REVIEW 3 major objections 5 minor 52 references
(Un)informed Consent: Studying GDPR Consent Notices in the Field
T0 review · 3 major / 5 minor · reviewed 2026-08-14 · deepseek-v4-flash
Pith's one-line read Seemingly cosmetic choices in cookie consent banners—position, pre-selection, and wording—decisively shape whether users consent, with accept-all rates ranging from under 0.1% to roughly 30%.
desk verdict Good field experiment on consent banners, but the famous 0.1% opt-in figure conflates default setting with click effort; the qualitative results hold up. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing object is a set of consent-notice variants built from eight user-interface variables the authors first catalogued in 1,000 real notices: position, size, blocking, choices, text, nudging, formatting, and links. The experiments manipulate three of these—position; choice type and nudging; wording and privacy-policy link—while holding the rest constant. The mechanism that carries the argument is the comparison of interaction and accept/decline rates between otherwise identical notices, especially the contrast between pre-selected checkboxes (nudging) and unchecked, privacy-by-default checkboxes. That contrast isolates the effect of default framing from everything else about the notice.
What would settle it
Run the same nine-condition experiment on a site with a different audience, such as a desktop-heavy news site, and compare accept-all rates in the opt-in and pre-selected conditions: if the opt-in accept-all share approaches the pre-selected share, or if pre-selection raises acceptance only slightly, then the paper's central claim that design defaults dominate consent would not hold in that context.
Extended reading notes
Core claim
The central claim is that seemingly small implementation decisions in consent-notice interfaces substantially change whether and how visitors consent, and that most current notices are built to manufacture consent rather than record it. In the sharpest result, a privacy-by-default (opt-in) notice led fewer than 0.1% of visitors to allow cookies for all purposes, while pre-selecting all checkboxes led around 30% of mobile and 10% of desktop users to accept all third parties; 1 to 4% of opt-in users still selected some parties. A dialog in the lower-left corner drew interactions from 37.1% of visitors, versus 2.9% for a top bar. More choices made visitors more likely to decline cookies, and highlighting the accept button increased acceptance even when it was the only action. The authors conclude that opt-out banners are unlikely to produce intentional consent and recommend opt-in, category-based notices as the design that matches both GDPR's purpose-specific consent and users' stated preferences.
Load-bearing premise
The behavior of 82,890 visitors to a single German-language e-commerce website—78% on mobile devices and most staying only seconds—represents the broader European internet population closely enough to support the paper's regulatory recommendations.
Editorial extensions
If this is right
- Enforcing the GDPR's data-protection-by-default principle would, on these numbers, cut accept-all consent to below 0.1% on sites like the one studied, a level that current behavioral-advertising business models could not absorb.
- Regulators should specify consent-notice requirements—position, default states, and number of choices—rather than only requiring that consent be asked.
- Category-based opt-in notices would satisfy users' desire for control without the overwhelming detail of vendor lists.
- Websites serious about meaningful consent should place notices where they interrupt reading (lower left on desktop, lower part of the screen on mobile) and avoid pre-selection and highlighted accept buttons.
- The common top-of-screen bar used by about a quarter of sites in the authors' corpus is the least effective at eliciting any choice, which suggests many current notices mainly train users to ignore them.
Reading between the lines
- If the same banner-design elasticity holds across other site types, then 'consent fatigue' is partly an artifact of bad default designs, and browser-level or cross-site consent tools could be built on opt-in defaults rather than repeated banners.
- The study's site drew mostly mobile, short-dwell visitors; a replication on a desktop-heavy news site or a service with user accounts could show larger or smaller nudging effects, so the absolute percentages should be read as site-specific until re-tested.
- A natural extension would test the same variants with users who already run ad blockers; the paper's ad-blocker subsample suggests these users engage less with banners, which may mean their consent decisions are systematically underrepresented in current consent logs.
