of visitors, versus 2.9% for a top bar. More choices made visitors more likely to decline cookies, and highlighting the accept button increased acceptance even when it was the only action. The authors conclude that opt-out banners are unlikely to produce intentional consent and recommend opt-in, category-based notices as the design that matches both GDPR's purpose-specific consent and users' stated preferences.

Load-bearing premise

The behavior of 82,890 visitors to a single German-language e-commerce website—78% on mobile devices and most staying only seconds—represents the broader European internet population closely enough to support the paper's regulatory recommendations.

Editorial extensions

If this is right

  • Enforcing the GDPR's data-protection-by-default principle would, on these numbers, cut accept-all consent to below 0.1% on sites like the one studied, a level that current behavioral-advertising business models could not absorb.
  • Regulators should specify consent-notice requirements—position, default states, and number of choices—rather than only requiring that consent be asked.
  • Category-based opt-in notices would satisfy users' desire for control without the overwhelming detail of vendor lists.
  • Websites serious about meaningful consent should place notices where they interrupt reading (lower left on desktop, lower part of the screen on mobile) and avoid pre-selection and highlighted accept buttons.
  • The common top-of-screen bar used by about a quarter of sites in the authors' corpus is the least effective at eliciting any choice, which suggests many current notices mainly train users to ignore them.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • If the same banner-design elasticity holds across other site types, then 'consent fatigue' is partly an artifact of bad default designs, and browser-level or cross-site consent tools could be built on opt-in defaults rather than repeated banners.
  • The study's site drew mostly mobile, short-dwell visitors; a replication on a desktop-heavy news site or a service with user accounts could show larger or smaller nudging effects, so the absolute percentages should be read as site-specific until re-tested.
  • A natural extension would test the same variants with users who already run ad blockers; the paper's ad-blocker subsample suggests these users engage less with banners, which may mean their consent decisions are systematically underrepresented in current consent logs.
  • Comparing the same consent-banner variants across languages and countries could separate left-to-right reading effects from genuine position preferences, which the current single-language, single-site design cannot do.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 5 minor

Summary. The paper investigates how the user-interface design of GDPR cookie consent notices affects visitor consent behavior. The authors first analyze 1,000 consent notices collected from popular European websites and identify eight design variables. They then report three between-subjects field experiments on a German e-commerce website with 82,890 unique visitors, varying notice position (Experiment 1), choice granularity and nudging via preselection or highlighting (Experiment 2), and wording plus the presence of a privacy-policy link (Experiment 3). The main findings are that bottom-left placement yields the highest interaction, binary notices receive more acceptance than granular category/vendor notices, nudging substantially increases acceptance, and in the opt-in granular conditions fewer than 0.1% of visitors accept every purpose or vendor. The paper concludes that small implementation decisions have large effects and argues that enforcing the GDPR's data-protection-by-default principle would lead to very low active consent to third-party cookies, recommending opt-in category-based notices.

Significance. The study is valuable because it provides large-scale field evidence, with random assignment, on a topic previously studied mostly through surveys or small lab experiments. The external validation against Cookiebot data and the public availability of the materials are notable strengths, as are the rich interaction logs and the follow-up survey responses. If the headline results are interpreted carefully, the paper makes a strong empirical case that seemingly minor design choices in consent notices substantially change consent behavior, which is directly relevant to current regulatory and technical debates about dark patterns and meaningful consent. However, the quantitative headline about 'less than 0.1%' under GDPR-compliant opt-in notices is weakened by a confound between default selection and interaction effort, and the single-site sample limits the policy generalization.

