Analysis of a Consent Management Specification and Prototype Under the GDPR

被引:0
|
作者
Palm, Jonas [1 ]
Jensen, Meiko [2 ]
机构
[1] Kiel Univ Appl Sci, Kiel, Germany
[2] Karlstad Univ, Karlstad, Sweden
来源
关键词
consent management; usability; requirements elicitation;
D O I
10.1007/978-3-031-47748-5_1
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Consent requests for the processing of personal information are ubiquitous for users of web services across the European Union (EU). However, their form and contents differ greatly, and often include deceptive design patterns (so-called dark patterns) meant to influence users' choices. In this paper, we provide the results of a research project to define a new specification that can be used to handle consent requests based on cookies in a standardized and GDPR-compliant manner. We define and evaluate a set of requirements for consent management systems and we illustrate the advantage of our proposed specification to the state of the art based on a prototype implementation and evaluation. Based on a small usability study, we found our solution to reduce the necessary interactions with respect to consenting, consent withdrawal, and consent configuration by far.
引用
收藏
页码:3 / 17
页数:15
相关论文
共 50 条
  • [21] The DMA's Consent Moment and its Relationship with the GDPR
    D'Amico, Alessia S.
    EUROPEAN JOURNAL OF RISK REGULATION, 2024,
  • [22] Towards a Semantic Specification for GDPR Data Breach Reporting
    Pandit, Harshvardhan J.
    Ryan, Paul
    Krog, Georg Philip
    Crane, Martin
    Brennan, Rob
    LEGAL KNOWLEDGE AND INFORMATION SYSTEMS, 2023, 379 : 131 - 136
  • [23] What GDPR and the Health Research Regulations (HRRs) mean for Ireland: “explicit consent”—a legal analysis
    Mary Kirwan
    Blanaid Mee
    Niamh Clarke
    Aoife Tanaka
    Lino Manaloto
    Emma Halpin
    Una Gibbons
    Ann Cullen
    Sarah McGarrigle
    Elisabeth M. Connolly
    Kathleen Bennett
    Eoin Gaffney
    Ciaran Flanagan
    Laura Tier
    Richard Flavin
    Noel G. McElvaney
    Irish Journal of Medical Science (1971 -), 2021, 190 : 515 - 521
  • [24] What GDPR and the Health Research Regulations (HRRs) mean for Ireland: "explicit consent"-a legal analysis
    Kirwan, Mary
    Mee, Blanaid
    Clarke, Niamh
    Tanaka, Aoife
    Manaloto, Lino
    Halpin, Emma
    Gibbons, Una
    Cullen, Ann
    McGarrigle, Sarah
    Connolly, Elisabeth M.
    Bennett, Kathleen
    Gaffney, Eoin
    Flanagan, Ciaran
    Tier, Laura
    Flavin, Richard
    McElvaney, Noel G.
    IRISH JOURNAL OF MEDICAL SCIENCE, 2021, 190 (02) : 515 - 521
  • [25] Is Automated Consent in Solid GDPR-Compliant? An Approach for Obtaining Valid Consent with the Solid Protocol
    Florea, Marcu
    Esteves, Beatriz
    INFORMATION, 2023, 14 (12)
  • [26] GDPR bypass by design? Transient processing of data under the GDPR
    George, Damian
    Reutimann, Kento
    Tamo-Larrieux, Aurelia
    INTERNATIONAL DATA PRIVACY LAW, 2019, 9 (04) : 285 - 298
  • [27] Will EU's GDPR Act as an Effective Enforcer to Gain Consent?
    Oh, Junhyoung
    Hong, Jinhyoung
    Lee, Changsoo
    Lee, Jemin Justin
    Woo, Simon S.
    Lee, Kyungho
    IEEE ACCESS, 2021, 9 : 79477 - 79490
  • [28] Biobank consent under the GDPR: are potential sample donors informed about all lawful uses of biobank data?
    Kaaya, Emmi
    MEDICINE HEALTH CARE AND PHILOSOPHY, 2024, 27 (04) : 567 - 577
  • [29] Connected Cars under the GDPR
    Zallone, Raffaele
    2019 AEIT INTERNATIONAL CONFERENCE OF ELECTRICAL AND ELECTRONIC TECHNOLOGIES FOR AUTOMOTIVE (AEIT AUTOMOTIVE), 2019,
  • [30] Library Management in the Context of the GDPR
    Banciu, Doina
    Mantykangas, Arja
    ELEARNING CHALLENGES AND NEW HORIZONS, VOL 4, 2018, : 372 - 377