- Comparing the same consent-banner variants across languages and countries could separate left-to-right reading effects from genuine position preferences, which the current single-language, single-site design cannot do.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper investigates how the user-interface design of GDPR cookie consent notices affects visitor consent behavior. The authors first analyze 1,000 consent notices collected from popular European websites and identify eight design variables. They then report three between-subjects field experiments on a German e-commerce website with 82,890 unique visitors, varying notice position (Experiment 1), choice granularity and nudging via preselection or highlighting (Experiment 2), and wording plus the presence of a privacy-policy link (Experiment 3). The main findings are that bottom-left placement yields the highest interaction, binary notices receive more acceptance than granular category/vendor notices, nudging substantially increases acceptance, and in the opt-in granular conditions fewer than 0.1% of visitors accept every purpose or vendor. The paper concludes that small implementation decisions have large effects and argues that enforcing the GDPR's data-protection-by-default principle would lead to very low active consent to third-party cookies, recommending opt-in category-based notices.
Significance. The study is valuable because it provides large-scale field evidence, with random assignment, on a topic previously studied mostly through surveys or small lab experiments. The external validation against Cookiebot data and the public availability of the materials are notable strengths, as are the rich interaction logs and the follow-up survey responses. If the headline results are interpreted carefully, the paper makes a strong empirical case that seemingly minor design choices in consent notices substantially change consent behavior, which is directly relevant to current regulatory and technical debates about dark patterns and meaningful consent. However, the quantitative headline about 'less than 0.1%' under GDPR-compliant opt-in notices is weakened by a confound between default selection and interaction effort, and the single-site sample limits the policy generalization.
major comments (3)
- [Section 4.3.1 and Section 7] The central quantitative claim conflates the default setting with the required interaction effort. In Experiment 2, the opt-in category and vendor conditions (Categories–Non-Nudging and Vendors–Non-Nudging) began with all checkboxes unchecked and required the visitor to tick each purpose or vendor individually before submitting; no 'Accept all' or 'Select all' control is described in Section 3.3 or in Figure 4. The preselected conditions, by contrast, allowed acceptance with zero additional clicks. Thus the contrast 'less than 0.1% accept all' versus roughly 30% of mobile and 10% of desktop users accepting all third parties simultaneously varies the default and the number of clicks needed to reach 'accept all' (five to six clicks versus none). The timing data in Appendix A, with medians of 7–8 seconds for category/vendor notices versus 4–5 seconds for binary notices, are consistent with an effort effect. Section 7's conclusion that enforcing data-protection-by-default would lead to 'less than 0.1% of users actively consenting to the use of third-party cookies' is therefore warranted only for this specific high-effort granular design, not for opt-in notices generally. The authors should either add an opt-in condition with an 'Accept all' button, reanalyze the existing data to separate the default effect from the effort effect, or substantially qualify the claim.
- [Section 6.2 and Section 4.3.1] The manuscript reports no confidence intervals for the main proportions, even though the headline claims rest on comparisons of very small percentages (e.g., <0.1% versus 0.16% in Table 2). For a proportion near zero with a few thousand observations, the sampling uncertainty is non-negligible, and the paper's own external validation shows differences that are attributed to context but are unquantified. Reporting Wilson or exact binomial confidence intervals for the key 'Accept all' proportions in Figures 4 and 6 and Table 2 would make the strength of the evidence transparent. This is not merely a presentation issue because the regulatory conclusion in Section 7 depends on how precisely the extremely low opt-in rate is estimated.
- [Section 6.2] The paper acknowledges in Section 6.2 that the sample is a German-language e-commerce website whose visitors may not be representative of the general public, and that the sample 'seems more inclined towards rejecting cookies.' Given that the policy recommendations in Sections 6.1 and 7 generalize from this single site, the authors should more explicitly condition their recommendations on this limitation and discuss which findings are likely to be site-specific. The Cookiebot comparison helps, but the Cookiebot notices differ in interaction design (some categories cannot be deselected), so it does not fully resolve external validity. This does not invalidate the qualitative conclusion that design matters, but it does limit the quantitative claims about the absolute level of consent under GDPR-compliant notices.
minor comments (5)
- [Section 3.1] The 30-second automatic replacement of the consent notice with the survey invitation is a notable modification of the browsing experience, but the paper does not discuss whether this auto-replacement could itself affect the measured interaction rates or the interpretation of 'no action' responses. A sentence addressing this would strengthen the methodology.