major comments (3)
  1. [Section 4.3.1 and Section 7] The central quantitative claim conflates the default setting with the required interaction effort. In Experiment 2, the opt-in category and vendor conditions (Categories–Non-Nudging and Vendors–Non-Nudging) began with all checkboxes unchecked and required the visitor to tick each purpose or vendor individually before submitting; no 'Accept all' or 'Select all' control is described in Section 3.3 or in Figure 4. The preselected conditions, by contrast, allowed acceptance with zero additional clicks. Thus the contrast 'less than 0.1% accept all' versus roughly 30% of mobile and 10% of desktop users accepting all third parties simultaneously varies the default and the number of clicks needed to reach 'accept all' (five to six clicks versus none). The timing data in Appendix A, with medians of 7–8 seconds for category/vendor notices versus 4–5 seconds for binary notices, are consistent with an effort effect. Section 7's conclusion that enforcing data-protection-by-default would lead to 'less than 0.1% of users actively consenting to the use of third-party cookies' is therefore warranted only for this specific high-effort granular design, not for opt-in notices generally. The authors should either add an opt-in condition with an 'Accept all' button, reanalyze the existing data to separate the default effect from the effort effect, or substantially qualify the claim.
  2. [Section 6.2 and Section 4.3.1] The manuscript reports no confidence intervals for the main proportions, even though the headline claims rest on comparisons of very small percentages (e.g., <0.1% versus 0.16% in Table 2). For a proportion near zero with a few thousand observations, the sampling uncertainty is non-negligible, and the paper's own external validation shows differences that are attributed to context but are unquantified. Reporting Wilson or exact binomial confidence intervals for the key 'Accept all' proportions in Figures 4 and 6 and Table 2 would make the strength of the evidence transparent. This is not merely a presentation issue because the regulatory conclusion in Section 7 depends on how precisely the extremely low opt-in rate is estimated.
  3. [Section 6.2] The paper acknowledges in Section 6.2 that the sample is a German-language e-commerce website whose visitors may not be representative of the general public, and that the sample 'seems more inclined towards rejecting cookies.' Given that the policy recommendations in Sections 6.1 and 7 generalize from this single site, the authors should more explicitly condition their recommendations on this limitation and discuss which findings are likely to be site-specific. The Cookiebot comparison helps, but the Cookiebot notices differ in interaction design (some categories cannot be deselected), so it does not fully resolve external validity. This does not invalidate the qualitative conclusion that design matters, but it does limit the quantitative claims about the absolute level of consent under GDPR-compliant notices.
minor comments (5)
  1. [Section 3.1] The 30-second automatic replacement of the consent notice with the survey invitation is a notable modification of the browsing experience, but the paper does not discuss whether this auto-replacement could itself affect the measured interaction rates or the interpretation of 'no action' responses. A sentence addressing this would strengthen the methodology.
  2. [Section 4.3.2] The observation that 'more visitors selected specific vendors than categories' is presented without a statistical test or confidence interval; given the small absolute numbers, a significance test or an explicit statement of the raw counts would help the reader gauge the robustness of this finding.
  3. [Table 1] In the 'Text: Processor' row, 'third party 2.6 &' should read 'third party 2.6 %'.
  4. [Abstract and Section 2.1] The phrase 'data protection by default' is used to refer both to the GDPR's Article 25 principle and to an opt-in consent default; a brief clarification of the legal term would prevent conflation of the two concepts.
  5. [Section 4.2.1] The use of Cramér's V is fine, but the paper should state whether the reported p-values are corrected for multiple comparisons across the many conditions and interactions tested in Experiment 1.

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity: the paper's conclusions are empirical field measurements, and its self-citations supply only background taxonomy and prevalence data.

full rationale

The paper's central claims—position, choice complexity, nudging, and wording affect consent behavior—are supported by between-subjects field experiments on 82,890 real visitors, not by derivation from assumed inputs. The sharp quantitative headline that fewer than 0.1% of visitors accept all purposes in opt-in notices while preselection yields roughly 30% (mobile) and 10% (desktop) acceptance is an observed contrast between specific notice variants (Section 4.3.1), not a quantity fitted to or defined by another result. The authors' prior taxonomy (Degeling et al. [12]) is used to describe notice properties and motivate conditions, but the outcome data are newly collected and are externally benchmarked against Cookiebot logs (Section 4.3.3), so the self-citation is not load-bearing. The skeptical concern that the opt-in conditions differed from the nudging conditions in required click effort is a construct-validity or generalizability limitation, not circularity: the paper does not define 'opt-in' as 'high-effort interface' and then predict high-effort behavior from that definition. The paper even acknowledges sample-representativeness limits in Section 6.2. No equation, fitted parameter, or imported uniqueness theorem makes any claimed result equivalent to its inputs by construction.

