Source-linked AI summary
Dark Patterns after the GDPR: Scraping Consent Pop-ups and Demonstrating their Influence
Midas Nouwens, Ilaria Liccardi, Michael Veale, David Karger, Lalana Kagal
TL;DR
The paper investigates whether prevalent GDPR-era CMP designs produce legally meaningful consent and how those designs affect users’ choices. It combines a survey of CMP implementations on 10,000 UK websites with a 40-participant interface experiment, finding widespread problematic practices and that controls below the first layer are effectively ignored. The authors argue that enforcement focused on centralized third-party CMP services could improve compliance.
Problem
The paper addresses limited evidence about the prevalence, legal quality, and behavioral effects of CMP consent designs after the GDPR.
Method
The study scrapes five prevalent CMPs across the top 10,000 UK websites and runs a controlled experiment with 40 participants using eight interfaces.
Results
Only 11.8% of surveyed sites met the study’s minimal compliance requirements, while user-study interactions overwhelmingly remained on the first page and lower-layer controls were effectively ignored.
Takeaways & Limitations
The findings support regulatory attention to centralized third-party CMP services and to presenting meaningful information and controls on the first layer.
Takeaways & Limitations
The survey may contain false positives or negatives because dynamically rendered and customized CMP implementations can evade automated detection, and the experiment used US participants despite its EU policy focus.
Abstract
from arXiv · showhide
New consent management platforms (CMPs) have been introduced to the web to conform with the EU's General Data Protection Regulation, particularly its requirements for consent when companies collect and process users' personal data. This work analyses how the most prevalent CMP designs affect people's consent choices. We scraped the designs of the five most popular CMPs on the top 10,000 websites in the UK (n=680). We found that dark patterns and implied consent are ubiquitous; only 11.8% meet the minimal requirements that we set based on European law. Second, we conducted a field experiment with 40 participants to investigate how the eight most common designs affect consent choices. We found that notification style (banner or barrier) has no effect; removing the opt-out button from the first page increases consent by 22--23 percentage points; and providing more granular controls on the first page decreases consent by 8--20 percentage points. This study provides an empirical basis for the necessary regulatory action to enforce the GDPR, in particular the possibility of focusing on the centralised, third-party CMP services as an effective way to increase compliance.
INTRODUCTION
The paper examines how post-GDPR consent interfaces and CMP practices shape legally meaningful consent on the web. It surveys prevalent CMP designs and investigates how interface design affects users’ consent actions.
- GDPR-era European law raised standards for consent quality, emphasizing that consent must be freely given, informed, and affirmative.
- CMPs are often third-party services that help websites establish a lawful basis for browser storage and personal-data processing.
- The paper asks what CMP interface designs prevail in the EU and how frequently they contain non-compliant elements.
- The study surveys five common third-party CMPs across the top 10,000 UK websites and evaluates their implementations against European law and guidance.The survey covered n=680 sites.
- A controlled experiment with 40 participants tests how eight consent interfaces affect users’ consent responses.A browser plugin injected the interfaces into web pages.
Freely given and unambiguous consent
European consent must be explicit, freely given, and equally easy to refuse or withdraw. Interface choices such as pre-ticked boxes, unequal buttons, and consent walls can therefore undermine legal validity.
- Implicit or opt-out consent is invalid because continuing to use a website is not a clear positive action.
- Pre-ticked boxes are explicitly identified as invalid consent under the GDPR.
- Consent mechanisms that emphasize agreement over rejection, or hide rejection behind additional navigation, are non-compliant.
- Withdrawal must be as easy as giving consent and must not reduce service levels or otherwise disadvantage the user.
- The legality of cookie walls remains unclear, despite several regulators indicating that they may be illegal.
- An accept-all option is compliant only when users can also consent separately to each specific processing purpose.
Efficient and timely data protection
Data protection requires consent before non-essential processing and meaningful information about the purposes and organisations involved. The paper situates these requirements within longstanding usability problems of notice-and-consent interfaces.
- Cookies and other browser storage for non-essential features require clear information and opt-in consent before processing.
- Fresh consent is required when a new third party sets new non-essential cookies.
- Notice-and-consent interfaces have long faced usability problems that make meaningful privacy decisions difficult.
- The paper focuses on the legal quality of collected consent rather than primarily on how interfaces support informed decisions.
Dark patterns
The paper connects dark patterns in CMPs with widespread consent practices whose legal and practical validity is contested. Prior studies and the paper’s survey show that problematic configurations and consent signals remain common.
- Dark patterns are interaction flows designed to guide users toward desired behavior through manipulative design.
- GDPR guidance identifies privacy-intrusive defaults, hidden privacy-friendly choices, and unequal effort as non-compliant examples.
- Prior research found dark patterns in at least 57.4% of sampled CMPs and no consent choice or confirmation-only designs in 95.8%.
- Another study detected consent signals before user choice on 12.3% of 1,426 sites and at least one consent-related violation on 54% of 560 reviewed sites.
