[论文解读] Opted Out, Yet Tracked: Are Regulations Enough to Protect Your Privacy?
本文提出了一种自动化审计框架,利用广告商的出价行为作为侧信道,检测其在GDPR和CCPA下的同意 opt-out 机制是否合规。尽管用户通过Consent Management Platforms(CMPs)如OneTrust和CookieBot选择退出,研究发现广告商仍会处理和共享用户数据,部分CMPs表现明显优于其他,而自有的退出机制如NAI的也未能有效阻止数据处理。
Data protection regulations, such as GDPR and CCPA, require websites and embedded third-parties, especially advertisers, to seek user consent before they can collect and process user data. Only when the users opt in, can these entities collect, process, and share user data. Websites typically incorporate Consent Management Platforms (CMPs), such as OneTrust and CookieBot, to solicit and convey user consent to the embedded advertisers, with the expectation that the consent will be respected. However, neither the websites nor the regulators currently have any mechanism to audit advertisers' compliance with the user consent, i.e., to determine if advertisers indeed do not collect, process, and share user data when the user opts out. In this paper, we propose an auditing framework that leverages advertisers' bidding behavior to empirically assess the violations of data protection regulations. Using our framework, we conduct a measurement study to evaluate four of the most widely deployed CMPs, i.e., Didomi, Quantcast, OneTrust, and CookieBot, as well as advertiser-offered opt-out controls, i.e., National Advertising Initiative's opt-out, under GDPR and CCPA. Our results indicate that in many cases user data is unfortunately still being collected, processed, and shared even when users opt-out. We also find that some CMPs are better than the others at conveying user consent and that several ad platforms ignore user consent. Our results also indicate that advertiser-offered opt-out are equally ineffective at protecting user privacy.
研究动机与目标
- 解决当前缺乏可扩展机制来审计广告商是否遵守GDPR和CCPA下用户选择退出的机制。
- 评估主要Consent Management Platforms(CMPs)在将用户同意传达给第三方广告商方面的有效性。
- 调查广告商提供的退出机制(如NAI的中心化退出)是否能有效阻止数据处理和共享。
- 开发并验证一种自动化框架,利用受控的A/B实验和出价行为,检测监管违规行为。
- 证明即使技术上已传达同意,用户选择退出也无法可靠地阻止跟踪行为。
提出的方法
- 扩展OpenWPM以自动化模拟用户行为,包括通过CMPs进行程序化同意和退出。
- 通过向网站泄露用户兴趣数据,开展受控的A/B实验,并测量广告商出价行为的变化。
- 基于假设:更高的出价表明广告商已事先掌握用户数据,暗示存在数据处理或共享行为。
- 使用Amazon EC2从地理上多样的位置(德国和加州)模拟用户访问,以复现真实世界条件。
- 从广告交易所收集并分析出价数据,推断广告商是否在用户选择退出后仍处理或共享用户数据。
- 在352个网站上重复测量8次,以减少抽样偏差并提高结果可靠性。
实验结果
研究问题
- RQ1在用户通过CMPs选择退出后,广告商在GDPR和CCPA下在多大程度上仍继续处理和共享用户数据?
- RQ2主要CMPs(Didomi、Quantcast、OneTrust和CookieBot)在确保广告商尊重用户退出选择方面有多有效?
- RQ3广告商提供的自有的退出机制(如NAI的中心化退出)是否能有效阻止广告商的数据处理和共享行为?
- RQ4广告商的出价行为能否作为检测数据保护法规不合规行为的可靠侧信道信号?
- RQ5不同CMP实现方式对现实广告生态系统中用户同意实际执行的影响如何?
主要发现
- 尽管用户通过CMPs选择退出,广告商仍会处理和共享用户数据,表现为对泄露用户兴趣的响应中出价行为未变或上升。
- 当通过Didomi传达同意时,广告商在CCPA下的出价行为显著改变,表明其合规性优于其他CMPs。
- OneTrust和CookieBot在执行用户退出选择方面表现较弱,广告商在用户选择退出后仍基于用户数据出价。
- Quantcast表现出中等有效性,但并非所有退出信号都被广告商尊重。
- 广告商提供的退出机制(如NAI的中心化退出)与其它机制一样无效,无法阻止数据处理和共享。
- 本研究证实,当前监管机制不足以保护用户隐私,因为若无主动审计,无法验证合规性。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。