Assumptions & free parameters 1 free parameters · 4 assumptions · 0 invented entities

The paper is an empirical field study and introduces no new theoretical entities, forces, or parameters. The main assumptions are about the correctness of the measurement plugin, the representativeness of the prior crawl, the legal interpretation of GDPR, and the validity of round-robin assignment.

free parameters (1)
  • Auto-replacement threshold = 30 seconds
    Time after page load after which the consent notice content is replaced with a survey invitation. Chosen based on analytics showing 95% of interactions occur within 30 seconds. This threshold defines which visitors are classified as having taken no action.
assumptions (4)
  • domain assumption The modified Ginger plugin correctly blocks non-necessary cookies before opt-in and logs all interactions as described in Section 3.1.
    The study does not independently verify the plugin's cookie blocking behavior. If enforcement failed, the click events would not correspond to actual consent outcomes.
  • domain assumption The set of 5,087 consent notices and the random sample of 1,000 drawn from the authors' previous study [12] is representative of European consent notices.
    Section 2.2 builds on the earlier crawl; its representativeness is inherited, not re-established in this paper.
  • domain assumption The GDPR requires 'freely given, specific, informed and unambiguous' consent and enshrines data protection by default.
    The paper uses this legal standard as the normative benchmark for evaluating observed consent behavior (Sections 2.1 and 6.1). If the interpretation is disputed, the policy conclusions weaken.
  • standard math Round-robin assignment of notices approximates random assignment for valid between-subjects inference.
    Section 3.1 states notices were assigned in round-robin fashion; no randomization check or covariate balance table is provided.

how reviews work

0 comments
Cite this review

Pith. "Pith review of (Un)informed Consent: Studying GDPR Consent Notices in the Field." pith.science (2026). https://pith.science/paper/6RUN76X7

@misc{pith2026190902638,
  author       = {Pith},
  title        = {Pith review of: (Un)informed Consent: Studying GDPR Consent Notices in the Field},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/6RUN76X7}},
  note         = {Machine review of arXiv:1909.02638}
}
read the original abstract

Since the adoption of the General Data Protection Regulation (GDPR) in May 2018 more than 60 % of popular websites in Europe display cookie consent notices to their visitors. This has quickly led to users becoming fatigued with privacy notifications and contributed to the rise of both browser extensions that block these banners and demands for a solution that bundles consent across multiple websites or in the browser. In this work, we identify common properties of the graphical user interface of consent notices and conduct three experiments with more than 80,000 unique users on a German website to investigate the influence of notice position, type of choice, and content framing on consent. We find that users are more likely to interact with a notice shown in the lower (left) part of the screen. Given a binary choice, more users are willing to accept tracking compared to mechanisms that require them to allow cookie use for each category or company individually. We also show that the wide-spread practice of nudging has a large effect on the choices users make. Our experiments show that seemingly small implementation decisions can substantially impact whether and how people interact with consent notices. Our findings demonstrate the importance for regulation to not just require consent, but also provide clear requirements or guidance for how this consent has to be obtained in order to ensure that users can make free and informed choices.

Figures

Figures reproduced from arXiv: 1909.02638 by the authors.