- The paper’s CMP survey finds that interface design varies substantially even among sites using the same major vendor.
- CMPs commonly detect prior preferences, display notices when needed, record responses, and pass consent status to advertising and bidding systems.
- CMP interfaces generally use a first page for broad choices, a second page for purposes, and a third page for vendor details.
Method
The study scraped five prevalent third-party CMPs across 10,000 UK websites and evaluated their designs against three measurable minimum conditions derived from European law. It found widespread implicit consent, unequal rejection controls, pre-ticked options, extensive vendor disclosures, and low minimum compliance.
- Data collection: The scraper recorded CMP vendors, notification styles, consent types, consent-triggering actions, accept/reject controls, and other interface elements.It combined DOM and globally scoped-object queries with JavaScript rendering and database storage.
- Compliance assessment: The assessment did not examine qualitative information adequacy or visual features such as button colour, size, and prominence beyond click requirements.These unexamined factors could also contribute to non-compliance.
- Data collection: 680 CMP instances were captured from the top 10,000 UK websites, representing 57.09% of the estimated population using the five targeted CMPs.The scraper operated over three days in September 2019 and targeted third-party CMP services accounting for approximately 58% of market share.
- Observed designs: 32.5% of sites used implicit consent, including consent inferred from visiting, navigating, refreshing, scrolling, clicking, or closing the notice.Implicit consent was found almost exclusively in banner-style implementations, while explicit-consent CMPs were roughly split between banners and barriers.
- Observed designs: 50.1% of sites lacked a reject-all button, and only 12.6% made rejecting all tracking as accessible as accepting it.Where present, 74.3% of reject-all buttons required two clicks, while accept-all was never buried beyond the first page.
- Observed designs: 56.2% of sites pre-ticked optional vendors or purposes/categories, including 54.1% pre-ticking optional purposes and 32.3% optional categories.The scraper measured visual status and therefore could not verify the functional effect of toggling these settings.
- Observed designs: Among sites listing vendors, the median was 315 vendors and descriptions averaged 7985 words, or roughly 31.9 minutes of reading.85.4% of sites listed vendors, and the reported reading estimate excludes interaction time and linked privacy-policy review.
- Compliance assessment: Only 11.8% of sites met all three minimum conditions: explicit consent, equally easy acceptance and rejection, and no pre-ticked optional choices.These conditions provide a measurable minimum hurdle, not a guarantee of full legal compliance; additional qualitative aspects were not assessed.
Interim Discussion
The authors argue that the low observed compliance warrants regulatory attention, while noting that the measured 11.8% is only a maximum estimate because harder-to-assess legal requirements were excluded.
- Regulatory implications: 11.8% is described as an extraordinarily low compliance rate for seemingly market-leading CMP vendors, suggesting an urgent role for data protection authorities.The authors note that non-compliance could reflect site configuration, vendor encouragement, or outdated CMP implementations.
- Scope of the estimate: The 11.8% compliance figure is a maximum value that is likely to decrease when additional qualitative legal requirements are assessed.The paper specifically points to further scrutiny of scraped text content and aspects of the law that are difficult to evaluate formulaically.
Limitations
The study’s scraper-based dataset may contain false negatives or false positives because dynamically rendered and customized CMP implementations are difficult to identify reliably.
- The authors cannot guarantee that the scraper dataset contains no false negatives or false positives.Manual validation was performed, but dynamic rendering complicates determining whether the scraped DOM state is final.
- CMP customization, legacy code branches, and deliberate anti-automation changes could cause implementations to evade automated identification.The scraper used hardcoded waiting times and workarounds, but exceptions and missed branches remained possible.
- The field experiments examined whether interface designs affect participants’ consent responses using eight notification interfaces.The experiments covered banner and barrier notifications, button prominence, and consent granularity.
Method
The study combined a controlled browser-based experiment with eight consent interfaces and a participant sample of 40 people. The interfaces varied notification style, bulk-button availability, and first-page consent granularity.
- 40 participants completed two counter-balanced experiments evaluating 8 different consent interfaces.The experiments used within-subjects Latin square designs.
- Experiment 1 varied notification style between barrier and banner and bulk buttons between Accept all + Reject all and Accept all.The primary outcome was the consent answer, including accepting, rejecting, submitting defaults, or submitting personalized choices.
- Experiment 2 varied first-page consent granularity across Bulk, Bulk + Purposes, Bulk + Vendors, and Bulk + Purposes + Vendors.Consent answer was again the primary dependent variable.
- Participants were recruited through an author’s personal network and a university mailing list, receiving $50 for completion and $10 for successful referrals.The sample included people residing in the United States during the study.
- The materials comprised pre-study and post-study surveys plus a browser extension that injected the experimental pop-ups.The pre-study survey collected demographics, eligibility information, and informed consent.
- The extension’s eight conditions were modeled on designs from the five CMPs used in the scraper study.Their text, purposes, and vendor names synthesized or reproduced elements found on websites and CMP configurations.