- [Section 4.3.2] The observation that 'more visitors selected specific vendors than categories' is presented without a statistical test or confidence interval; given the small absolute numbers, a significance test or an explicit statement of the raw counts would help the reader gauge the robustness of this finding.
- [Table 1] In the 'Text: Processor' row, 'third party 2.6 &' should read 'third party 2.6 %'.
- [Abstract and Section 2.1] The phrase 'data protection by default' is used to refer both to the GDPR's Article 25 principle and to an opt-in consent default; a brief clarification of the legal term would prevent conflation of the two concepts.
- [Section 4.2.1] The use of Cramér's V is fine, but the paper should state whether the reported p-values are corrected for multiple comparisons across the many conditions and interactions tested in Experiment 1.
Circularity Check
No significant circularity: the paper's conclusions are empirical field measurements, and its self-citations supply only background taxonomy and prevalence data.
full rationale
The paper's central claims—position, choice complexity, nudging, and wording affect consent behavior—are supported by between-subjects field experiments on 82,890 real visitors, not by derivation from assumed inputs. The sharp quantitative headline that fewer than 0.1% of visitors accept all purposes in opt-in notices while preselection yields roughly 30% (mobile) and 10% (desktop) acceptance is an observed contrast between specific notice variants (Section 4.3.1), not a quantity fitted to or defined by another result. The authors' prior taxonomy (Degeling et al. [12]) is used to describe notice properties and motivate conditions, but the outcome data are newly collected and are externally benchmarked against Cookiebot logs (Section 4.3.3), so the self-citation is not load-bearing. The skeptical concern that the opt-in conditions differed from the nudging conditions in required click effort is a construct-validity or generalizability limitation, not circularity: the paper does not define 'opt-in' as 'high-effort interface' and then predict high-effort behavior from that definition. The paper even acknowledges sample-representativeness limits in Section 6.2. No equation, fitted parameter, or imported uniqueness theorem makes any claimed result equivalent to its inputs by construction.
Assumptions & free parameters
free parameters (1)
- Auto-replacement threshold =
30 seconds
assumptions (4)
- domain assumption The modified Ginger plugin correctly blocks non-necessary cookies before opt-in and logs all interactions as described in Section 3.1.
- domain assumption The set of 5,087 consent notices and the random sample of 1,000 drawn from the authors' previous study [12] is representative of European consent notices.
- domain assumption The GDPR requires 'freely given, specific, informed and unambiguous' consent and enshrines data protection by default.
- standard math Round-robin assignment of notices approximates random assignment for valid between-subjects inference.
Cite this review
Pith. "Pith review of (Un)informed Consent: Studying GDPR Consent Notices in the Field." pith.science (2026). https://pith.science/paper/6RUN76X7
@misc{pith2026190902638,
author = {Pith},
title = {Pith review of: (Un)informed Consent: Studying GDPR Consent Notices in the Field},
year = {2026},
howpublished = {\url{https://pith.science/paper/6RUN76X7}},
note = {Machine review of arXiv:1909.02638}
}
read the original abstract
Since the adoption of the General Data Protection Regulation (GDPR) in May 2018 more than 60 % of popular websites in Europe display cookie consent notices to their visitors. This has quickly led to users becoming fatigued with privacy notifications and contributed to the rise of both browser extensions that block these banners and demands for a solution that bundles consent across multiple websites or in the browser. In this work, we identify common properties of the graphical user interface of consent notices and conduct three experiments with more than 80,000 unique users on a German website to investigate the influence of notice position, type of choice, and content framing on consent. We find that users are more likely to interact with a notice shown in the lower (left) part of the screen. Given a binary choice, more users are willing to accept tracking compared to mechanisms that require them to allow cookie use for each category or company individually. We also show that the wide-spread practice of nudging has a large effect on the choices users make. Our experiments show that seemingly small implementation decisions can substantially impact whether and how people interact with consent notices. Our findings demonstrate the importance for regulation to not just require consent, but also provide clear requirements or guidance for how this consent has to be obtained in order to ensure that users can make free and informed choices.