Figure 1
Figure 1. Cookie consent notices with different choice mechanisms and nudging used in our experiments: (a) a binary notice [PITH_FULL_IMAGE:figures/full_fig_p006_1.png] view at source ↗
Figure 2
Figure 2. Positions tested in Experiment 1. visitors towards accepting. We observed this for 57.4 % of the no￾tices in our sample. Our research question therefore was: Does the number of choices and nudging through emphasis or pre-selection in consent notices influence user’s consent decisions? For nudging, we used pre-checked checkboxes and buttons high￾lighted in contrasting colors, techniques often used to nudge users towa… view at source ↗
Figure 3
Figure 3. Interaction rates in Experiment 1 (notice position), [PITH_FULL_IMAGE:figures/full_fig_p008_3.png] view at source ↗
Figures from the paper (3 more)
Figure 4
Figure 4. Figure 4: Visitors’ consent choices in Experiment 2. “Ac [PITH_FULL_IMAGE:figures/full_fig_p009_4.png]
Figure 5
Figure 5. Figure 5: Decisions to allow or decline specific categories (1) or vendors (2) in the the specific conditions of Experiment 2. [PITH_FULL_IMAGE:figures/full_fig_p011_5.png]
Figure 6
Figure 6. Figure 6: Visitors’ interactions with different consent mech [PITH_FULL_IMAGE:figures/full_fig_p011_6.png]

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

52 extracted references · 38 canonical work pages

  1. [1]

    Alessandro Acquisti. 2009. Nudging Privacy: The Behavioral Economics of Personal Information. IEEE Security & Privacy 7, 6 (Dec. 2009), 82–85. https: //doi.org/10.1109/MSP.2009.163

  2. [2]

    Alessandro Acquisti, Idris Adjerid, Rebecca Hunt Balebako, Laura Brandimarte, Lorrie Faith Cranor, Saranga Komanduri, Pedro Leon, Norman Sadeh, Florian Schaub, Manya Sleeper, Yang Wang, and Shomir Wilson. 2017. Nudges for Privacy and Security: Understanding and Assisting Users’ Choices Online. Comput. Surveys 50, 3 (Aug. 2017). https://doi.org/10.2139/ssr...

  3. [3]

    Alessandro Acquisti, Laura Brandimarte, and George Loewenstein. 2015. Privacy and human behavior in the age of information. Science 347, 6221 (Jan. 2015), 509–514. https://doi.org/10.1126/science.aaa1465

  4. [4]

    Alexa Internet, Inc. 2019. The top 500 sites on the Web. https://www.alexa.com/ topsites

  5. [5]

    Article 29 Data Protection Working Party. 2016. Cookie Sweep Combined Analysis – Report . Technical Report 14/EN WP 229. European Commission, Brussels, Belgium

  6. [6]

    Article 29 Data Protection Working Party. 2018. Guidelines on consent under Reg- ulation 2016/679. Technical Report 17/EN WP259 rev.01. European Commission

  7. [7]

    Boerman, Sanne Kruikemeier, and Frederik J

    Sophie C. Boerman, Sanne Kruikemeier, and Frederik J. Zuiderveen Borgesius

  8. [8]

    Matt Burgess. 2018. The tyranny of GDPR popups and the websites failing to adapt. Retrieved April 22, 2019 from https://www.wired.co.uk/article/ gdpr-cookies-eprivacy-regulation-popups

Show all 52 references
  1. [9]

    Virginio Cantoni, Marco Porta, Stefania Ricotti, and Francesca Zanin. 2013. Ban- ner positioning in the masthead area of online newspapers: an eye tracking study. In 14th International Conference on Computer Systems and Technologies (CompSysTech ’13). ACM, New York, NY, USA, 1...

  2. [10]

    Forbrukerrådet (Norwegian Consumer Council). 2018. Deceived by Design – How tech companies use dark patterns to discourage us from exercising our rights to privacy. Technical Report. Oslo, Norway

  3. [11]

    Commission Nationale de l’Informatique et des Libertés (National Commission on Informatics and Liberty). 2018. Décision no MED 2018-042 du 30 octobre 2018 met- tant en demeure la société VECTAURY (Decision No. MED 2018-042 of 30 October 2018 giving notice to the company VECTAU...