Procedure
Participants encountered the experimental pop-ups during ordinary browsing, with each interface repeated four times and interactions recorded. The procedure linked extension installations to participant records and excluded eight participants whose answers were reportedly study-affected.
- The extension was installed through the Chrome Web Store and linked each installation to an assigned participant number.Participants first completed a pre-study survey before receiving the extension link.
- Each participant encountered a pop-up every fourth URL visited, excluding redirects and URLs with previously recorded answers.Each interface condition was repeated four times, requiring 16 responses per experiment.
- All interactions with the pop-ups were recorded and timestamped during the experiments.The procedure captured participant actions such as clicking and toggling controls.
- The experiment took between four days and three weeks to complete, depending on participants’ browsing patterns and circumstances.Variation reflected factors such as repeated visits to the same websites, holidays, and secondary-device use.
- Eight of the original 48 completers were removed after reporting that the study affected their answers.The remaining responses were analyzed using fixed-effects linear regression with participants treated as a factor.
- Figure 3 presents the eight interface conditions used in the experiments.The conditions combine banner or barrier notifications with different button and consent-granularity arrangements.
Results
Participants usually used bulk choices and interacted only with the first pop-up page. Banner versus barrier style did not change consent rates, while removing Reject all substantially increased acceptance.
- 89.3% of responses used bulk options, including 55.2% Accept all and 34.1% Reject all.Only 9.7% submitted preferences, and 0.9% produced no answer.
- 93.1% of interactions were limited to the pop-up’s first page.Participants clicked the more-options link only 88 times, or 6.9% of opportunities.
- 68.6% of occasions involving scrollable purpose or vendor lists were ignored.When participants did scroll, 64.2% of instances covered 75–100% of the list.
- Notification style: Notification style did not affect participants’ consent rates.The barrier-versus-banner comparisons found no significant relationship, including p = 1 for the Accept + Reject comparison and p = 0.702 for the Accept-only comparison.
- Notification style: Banner notifications were ignored 3.6 times more often than barriers.Among 133 ignored pop-ups, 78.9% were banners and 21.1% were barriers.
- Button prominence: Only 12.6% of sites displayed Accept all and Reject all with equal prominence on the same page.The paper describes unequal prominence as non-compliant with the GDPR because it is expected to affect consent answers.
- Button prominence: Removing Reject all from the first page increased consent probability by 22–23 percentage points.The estimated increases were 22.0 percentage points for barriers and 23.1 percentage points for banners.
Level of granularity
Placing more granular consent choices on the first page reduced consent, while participants’ reported choices often diverged from their ideal privacy preferences. The experiment also had important confounds and limited generalisability because it was conducted with a nonrepresentative US sample.
- Level of granularity: Bulk consent was typically presented first, with purposes and vendors disclosed on later pages or combined on a subsequent page.
- Level of granularity: 8–20 percentage points: more granular first-page consent choices reduced the probability of consent.Compared with bulk-only controls, bulk plus vendors produced the largest reduction (−0.200), followed by bulk plus purposes (−0.088) and bulk plus purposes plus vendors (−0.119).
- Participant Strategies and Behaviour Patterns: Participants’ actual consent behaviour frequently failed to match their ideal privacy settings.Only participants in the always-accept and always-reject categories uniformly agreed that their answers matched their ideals.
- Participant Strategies and Behaviour Patterns: Interface demands were the most commonly cited reason for differences between participants’ behaviour and ideal preferences.Other explanations included wanting more privacy, fearing that opting out could break websites, and not knowing their ideal preferences.
- Participant Strategies and Behaviour Patterns: The findings had several potential confounds, including uncontrolled order effects, unequal exposure to conditions, and simultaneous real pop-ups.
- Participant Strategies and Behaviour Patterns: The experiment’s US setting may limit generalisation to European users because participants encountered different legal regimes and consent controls.The sample was also almost entirely young and university-educated, recruited primarily through a computer science department mailing list.
DISCUSSION AND CONCLUSION
The paper argues that widespread noncompliant CMP practices warrant stronger enforcement and upstream oversight of third-party CMP vendors. It also identifies first-layer visibility and durable browser-based preferences as important directions for genuine user control.
- DISCUSSION AND CONCLUSION: Automated tools could help data protection authorities discover and enforce illegal CMP configurations more efficiently.The paper suggests focusing regulatory requirements upstream on CMP vendors and designing tools for regulators.
- DISCUSSION AND CONCLUSION: The survey’s empirical data alone is insufficient to establish legal compliance.
- DISCUSSION AND CONCLUSION: Controls or information placed below the first layer are effectively ignored, weakening genuine control over online tracking.
- DISCUSSION AND CONCLUSION: Consent may need a compact, representative, and rich first-layer description to remain valid under the notice-and-consent model.The paper presents this as a possible direction for future Court of Justice interpretation.
- DISCUSSION AND CONCLUSION: Richer, more durable preference mechanisms, potentially within browsers, are proposed as an alternative to consent banners or barriers.The paper argues that such browser settings should have legally binding rather than weak self-regulatory effect.