Figures
Figures from the paper (3 more)
Reference graph
Works this paper leans on
-
[1]
Alessandro Acquisti. 2009. Nudging Privacy: The Behavioral Economics of Personal Information. IEEE Security & Privacy 7, 6 (Dec. 2009), 82–85. https: //doi.org/10.1109/MSP.2009.163
-
[2]
Alessandro Acquisti, Idris Adjerid, Rebecca Hunt Balebako, Laura Brandimarte, Lorrie Faith Cranor, Saranga Komanduri, Pedro Leon, Norman Sadeh, Florian Schaub, Manya Sleeper, Yang Wang, and Shomir Wilson. 2017. Nudges for Privacy and Security: Understanding and Assisting Users’ Choices Online. Comput. Surveys 50, 3 (Aug. 2017). https://doi.org/10.2139/ssr...
-
[3]
Alessandro Acquisti, Laura Brandimarte, and George Loewenstein. 2015. Privacy and human behavior in the age of information. Science 347, 6221 (Jan. 2015), 509–514. https://doi.org/10.1126/science.aaa1465
-
[4]
Alexa Internet, Inc. 2019. The top 500 sites on the Web. https://www.alexa.com/ topsites
work page 2019
-
[5]
Article 29 Data Protection Working Party. 2016. Cookie Sweep Combined Analysis – Report . Technical Report 14/EN WP 229. European Commission, Brussels, Belgium
work page 2016
-
[6]
Article 29 Data Protection Working Party. 2018. Guidelines on consent under Reg- ulation 2016/679. Technical Report 17/EN WP259 rev.01. European Commission
work page 2018
-
[7]
Boerman, Sanne Kruikemeier, and Frederik J
Sophie C. Boerman, Sanne Kruikemeier, and Frederik J. Zuiderveen Borgesius
-
[8]
Matt Burgess. 2018. The tyranny of GDPR popups and the websites failing to adapt. Retrieved April 22, 2019 from https://www.wired.co.uk/article/ gdpr-cookies-eprivacy-regulation-popups
work page 2018
Show all 52 references
-
[9]
Virginio Cantoni, Marco Porta, Stefania Ricotti, and Francesca Zanin. 2013. Ban- ner positioning in the masthead area of online newspapers: an eye tracking study. In 14th International Conference on Computer Systems and Technologies (CompSysTech ’13). ACM, New York, NY, USA, 1...
2013
-
[10]
Forbrukerrådet (Norwegian Consumer Council). 2018. Deceived by Design – How tech companies use dark patterns to discourage us from exercising our rights to privacy. Technical Report. Oslo, Norway
2018
-
[11]
Commission Nationale de l’Informatique et des Libertés (National Commission on Informatics and Liberty). 2018. Décision no MED 2018-042 du 30 octobre 2018 met- tant en demeure la société VECTAURY (Decision No. MED 2018-042 of 30 October 2018 giving notice to the company VECTAU...
2018
-
[12]
Martin Degeling, Christine Utz, Christopher Lentzsch, Henry Hosseini, Florian Schaub, and Thorsten Holz. 2019. We Value Your Privacy ... Now Take Some Cookies: Measuring the GDPR’s Impact on Web Privacy. In 26th Annual Network and Distributed System Security Symposium (NDSS ’1...
