Source-linked AI summary
We Value Your Privacy ... Now Take Some Cookies: Measuring the GDPR's Impact on Web Privacy
Martin Degeling, Christine Utz, Christopher Lentzsch, Henry Hosseini, Florian Schaub, Thorsten Holz
TL;DR
The paper asks how the GDPR changed privacy transparency and consent practices on European websites. It studies popular sites across EU countries using longitudinal, multilingual analysis with automated and manual methods. The results show more privacy disclosures and cookie notices, but limited explicit consent and persistent technical and usability gaps.
Problem
Evidence on multilingual privacy-policy changes and the use and implementation of cookie-consent notices around GDPR enforcement was limited.
Method
The study analyzed monthly scans of the 500 most popular websites in each of 28 EU member states, combining automated and manual analysis of policies and cookie notices.
Results
The GDPR was associated with greater web transparency, including a 4.9% increase in sites with privacy policies and 62.1% displaying cookie banners, while most sites still used opt-out consent.
Takeaways & Limitations
The GDPR improved website transparency, but few sites offered users actual choice regarding cookie-based tracking and most analyzed consent libraries did not meet GDPR requirements.
Takeaways & Limitations
The country-specific top-site lists fluctuated substantially, with January and May lists sharing an average of only 387 entries, limiting ranking correlations.
Abstract
from arXiv · showhide
The European Union's General Data Protection Regulation (GDPR) went into effect on May 25, 2018. Its privacy regulations apply to any service and company collecting or processing personal data in Europe. Many companies had to adjust their data handling processes, consent forms, and privacy policies to comply with the GDPR's transparency requirements. We monitored this rare event by analyzing the GDPR's impact on popular websites in all 28 member states of the European Union. For each country, we periodically examined its 500 most popular websites - 6,579 in total - for the presence of and updates to their privacy policy. While many websites already had privacy policies, we find that in some countries up to 15.7 % of websites added new privacy policies by May 25, 2018, resulting in 84.5 % of websites having privacy policies. 72.6 % of websites with existing privacy policies updated them close to the date. Most visibly, 62.1 % of websites in Europe now display cookie consent notices, 16 % more than in January 2018. These notices inform users about a site's cookie use and user tracking practices. We categorized all observed cookie consent notices and evaluated 16 common implementations with respect to their technical realization of cookie consent. Our analysis shows that core web security mechanisms such as the same-origin policy pose problems for the implementation of consent according to GDPR rules, and opting out of third-party cookies requires the third party to cooperate. Overall, we conclude that the GDPR is making the web more transparent, but there is still a lack of both functional and usable mechanisms for users to consent to or deny processing of their personal data on the Internet.
I. INTRODUCTION
The GDPR created a rare opportunity to measure how European websites changed privacy disclosures and cookie-consent practices. The study combines longitudinal, multilingual website analysis with manual and automated methods to assess transparency and consent mechanisms.
- Regulatory context: The GDPR applies to services processing European users’ personal data and requires transparent disclosures, lawful processing bases, and mechanisms for individual consent.It can affect companies worldwide when their services are available in Europe.
- Study design: The study tracks the 500 most popular websites in each of 28 EU member states across eleven months and 24 languages.The researchers combined automated and manual methods and retrieved 112,041 privacy policies.
- Consent challenges: The study finds greater transparency, but most sites retained opt-out consent mechanisms and only 37 sites requested explicit consent before setting cookies.Cookie-consent implementations varied substantially in functionality and user-control granularity.
- Observed changes: 62.1% of analyzed websites used cookie banners after the GDPR came into force, compared with 46.1% in January 2018.The banners increasingly offered choices concerning tracking and social-media cookies.
- Observed changes: 4.9 percentage points: the average increase in websites providing privacy policies between January and the end of May 2018.After May, additions slowed to 0.9 percentage points for privacy policies and 1.1 for cookie-consent notices.
- Regulatory context: The GDPR was intended to harmonize divergent national privacy laws and imposes requirements concerning consent, transparency, and data protection by design and default.Its consent framework includes freely given, specific, informed, and unambiguous indications of users’ wishes.
B. Technical Background
Earlier privacy solutions addressed disclosure and tracking preferences through policies, browser mechanisms, and industry tools. However, adoption, usability, and language coverage limited their effectiveness.
