Widely-used cookie walls are flouting GDPR rules

Only 12% of third-party consent-seeking banners and notifications meet minimum requirements

The majority of third-party cookie walls used by UK organisations to obtain consent from users contravene strict data protection laws, researchers claim.

Just 11.8% of the content management platforms (CMPs) deployed by UK websites to seek user consent and offer tracking controls meet minimum legal requirements under the General Data Protection Regulation (GDPR).

Advertisement - Article continues below

CMPs, including banners and pop-up windows, are automatically displayed when users visit a website and give a number of options pertaining to consent as well as advanced controls over elements like tracking.

These are designed and distributed by a handful of developers, including Cookiebot, Crownpeak, OneTrust, QuantCast and TrustArc, and used by organisations who prefer this to building their own. Approximately 20% of the top 10,000 UK websites use such a service.

Among the most widely-used CMPs, researchers with Cornell University found that implied consent is universal, as well as dark patterns that guide people into desired behaviour.

“The results of our empirical survey of CMPs today illustrates the extent to which illegal practices prevail, with vendors of CMPs turning a blind eye to - or worse, incentivising - clearly illegal configurations of their systems,” the researchers concluded.

“Enforcement in this area is sorely lacking.

“Designers might help here to design tools for regulators, rather than just for users or for websites. Regulators should also work further upstream and consider placing requirements on the vendors of CMPs to only allow compliant designs to be placed on the market.”

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

Researchers scraped designs of the five most popular consent-seeking interfaces deployed by the top 10,000 websites in the UK, finding that explicit consent was rare.

The extent of the scale of non-compliance is so broad that even the Information Commissioner's Office (ICO) admitted last year that its cookie wall was non-compliant.

To be fully GDPR-compliant, the researchers stated, cookie walls must offer explicit consent that’s clear and positive, and allow users to reject all options just as easy as it is to accept all options. These notifications must also contain no pre-ticked boxes.

Related Resource

Testing for compliance just became easier

How you can use technology to ensure compliance in your organisation

Download now

A further in-depth study conducted with 40 participants, moreover, showed how tweaking CMP designs may significantly change the rates of consent.

Organisations, for example, that remove opt-out buttons from the first page of their cookie walls raised consent levels by 22 to 23%. Inversely, offering more granular controls on the first page decreased consent by 8 to 20%.

Advertisement - Article continues below

The key takeaway from the study, according to those involved, was that placing information or controls before the very first layer is almost pointless given it’s largely ignored by users.

Offering genuine controls, therefore, would require organisations to place everything on the first page of any cookie wall.

Alternatively, the design patterns of consent banners could be overhauled to allow for richer and more durable ways to set privacy settings. These would have to be legally binding, however, rather than self-regulatory.

This is difficult because intense lobbying around the EU’s draft ePrivacy Regulation has predominately involved adtech firms campaigning to prevent browsers from having legally-binding elements.

Mozilla is one example of a developer that’s taken action into its own hands, introducing a set of top-level privacy and anti-tracking controls for its Firefox browser last year. Microsoft’s renewed Edge browser, similarly, is packaged with default anti-tracking and baseline cookie blocking.

  • compliance
  • General Data Protection Regulation (GDPR)
Featured Resources

Top 5 challenges of migrating applications to the cloud

Explore how VMware Cloud on AWS helps to address common cloud migration challenges

Download now

3 reasons why now is the time to rethink your network

Changing requirements call for new solutions

Download now

All-flash buyer’s guide

Tips for evaluating Solid-State Arrays

Download now

Enabling enterprise machine and deep learning with intelligent storage

The power of AI can only be realised through efficient and performant delivery of data

Download now
Advertisement
Advertisement

Most Popular

Visit/security/privacy/355155/zoom-kills-facebook-integration-after-data-transfer-backlash
privacy

Zoom kills Facebook integration after data transfer backlash

30 Mar 2020
Visit/security/data-breaches/355173/marriott-hit-by-data-breach-exposing-personal-data-of-52-million
data breaches

Marriott data breach exposes personal data of 5.2 million guests

31 Mar 2020
Visit/security/cyber-crime/355171/fbi-warns-of-zoom-bombing-hackers-amidst-coronavirus-usage-spike
cyber crime

FBI warns of ‘Zoom-bombing’ hackers amid coronavirus usage spike

31 Mar 2020
Visit/data-insights/data-management/355170/oracle-cloud-courses-are-free-during-coronavirus-lockdown
data management

Oracle cloud courses are free during coronavirus lockdown

31 Mar 2020