  4. [12]

    Martin Degeling, Christine Utz, Christopher Lentzsch, Henry Hosseini, Florian Schaub, and Thorsten Holz. 2019. We Value Your Privacy ... Now Take Some Cookies: Measuring the GDPR’s Impact on Web Privacy. In 26th Annual Network and Distributed System Security Symposium (NDSS ’1...

  5. [13]

    Serge Egelman, Lorrie Faith Cranor, and Jason Hong. 2008. You’ve Been Warned: An Empirical Study of the Effectiveness of Web Browser Phishing Warnings. In Conference on Human Factors in Computing Systems (CHI ’08) . ACM, New York, NY, USA, 1065–1074. https://doi.org/10.1145/13...

  6. [14]

    Interactive Advertising Bureau Europe. 2019. GDPR Trans- parency and Consent Framework. https://iabtechlab.com/standards/ gdpr-transparency-and-consent-framework/. [Online; accessed 2 May 2019]

  7. [15]

    European Data Protection Board. 2019. Opinion 5/2019 on the interplay between the ePrivacy Directive and the GDPR, in particular regarding the competence, tasks and powers of data protection authorities . Technical Report 5/2019

  8. [16]

    Reeder, Sunny Consolvo, Somas Thyagaraja, Helen Bettes, Alan ad Harris, and Jeff Grimes

    Adrienne Porter Felt, Alex Ainslie, Robert W. Reeder, Sunny Consolvo, Somas Thyagaraja, Helen Bettes, Alan ad Harris, and Jeff Grimes. 2015. Improving SSL Warnings: Comprehension and Adherence. In 33rd Annual ACM Conference on Human Factors in Computing Systems (CHI ’15) . ACM...

  9. [17]

    Vitaly Friedman. 2019. Privacy UX: Better Cookie Consent Experiences. Retrieved May 7, 2019 from https://www.smashingmagazine.com/2019/04/ privacy-ux-better-cookie-consent-experiences/

  10. [18]

    Stacia Garlach and Daniel Suthers. 2018. ‘I’m supposed to see that?’ AdChoices Usability in the Mobile Environment. In Hawaii International Conference on System Sciences. University of Hawai‘i at M¯anoa, Honolulu, HI, USA, 3779–3788. https://doi.org/10.24251/hicss.2018.476

  11. [19]

    Vicki Ha, Kori Inkpen, Farah Al Shaar, and Lina Hdeib. 2006. An Examination of User Perception and Misconception of Internet Cookies. In CHI ’06 Extended Abstracts on Human Factors in Computing Systems (CHI EA ’06) . ACM, New York, NY, USA, 833–838. https://doi.org/10.1145/112...

  12. [20]

    Hana Habib, Yixin Zou, Aditi Jannu, Neha Sridhar, Chelse Swoopes, Alessandro Acquisti, Lorrie Faith Cranor, Norman Sadeh, and Florian Schaub. 2019. An Empir- ical Analysis of Data Deletion and Opt-Out Choices on 150 Websites. InFifteenth Symposium On Usable Privacy and Securit...

  13. [21]

    Daniel Kladnik. 2019. I don’t care about cookies 3.0.0. https://www. i-dont-care-about-cookies.eu/. [Online; accessed 2 May 2019]

  14. [22]

    This Website Uses Cookies

    Oksana Kulyk, Annika Hilt, Nina Gerber, and Melanie Volkamer. 2018. “This Website Uses Cookies”: Users’ Perceptions and Reactions to the Cookie Disclaimer. In 3rd European Workshop on Usable Security (EuroUSec 2018) . London, England, 11

  15. [23]

    Oksana Kulyk, Peter Mayer, Oliver Käfer, and Melanie Volkamer. 2018. A Concept and Evaluation of Usable and Fine-Grained Privacy-Friendly Cookie Settings Interface. In 17th IEEE International Conference On Trust, Security And Privacy In Computing And Communications (TrustCom 2...

  16. [24]

    Pedro Leon, Blase Ur, Richard Shay, Yang Wang, Rebecca Balebako, and Lorrie Cranor. 2012. Why Johnny can’t opt out: a usability evaluation of tools to limit online behavioral advertising. In Conference on Human Factors in Computing Systems (CHI ’12) . ACM, New York, NY, USA, 5...