- Browser-based mechanisms: P3P enabled browsers to interpret machine-readable privacy policies and negotiate cookie handling according to user preferences.Major browsers no longer support P3P because websites did not adopt it widely.
- Browser-based mechanisms: Do Not Track lets users signal preferences about tracking and behavioral advertising, but many websites do not honor those signals.The mechanism is supported by all major browsers.
- Industry self-regulation: AdChoices provides opt-out information through advertising icons and the WebChoice tool, yet users struggle to identify participating companies and locate the icons.These challenges complicate company-specific control over online behavioral advertising.
- Privacy disclosures: Privacy policies remain the main way websites inform users about data-processing practices, but users rarely read them because they are long and complex.Automated language-processing tools have sought to make key contents more accessible.
- Research gap: Prior privacy-policy research largely focused on English-language policies, while cookie-consent notices and their implementations had received limited detailed study.This motivates broader multilingual and implementation-focused analysis.
III. STUDYING PRIVACY POLICIES
The privacy-policy study combines multilingual automated detection with manual review and annotation. This hybrid design addresses the complexity, language diversity, and inconsistent structure of real websites.
- Automated analysis: The system scans rendered websites for multilingual privacy-policy links, tracking libraries, and cookie-consent notices using automated tools and manual verification.Screenshots supported manual inspection of cookie banners.
- Data collection: The sample consists of monthly scans of the 500 most popular websites in each EU member state, including scans immediately before and after May 25, 2018.The collection produced 12 scans in total.
- Automated analysis: Automated detection searched for privacy-policy phrases in all 24 official EU languages plus four additional EU languages.The phrases were used to identify relevant hyperlinks while limiting false positives.
- Manual validation: Fully automated detection was insufficient because websites used varied layouts, uncommon terminology, language-selection screens, and policies embedded in terms of service.The researchers therefore complemented automated search with manual validation.
- Manual validation: Websites marked Review or No Link Found were manually inspected and annotated by the authors.Manual review also considered terms of service, user agreements, legal disclaimers, registration forms, and related documents.
C. Archival data
The archival-data workflow retrieves historical policy versions, cleans and compares their text, and applies multilingual processing to identify GDPR-related content. Several exclusions and source constraints bound the resulting dataset.
- Archival retrieval: The researchers used the Internet Archive to retrieve earlier versions of policy URLs during the GDPR’s two-year grace period.Historical versions enabled analysis of whether and when policies changed before data collection began.
- Data cleaning: The analysis excluded 72 JavaScript-displayed policies and 163 downloadable PDF or DOC policies because the crawler could not process them correctly.These exclusions occurred after the data-collection problem was discovered.
- Data cleaning: 81,617 policies from 9,461 URLs and 7,812 domains remained in the text-mining dataset after cleaning.Duplicate policies and other unusable records were removed during data preparation.
- Policy comparison: Policy versions were compared using a sentence-level Jaccard similarity index based on lists of hashed sentences.Comparisons focused on versions from the same domain and URL, including monthly and longer-interval comparisons.
- Multilingual text analysis: Multilingual GDPR-term analysis used translated Article 6 and 13 word lists, language detection, lemmatization, stemming, named-entity recognition, and regular expressions.Native speakers validated lists for 17 of the 24 languages, and 1.7% of texts were excluded when language libraries disagreed.
E. Limitations
The study’s measurements are constrained by fluctuating country rankings, exclusions, and limited keyword-based insight into GDPR compliance.
- Ranking bias and fluctuation: Country top lists fluctuated substantially, with only 387 entries shared on average between January and May.The authors therefore avoided correlating rankings with measured factors, except consent-notice library use.
- Data exclusions: Offline or browser-blocked websites were excluded from the analysis.The authors note that legal compliance obligations do not depend on inclusion in popularity rankings.
- Text-analysis limitation: Keyword analysis provides limited evidence of GDPR compliance because policies need not use the selected translated terms.The authors also note that intelligible policies could potentially use less legal jargon, although they observed no such evidence.
- Sampling scope: The pre-post analysis used domains present in the January top list, while cookie-consent analysis used an expanded May list.The two analyses consequently rely on different domain populations.
