Analysis of a Consent Management Specification and Prototype Under the GDPR

被引:0
|
作者
Palm, Jonas [1 ]
Jensen, Meiko [2 ]
机构
[1] Kiel Univ Appl Sci, Kiel, Germany
[2] Karlstad Univ, Karlstad, Sweden
来源
关键词
consent management; usability; requirements elicitation;
D O I
10.1007/978-3-031-47748-5_1
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Consent requests for the processing of personal information are ubiquitous for users of web services across the European Union (EU). However, their form and contents differ greatly, and often include deceptive design patterns (so-called dark patterns) meant to influence users' choices. In this paper, we provide the results of a research project to define a new specification that can be used to handle consent requests based on cookies in a standardized and GDPR-compliant manner. We define and evaluate a set of requirements for consent management systems and we illustrate the advantage of our proposed specification to the state of the art based on a prototype implementation and evaluation. Based on a small usability study, we found our solution to reduce the necessary interactions with respect to consenting, consent withdrawal, and consent configuration by far.
引用
收藏
页码:3 / 17
页数:15
相关论文
共 50 条
  • [31] Cookiescanner: An Automated Tool for Detecting and Evaluating GDPR Consent Notices on Websites
    Gundelach, Ralf
    Herrmann, Dominik
    18TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY & SECURITY, ARES 2023, 2023,
  • [32] JOINT CONTROLLER AGREEMENT UNDER GDPR
    Colcelli, Valentina
    EU AND MEMBER STATES - LEGAL AND ECONOMIC ISSUES, 2019, 3 : 1030 - 1047
  • [33] Human-Induced Errors in Networked Healthcare Research: Risk Management Under the GDPR
    Bienzeisler, Jonas
    Fischer, Hauke
    Thiemann, Volker S.
    Roehrig, Rainer
    DIGITAL PERSONALIZED HEALTH AND MEDICINE, 2020, 270 : 1128 - 1132
  • [34] On Purpose and by Necessity: Compliance Under the GDPR
    Basin, David
    Debois, Soren
    Hildebrandt, Thomas
    FINANCIAL CRYPTOGRAPHY AND DATA SECURITY, FC 2018, 2018, 10957 : 20 - 37
  • [35] Analysis of policy management models and specification languages
    Aib, I
    Agoulmine, N
    Fonseca, MS
    Pujolle, G
    NETWORK CONTROL AND ENGINEERING FOR QOS, SECURITY AND MOBILITY II, 2003, 133 : 26 - 50
  • [36] Designing the GDPR Compliant Consent Procedure for Personal Information Collection in the Iot Environment
    Lee, Goo Yeon
    Cha, Kyung Jin
    Kim, Hwa Jong
    2019 IEEE INTERNATIONAL CONGRESS ON INTERNET OF THINGS (IEEE ICIOT 2019), 2019, : 79 - 81
  • [37] Consumer Consent and Firm Targeting After GDPR: The Case of a Large Telecom Provider
    de Matos, Miguel Godinho
    Adjerid, Idris
    MANAGEMENT SCIENCE, 2022, 68 (05) : 3330 - 3378
  • [38] Teachers in the loop? An analysis of automatic assessment systems under Article 22 GDPR
    Colonna, Liane
    INTERNATIONAL DATA PRIVACY LAW, 2024, 14 (01) : 3 - 18
  • [39] THE FORMAL SPECIFICATION AND PROTOTYPE IMPLEMENTATION OF A SIMPLE EDITOR
    AMOROSO, EG
    SIGPLAN NOTICES, 1985, 20 (08): : 51 - 59
  • [40] Transferring personal data to international organizations under the GDPR: an analysis of the transfer mechanisms
    Marelli, Massimo
    INTERNATIONAL DATA PRIVACY LAW, 2024, 14 (01) : 19 - 36