2019
-
[13]
Serge Egelman, Lorrie Faith Cranor, and Jason Hong. 2008. You’ve Been Warned: An Empirical Study of the Effectiveness of Web Browser Phishing Warnings. In Conference on Human Factors in Computing Systems (CHI ’08) . ACM, New York, NY, USA, 1065–1074. https://doi.org/10.1145/13...
2008
-
[14]
Interactive Advertising Bureau Europe. 2019. GDPR Trans- parency and Consent Framework. https://iabtechlab.com/standards/ gdpr-transparency-and-consent-framework/. [Online; accessed 2 May 2019]
2019
-
[15]
European Data Protection Board. 2019. Opinion 5/2019 on the interplay between the ePrivacy Directive and the GDPR, in particular regarding the competence, tasks and powers of data protection authorities . Technical Report 5/2019
2019
-
[16]
Reeder, Sunny Consolvo, Somas Thyagaraja, Helen Bettes, Alan ad Harris, and Jeff Grimes
Adrienne Porter Felt, Alex Ainslie, Robert W. Reeder, Sunny Consolvo, Somas Thyagaraja, Helen Bettes, Alan ad Harris, and Jeff Grimes. 2015. Improving SSL Warnings: Comprehension and Adherence. In 33rd Annual ACM Conference on Human Factors in Computing Systems (CHI ’15) . ACM...
2015
-
[17]
Vitaly Friedman. 2019. Privacy UX: Better Cookie Consent Experiences. Retrieved May 7, 2019 from https://www.smashingmagazine.com/2019/04/ privacy-ux-better-cookie-consent-experiences/
2019
-
[18]
Stacia Garlach and Daniel Suthers. 2018. ‘I’m supposed to see that?’ AdChoices Usability in the Mobile Environment. In Hawaii International Conference on System Sciences. University of Hawai‘i at M¯anoa, Honolulu, HI, USA, 3779–3788. https://doi.org/10.24251/hicss.2018.476
2018 doi
-
[19]
Vicki Ha, Kori Inkpen, Farah Al Shaar, and Lina Hdeib. 2006. An Examination of User Perception and Misconception of Internet Cookies. In CHI ’06 Extended Abstracts on Human Factors in Computing Systems (CHI EA ’06) . ACM, New York, NY, USA, 833–838. https://doi.org/10.1145/112...
2006
-
[20]
Hana Habib, Yixin Zou, Aditi Jannu, Neha Sridhar, Chelse Swoopes, Alessandro Acquisti, Lorrie Faith Cranor, Norman Sadeh, and Florian Schaub. 2019. An Empir- ical Analysis of Data Deletion and Opt-Out Choices on 150 Websites. InFifteenth Symposium On Usable Privacy and Securit...
2019
-
[21]
Daniel Kladnik. 2019. I don’t care about cookies 3.0.0. https://www. i-dont-care-about-cookies.eu/. [Online; accessed 2 May 2019]
2019
-
[22]
This Website Uses Cookies
Oksana Kulyk, Annika Hilt, Nina Gerber, and Melanie Volkamer. 2018. “This Website Uses Cookies”: Users’ Perceptions and Reactions to the Cookie Disclaimer. In 3rd European Workshop on Usable Security (EuroUSec 2018) . London, England, 11
2018
-
[23]
Oksana Kulyk, Peter Mayer, Oliver Käfer, and Melanie Volkamer. 2018. A Concept and Evaluation of Usable and Fine-Grained Privacy-Friendly Cookie Settings Interface. In 17th IEEE International Conference On Trust, Security And Privacy In Computing And Communications (TrustCom 2...
2018
-
[24]
Pedro Leon, Blase Ur, Richard Shay, Yang Wang, Rebecca Balebako, and Lorrie Cranor. 2012. Why Johnny can’t opt out: a usability evaluation of tools to limit online behavioral advertising. In Conference on Human Factors in Computing Systems (CHI ’12) . ACM, New York, NY, USA, 5...