A. Privacy Policies
Privacy-policy availability increased after GDPR enforcement, while adoption and updating patterns varied across countries, domains, and website categories.
- Policy adoption: 84.5% of websites had privacy policies after May 25, up from 79.6% in January 2018.The comparison excluded sites offline during at least one crawl.
- Country and domain differences: 10.2% of websites in Latvia’s top-500 list added privacy policies, while Latvian .lv domains increased by 27%.Countries with lower initial policy prevalence generally added more policies than countries where policies were already common.
- Category differences: 4.9% of websites added privacy policies overall, with the biggest impact on categories associated with sensitive information or children.These included health, sports, Kids & Teens, and Education websites.
- Policy content: Privacy-policy text length rose from 2,145 words in March 2016 to 3,603 words in late May 2018.The authors describe tension between concise, readable notices and additional disclosure requirements.
3) GDPR compliance issues:
GDPR-era transparency mechanisms expanded, but privacy-policy gaps, unchanged tracking practices, and uneven cookie-consent functionality remained.
- GDPR compliance issues: More than 24% of top-listed sites in Lithuania, Latvia, and Estonia still had no privacy policy.The study also found 73 sites displaying cookie consent without a privacy policy, down from 161 in January.
- GDPR-related disclosures: 9% more policies included email addresses and data protection officer references between January and May.Use of GDPR-related keywords increased across the multilingual policy set, although those terms were not required.
- Tracking and cookies: Tracking-service use showed no significant change, with websites averaging 3.5 third-party tracking services in January.However, 146 sites stopped using ad or tracking services, and 37 did not track before explicit consent.
- Tracking and cookies: First-party cookies decreased from 22.2 to 17.9 on average, while third-party cookies remained about 5.4.The median stayed unchanged for both cookie groups.
- HTTPS: HTTPS-by-default adoption rose from 59.9% in December 2017 to 80.2% in November 2018.At the end of May, 70.8% of websites redirected to HTTPS.
- Cookie-consent mechanisms: Cookie-consent notices were categorized by interaction options, including no option, confirmation, binary, slider, checkbox, vendor, and other.The study manually inspected notices and grouped them according to available choices.
A. Analysis of Cookie Consent Libraries
The study identified cookie consent libraries and tested their interfaces, cookie effects, geolocation behavior, prevalence, and user exposure. It also examined technical setup limitations that could affect observed website behavior and language.
- Library evaluation: The researchers implemented identified consent libraries on a live WordPress site and observed cookie changes after interacting with each interface.Testing used Microsoft Edge with cookies unblocked and the Developer Console to inspect cookies stored on the machine.
- Library evaluation: Geolocation features were tested with Tor Browser circuits exiting in countries where configured cookie banners should not appear.
- Library prevalence: Library popularity was measured by scanning domains’ home pages in July and December 2018 and checking library resource locations and third-party requests.
- Library prevalence: Exposure was scored from Alexa rankings, favoring libraries used by domains highly ranked across many EU top lists.The score inherits bias from Alexa’s top list and assigns rank 501 to sites no longer present.
- Limitations: Automated-browser detection and server or browser language settings could affect observed behavior and the language presented by websites.Manual visits were used to check effects such as Cloudflare blocking and CAPTCHA challenges.
VI. EVALUATION OF COOKIE CONSENT NOTICES
Cookie consent notices became substantially more common after the GDPR, but implementations varied in interface, functionality, and technical ability to enforce user choices. Existing libraries often lacked granular controls, consent withdrawal, or reliable handling of third-party cookies.
- Adoption: 62.1% of analyzed websites displayed cookie consent notices at the end of May 2018, up from 46.1% in January and reaching 63.2% in October.
- Adoption: +20.2 to +45.4 percentage points measured the country-level increase in cookie-banner prevalence between January and May 2018.Slovenia had the smallest increase and Italy the largest; TLD adoption rose from 50.3% to 69.9%.
- Adoption: Cookie-notice types differed across countries: checkbox interfaces were prominent in France and Slovenia, while Poland had the most no-option notices.
- Cookie Banner Libraries: 31 cookie consent libraries were identified, but only 15.4% of websites displaying notices used one of them in July 2018.The in-depth analysis covered 28 libraries after excluding two unavailable in English and one discontinued WordPress plugin.