  17. [25]

    White, and Susan Dumais

    Chao Liu, Ryen W. White, and Susan Dumais. 2010. Understanding Web Browsing Behaviors Through Weibull Analysis of Dwell Time. In 33rd International ACM SIGIR Conference on Research and Development in Information Retrieval (SIGIR ’10). ACM, New York, NY, USA, 379–386. https://d...

  18. [26]

    Manafactory. 2019. Ginger – EU Cookie Law. https://wordpress.org/plugins/ ginger/. [Online; accessed 22 August 2019]

  19. [27]

    Kirsten Martin. 2016. Do Privacy Notices Matter? Comparing the Impact of Violating Formal Privacy Notices and Informal Privacy Norms on Consumer Trust Online. The Journal of Legal Studies 45, S2 (June 2016), S191–S215. https: //doi.org/10.1086/688488

  20. [28]

    Arunesh Mathur, Gunes Acar, Michael Friedman, Elena Lucherini, Jonathan Mayer, and Marsh Chetty. 2019. Dark Patterns at Scale: Findings from a Crawl of 11K Shopping Websites. (2019). arXiv:1907.07032

  21. [29]

    Mayer and John C

    Jonathan R. Mayer and John C. Mitchell. 2012. Third-Party Web Tracking: Policy and Technology. In 2012 IEEE Symposium on Security and Privacy (SP ’12) . IEEE Computer Society, Washington, DC, USA, 413–427. https://doi.org/10.1109/SP. 2012.47

  22. [30]

    McDonald and Lorrie Faith Cranor

    Aleecia M. McDonald and Lorrie Faith Cranor. 2010. Americans’ Attitudes About Internet Behavioral Advertising Practices. In 9th Annual ACM Workshop on Privacy in the Electronic Society (WPES ’10) . ACM, New York, NY, USA, 63–72. https://doi.org/10.1145/1866919.1866929

  23. [31]

    Mike O’Neill. 2018. Do Not Track and the GDPR. Retrieved May 15, 2019 from https://www.w3.org/blog/2018/06/do-not-track-and-the-gdpr/ 14

  24. [32]

    Ashwini Rao, Florian Schaub, Norman Sadeh, Alessandro Acquisti, and Ruogo Kang. 2016. Expecting the Unexpected: Understanding Mismatched Privacy Ex- pectations Online. In Twelfth Symposium On Usable Privacy and Security (SOUPS ’16). USENIX Association, 77–96. https://www.useni...

  25. [33]

    Reeder, Adrienne Porter Felt, Sunny Consolvo, Nathan Malkin, Christopher Thompson, and Serge Egelman

    Robert W. Reeder, Adrienne Porter Felt, Sunny Consolvo, Nathan Malkin, Christopher Thompson, and Serge Egelman. 2018. An Experience Sampling Study of User Reactions to Browser Warnings in the Field. In Conference on Human Factors in Computing Systems (CHI ’18) . ACM, New York,...

  26. [34]

    Johnny Ryan. 2017. Research result: what percentage will consent to tracking for... https://pagefair.com/blog/2017/new-research-how-many-consent-to-tracking/

  27. [35]

    Johnny Ryan. 2017. The state of the blocked web – 2017 Global Adblock Report . Technical Report. PageFair. Retrieved May 8, 2019 from https://pagefair.com/ downloads/2017/01/PageFair-2017-Adblock-Report.pdf

  28. [36]

    Johnny Ryan. 2018. French regulator shows deep flaws in IAB’s consent frame- work and RTB. Retrieved May 8, 2019 from https://brave.com/cnil-consent-rtb/

  29. [37]

    cookie wall

    Johnny Ryan. 2019. Formal GDPR complaint against IAB Europe‘s “cookie wall” and GDPR consent guidance. Retrieved May 10, 2019 from https://brave.com/ iab-cookie-wall/

  30. [38]

    Iskander Sanchez-Rola, Matteo Dell’Amico, Platon Kotzias, Davide Balzarotti, Leyla Bilge, Pierre-Antoine Vervier, and Igor Santos. 2019. Can I Opt Out Yet? GDPR and the Global Illusion of Cookie Control. In ACM ASIA Conference on Computer and Communications Security (AsiaCCS ’...