2012
-
[25]
White, and Susan Dumais
Chao Liu, Ryen W. White, and Susan Dumais. 2010. Understanding Web Browsing Behaviors Through Weibull Analysis of Dwell Time. In 33rd International ACM SIGIR Conference on Research and Development in Information Retrieval (SIGIR ’10). ACM, New York, NY, USA, 379–386. https://d...
2010
-
[26]
Manafactory. 2019. Ginger – EU Cookie Law. https://wordpress.org/plugins/ ginger/. [Online; accessed 22 August 2019]
2019
-
[27]
Kirsten Martin. 2016. Do Privacy Notices Matter? Comparing the Impact of Violating Formal Privacy Notices and Informal Privacy Norms on Consumer Trust Online. The Journal of Legal Studies 45, S2 (June 2016), S191–S215. https: //doi.org/10.1086/688488
2016 doi
-
[28]
Arunesh Mathur, Gunes Acar, Michael Friedman, Elena Lucherini, Jonathan Mayer, and Marsh Chetty. 2019. Dark Patterns at Scale: Findings from a Crawl of 11K Shopping Websites. (2019). arXiv:1907.07032
2019 arXiv
-
[29]
Mayer and John C
Jonathan R. Mayer and John C. Mitchell. 2012. Third-Party Web Tracking: Policy and Technology. In 2012 IEEE Symposium on Security and Privacy (SP ’12) . IEEE Computer Society, Washington, DC, USA, 413–427. https://doi.org/10.1109/SP. 2012.47
2012 doi
-
[30]
McDonald and Lorrie Faith Cranor
Aleecia M. McDonald and Lorrie Faith Cranor. 2010. Americans’ Attitudes About Internet Behavioral Advertising Practices. In 9th Annual ACM Workshop on Privacy in the Electronic Society (WPES ’10) . ACM, New York, NY, USA, 63–72. https://doi.org/10.1145/1866919.1866929
2010
-
[31]
Mike O’Neill. 2018. Do Not Track and the GDPR. Retrieved May 15, 2019 from https://www.w3.org/blog/2018/06/do-not-track-and-the-gdpr/ 14
2018
-
[32]
Ashwini Rao, Florian Schaub, Norman Sadeh, Alessandro Acquisti, and Ruogo Kang. 2016. Expecting the Unexpected: Understanding Mismatched Privacy Ex- pectations Online. In Twelfth Symposium On Usable Privacy and Security (SOUPS ’16). USENIX Association, 77–96. https://www.useni...
2016
-
[33]
Reeder, Adrienne Porter Felt, Sunny Consolvo, Nathan Malkin, Christopher Thompson, and Serge Egelman
Robert W. Reeder, Adrienne Porter Felt, Sunny Consolvo, Nathan Malkin, Christopher Thompson, and Serge Egelman. 2018. An Experience Sampling Study of User Reactions to Browser Warnings in the Field. In Conference on Human Factors in Computing Systems (CHI ’18) . ACM, New York,...
2018
-
[34]
Johnny Ryan. 2017. Research result: what percentage will consent to tracking for... https://pagefair.com/blog/2017/new-research-how-many-consent-to-tracking/
2017
-
[35]
Johnny Ryan. 2017. The state of the blocked web – 2017 Global Adblock Report . Technical Report. PageFair. Retrieved May 8, 2019 from https://pagefair.com/ downloads/2017/01/PageFair-2017-Adblock-Report.pdf
2017
-
[36]
Johnny Ryan. 2018. French regulator shows deep flaws in IAB’s consent frame- work and RTB. Retrieved May 8, 2019 from https://brave.com/cnil-consent-rtb/
2018
-
[37]
cookie wall
Johnny Ryan. 2019. Formal GDPR complaint against IAB Europe‘s “cookie wall” and GDPR consent guidance. Retrieved May 10, 2019 from https://brave.com/ iab-cookie-wall/
2019
-
[38]
Iskander Sanchez-Rola, Matteo Dell’Amico, Platon Kotzias, Davide Balzarotti, Leyla Bilge, Pierre-Antoine Vervier, and Igor Santos. 2019. Can I Opt Out Yet? GDPR and the Global Illusion of Cookie Control. In ACM ASIA Conference on Computer and Communications Security (AsiaCCS ’...