- Cookie Banner Libraries: Libraries varied in functionality, especially in the granularity of user control and their ability to apply the selected cookie configuration.The evaluation considered hosting source, consent-management mechanism, interface form, and available options.
- Technical Realization: Meaningful consent requires blocking or deleting cookies, yet opt-out is difficult because libraries must delete existing cookies and third parties may not provide opt-out APIs.The same-origin policy also restricts control over third-party cookies.
- Technical Realization: Implied or forced consent is easy to implement, whereas multi-option consent requires cookie setting and reading to depend on user choices.
- Technical Realization: IAB-based notices could expose unusable vendor lists: only two of 24 sampled sites customized their participating-vendor lists.The framework may list vendors not used by the site, while other third parties can remain outside the consent decision.
VII. DISCUSSION AND FUTURE WORK
The GDPR prompted website changes that improved web-privacy transparency, but the paper finds that harmonization across Europe had not yet been achieved. The authors discuss resulting challenges, opportunities, and study limitations.
- GDPR-era website changes were considered improvements for web privacy, but the goal of harmonization was not yet met.
- The study frames its findings as raising challenges and opportunities for researchers, policymakers, and companies.
- The paper states that it also discusses limitations of the study.
A. Impact of the GDPR
The GDPR increased privacy-policy adoption and references to GDPR-specific terms across Europe, but compliance practices and cookie-consent implementation remain uneven. The study also identifies unresolved legal uncertainty and warns that visible transparency does not establish legal compliance.
- A. Impact of the GDPR: 53% of U.S. top websites and 48% of Russian top websites also appear in at least one EU state’s top-500 list, extending the GDPR’s practical reach beyond the EU.The regulation also affects non-EU services that offer services in the EU.
- A. Impact of the GDPR: Privacy-policy adoption increased across Europe, and GDPR-specific terms became more prevalent, suggesting possible movement toward harmonized practices.The authors caution that actions taken to comply vary greatly, especially for consent and cookies.
- A. Impact of the GDPR: Cookie-consent implementation varies substantially, creating a need for clearer guidance on which cookies require consent and which may rely on legitimate interest.The paper highlights unresolved questions about analytics and user tracking.
- A. Impact of the GDPR: 15.5% of websites still lacked a privacy policy and 14.9% had not updated one in recent years, despite widespread policy adoption.The authors warn that uncertainty may produce a false sense of compliance, and that merely displaying an informative banner may not obtain consent.
- A. Impact of the GDPR: A privacy policy’s presence does not establish compliance with privacy law, and its actual legal adequacy remains an open research question.The paper calls for multilingual research and work connecting legal and technical privacy mechanisms.
A. Adoption of Privacy Policies
Prior research largely examined privacy-policy content in English and gave limited attention to cookie-consent use and implementation. This study addresses those gaps by examining multilingual websites and finds that transparency increased while usable consent mechanisms remain limited.
- A. Adoption of Privacy Policies: Privacy-policy research has examined user perception, disclosure, presentation, and automated assessment, while most approaches remain focused on English-language documents.Only a small number of studies evaluated multiple languages.
- A. Adoption of Privacy Policies: Cookie-consent notices and their implementations had received relatively little detailed research compared with privacy policies.Earlier work included a 2015 manual sweep of 437 sites in eight EU member states.
- A. Adoption of Privacy Policies: The study analyzes privacy policies in 24 languages and reports increased privacy-policy adoption and cookie banners around GDPR enforcement.The authors describe these changes as positive effects on web privacy, while noting that most users still lack actual choice regarding cookie-based tracking.
- A. Adoption of Privacy Policies: Most analyzed cookie-consent libraries did not meet GDPR requirements, and browser-industry disagreement over standards such as Do Not Track adds burden to users.Notifications may satisfy transparency requirements without helping users make informed privacy decisions.
X. APPENDIX
The appendix contains tables listing country codes and GDPR phrase lists.
- X. APPENDIX: Table V is identified as a list of countries and codes.
- X. APPENDIX: The appendix includes three tables titled as lists of GDPR phrases.These are Tables VI, VII, and VIII.