  31. [39]

    Durity, and Lorrie Faith Cranor

    Florian Schaub, Rebecca Balebako, Adam L. Durity, and Lorrie Faith Cranor

  32. [40]

    Mario Silic. 2016. Understanding Colour Impact on Warning Messages: Evidence from US and India. In 2016 CHI Conference Extended Abstracts on Human Factors in Computing Systems (CHI EA ’16) . ACM, New York, NY, USA, 2954–2960. https: //doi.org/10.1145/2851581.2892276

  33. [41]

    Jannick Sørensen and Sokol Kosta. 2019. Before and After GDPR: The Changes in Third Party Presence at Public and Private European Websites. In The 2019 World Wide Web Conference (WWW ’19) . ACM, New York, NY, USA, 1590–1600. https://doi.org/10.1145/3308558.3313524

  34. [42]

    State of California Legislative Counsel. 2018. Assembly Bill No. 375 – Chapter 55

  35. [43]

    Thaler and Cass R

    Richard H. Thaler and Cass R. Sunstein. 2009. Nudge: Improving Decisions About Health, Wealth, and Happiness. Penguin Books, New York, NY, USA

  36. [44]

    The European Parliament and the Council of the European Union. 2002. Direc- tive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector. Official ...

  37. [45]

    The European Parliament and the Council of the European Union. 2009. Directive 2009/136/EC of the European Parliament and of the Council of 25 November 2009 amending Directive 2002/22/EC, Directive 2002/58/EC and Regulation (EC) No 2006/2004. Official Journal of the European U...

  38. [46]

    The European Parliament and the Council of the European Union. 2016. Regula- tion (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such d...

  39. [47]

    Joseph Turow, Michael Hennessy, and Nora Draper. 2018. Persistent Mis- perceptions: Americans’ Misplaced Confidence in Privacy Policies, 2003–2015. Journal of Broadcasting & Electronic Media 62, 3 (July 2018), 461–478. https: //doi.org/10.1080/08838151.2018.1451867

  40. [48]

    Tobias Urban, Martin Degeling, Thorsten Holz, and Norbert Pohlmann. 2019. Perspectives on Transparency Tools for Online Advertising. In 35th Annual Computer Security Applications Conference (ACSAC). ACM, San Juan, 14

  41. [49]

    Rob van Eijk, Hadi Asghari, Philipp Winter, and Arvind Narayanan. 2019. The Impact of User Location on Cookie Notices (Inside and Outside of the European Union). In Workshop on Technology and Consumer Protection (ConPro ’19) . IEEE

  42. [50]

    cookie consent notice

    Markus Weinmann, Christoph Schneider, and Jan vom Brocke. 2016. Digital Nudging. Business & Information Systems Engineering 58, 6 (Dec. 2016), 433–436. https://doi.org/10.1007/s12599-016-0453-1 A TIMING IN EXPERIMENT 2 Table 3: Average time in seconds until users submitted dec...

  43. [2015]

    In Eleventh Symposium On Usable Privacy and Security (SOUPS ’15)

    A Design Space for Effective Privacy Notices. In Eleventh Symposium On Usable Privacy and Security (SOUPS ’15) . The USENIX Association, Ottawa, 1–17. https://doi.org/10.1145/567752.567774

  44. [2018]

    Communication Research 0, 0 (2018), 1–25

    Exploring Motivations for Online Privacy Protection Behavior: Insights From Panel Data. Communication Research 0, 0 (2018), 1–25. https://doi.org/10. 1177/0093650218800915

Pith tools

Reviewed August 14, 2026 · model on record in the stance chip above.