Analysis of a Consent Management Specification and Prototype Under the GDPR

被引:0
|
作者
Palm, Jonas [1 ]
Jensen, Meiko [2 ]
机构
[1] Kiel Univ Appl Sci, Kiel, Germany
[2] Karlstad Univ, Karlstad, Sweden
来源
关键词
consent management; usability; requirements elicitation;
D O I
10.1007/978-3-031-47748-5_1
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Consent requests for the processing of personal information are ubiquitous for users of web services across the European Union (EU). However, their form and contents differ greatly, and often include deceptive design patterns (so-called dark patterns) meant to influence users' choices. In this paper, we provide the results of a research project to define a new specification that can be used to handle consent requests based on cookies in a standardized and GDPR-compliant manner. We define and evaluate a set of requirements for consent management systems and we illustrate the advantage of our proposed specification to the state of the art based on a prototype implementation and evaluation. Based on a small usability study, we found our solution to reduce the necessary interactions with respect to consenting, consent withdrawal, and consent configuration by far.
引用
收藏
页码:3 / 17
页数:15
相关论文
共 50 条
  • [1] Consent Management Platforms Under the GDPR: Processors and/or Controllers?
    Santos, Cristiana
    Nouwens, Midas
    Toth, Michael
    Bielova, Nataliia
    Roca, Vincent
    PRIVACY TECHNOLOGIES AND POLICY, APF 2021, 2021, 12703 : 47 - 69
  • [2] GDPR consent management and automated compliance verification tool
    Chhetri, Tek Raj
    Fensel, Anna
    DeLong, Rance J.
    SOFTWAREX, 2024, 27
  • [3] CONSENT AS A LAWFUL BASIS FOR PROCESSING PERSONAL DATA UNDER THE GDPR
    Limba, T.
    Sidlauskas, A.
    14TH INTERNATIONAL TECHNOLOGY, EDUCATION AND DEVELOPMENT CONFERENCE (INTED2020), 2020, : 1374 - 1383
  • [4] Broad consent under the GDPR: an optimistic perspective on a bright future
    Hallinan, Dara
    LIFE SCIENCES SOCIETY AND POLICY, 2020, 16 (01)
  • [5] The Role of Consent Form Design Under GDPR: A Survey Experiment
    van Erkel, Patrick Folkert Anton
    Hopmann, David Nicolas
    Skovsgaard, Morten
    Terren, Ludovic
    INTERNATIONAL JOURNAL OF PUBLIC OPINION RESEARCH, 2024, 36 (01)
  • [6] SPECIFICATION AND IMPLEMENTATION OF A PROTOTYPE FOR PROJECT MANAGEMENT
    Cezario, S. F.
    de Souza, L. F.
    Costa, G. M.
    de Paiva, F. A. P.
    HOLOS, 2013, 29 (03) : 90 - 99
  • [7] A Smart Contract-Based Dynamic Consent Management System for Personal Data Usage under GDPR
    Merlec, Mpyana Mwamba
    Lee, Youn Kyu
    Hong, Seng-Phil
    In, Hoh Peter
    SENSORS, 2021, 21 (23)
  • [8] Guidelines for GDPR Compliant Consent and Data Management Model in ICT Businesses
    Peras, Dijana
    CENTRAL EUROPEAN CONFERENCE ON INFORMATION AND INTELLIGENT SYSTEMS (CECIIS 2018), 2018, : 113 - 121
  • [9] How to Improve the GDPR Compliance through Consent Management and Access Control
    Daoudagh, Said
    Marchetti, Eda
    Savarino, Vincenzo
    Di Bernardo, Roberto
    Alessi, Marco
    ICISSP: PROCEEDINGS OF THE 7TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2021, : 534 - 541
  • [10] (Un)informed Consent: Studying GDPR Consent Notices in the Field
    Utz, Christine
    Degeling, Martin
    Fahl, Sascha
    Schaub, Florian
    Holz, Thorsten
    PROCEEDINGS OF THE 2019 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (CCS'19), 2019, : 973 - 990