2019
-
[39]
Durity, and Lorrie Faith Cranor
Florian Schaub, Rebecca Balebako, Adam L. Durity, and Lorrie Faith Cranor
-
[40]
Mario Silic. 2016. Understanding Colour Impact on Warning Messages: Evidence from US and India. In 2016 CHI Conference Extended Abstracts on Human Factors in Computing Systems (CHI EA ’16) . ACM, New York, NY, USA, 2954–2960. https: //doi.org/10.1145/2851581.2892276
2016
-
[41]
Jannick Sørensen and Sokol Kosta. 2019. Before and After GDPR: The Changes in Third Party Presence at Public and Private European Websites. In The 2019 World Wide Web Conference (WWW ’19) . ACM, New York, NY, USA, 1590–1600. https://doi.org/10.1145/3308558.3313524
2019
-
[42]
State of California Legislative Counsel. 2018. Assembly Bill No. 375 – Chapter 55
2018
-
[43]
Thaler and Cass R
Richard H. Thaler and Cass R. Sunstein. 2009. Nudge: Improving Decisions About Health, Wealth, and Happiness. Penguin Books, New York, NY, USA
2009
-
[44]
The European Parliament and the Council of the European Union. 2002. Direc- tive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector. Official ...
2002
-
[45]
The European Parliament and the Council of the European Union. 2009. Directive 2009/136/EC of the European Parliament and of the Council of 25 November 2009 amending Directive 2002/22/EC, Directive 2002/58/EC and Regulation (EC) No 2006/2004. Official Journal of the European U...
2009
-
[46]
The European Parliament and the Council of the European Union. 2016. Regula- tion (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such d...
2016
-
[47]
Joseph Turow, Michael Hennessy, and Nora Draper. 2018. Persistent Mis- perceptions: Americans’ Misplaced Confidence in Privacy Policies, 2003–2015. Journal of Broadcasting & Electronic Media 62, 3 (July 2018), 461–478. https: //doi.org/10.1080/08838151.2018.1451867
2018
-
[48]
Tobias Urban, Martin Degeling, Thorsten Holz, and Norbert Pohlmann. 2019. Perspectives on Transparency Tools for Online Advertising. In 35th Annual Computer Security Applications Conference (ACSAC). ACM, San Juan, 14
2019
-
[49]
Rob van Eijk, Hadi Asghari, Philipp Winter, and Arvind Narayanan. 2019. The Impact of User Location on Cookie Notices (Inside and Outside of the European Union). In Workshop on Technology and Consumer Protection (ConPro ’19) . IEEE
2019
-
[50]
cookie consent notice
Markus Weinmann, Christoph Schneider, and Jan vom Brocke. 2016. Digital Nudging. Business & Information Systems Engineering 58, 6 (Dec. 2016), 433–436. https://doi.org/10.1007/s12599-016-0453-1 A TIMING IN EXPERIMENT 2 Table 3: Average time in seconds until users submitted dec...
2016 doi
-
[2015]
In Eleventh Symposium On Usable Privacy and Security (SOUPS ’15)
A Design Space for Effective Privacy Notices. In Eleventh Symposium On Usable Privacy and Security (SOUPS ’15) . The USENIX Association, Ottawa, 1–17. https://doi.org/10.1145/567752.567774
-
[2018]
Communication Research 0, 0 (2018), 1–25
Exploring Motivations for Online Privacy Protection Behavior: Insights From Panel Data. Communication Research 0, 0 (2018), 1–25. https://doi.org/10. 1177/0093650218800915
2018
Reviewed August 14, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.