[Paper Review] The Impact of User Location on Cookie Notices (Inside and Outside of the European Union)
This study investigates whether website cookie notices vary based on user location or website Top-Level Domain (TLD), using automated detection across 1,500 websites from 18 countries. It finds that TLDs, not user vantage point, primarily determine cookie notice presence and design—except for .com domains, which show significantly higher banner visibility when accessed from within the EU, indicating location-based adaptation in practice.
The web is global, but privacy laws differ by country. Which set of privacy rules do websites follow? We empirically study this question by detecting and analyzing cookie notices in an automated way. We crawl 1,500 European, American, and Canadian websites from each of 18 countries. We detect cookie notices on 40 percent of websites in our sample. We treat the presence or absence of cookie notices, as well as visual differences, as proxies for differences in privacy rules. Using a series of regression models, we find that the website's Top Level Domain explains a substantial portion of the variance in cookie notice metrics, but the user's vantage point does not. This suggests that websites follow one set of privacy rules for all their users. There is one exception to this finding: cookie notices differ when accessing .com domains from inside versus outside of the EU. We highlight ways in which future research could build on our preliminary findings.
Motivation & Objective
- To investigate whether websites modify cookie notices based on the user’s geographic location, particularly in response to differing privacy regulations.
- To assess whether the website’s Top-Level Domain (TLD) is a stronger predictor of cookie notice behavior than the user’s actual vantage point.
- To evaluate the effectiveness of automated detection for cookie notices in measuring global privacy compliance.
- To explore the implications of these findings for future web privacy measurement methodologies and regulatory enforcement.
Proposed method
- Automated web crawling of the top 100 websites from 18 countries (15 EU, plus Canada, Switzerland, and the US) in January 2019.
- Extension of the OpenWPM framework with a cookie banner detection module using the 'I don’t care about cookies' extension’s list of banner elements.
- Application of regression models to analyze the influence of TLD and vantage point on cookie notice metrics (presence, height, word count, links, language).
- Use of the TextBlob library to detect the primary language of cookie notices for cross-country comparison.
- Evaluation of detection accuracy via false positive rate (under 1%) and false negative rate (~20%), with limitations in detecting cookie-walls.
- Comparison of cookie notice characteristics across TLDs and vantage points to isolate regulatory and implementation effects.
Experimental results
Research questions
- RQ1Does the user’s geographic location influence the presence or design of cookie notices on websites?
- RQ2To what extent does a website’s Top-Level Domain (TLD) predict its cookie notice behavior compared to the user’s vantage point?
- RQ3Are there exceptions where websites adapt cookie notices based on user location, particularly for .com domains?
- RQ4How do cookie notice characteristics (e.g., height, number of links, language) vary across different TLDs and regions?
- RQ5What implications do these findings have for the methodology of large-scale web privacy measurement projects?
Key findings
- The website’s Top-Level Domain (TLD) explains a substantial portion of the variance in cookie notice metrics, indicating that websites follow a single set of privacy rules regardless of user location.
- User vantage point does not significantly affect cookie notice presence or design for most TLDs, supporting the hypothesis that websites use TLD as a proxy for regulatory compliance.
- For .com domains, the odds of seeing a cookie banner increase by 102% when accessed from within the EU compared to outside, indicating location-based adaptation.
- Cookie banners on .com domains are significantly more likely to appear when accessed from EU countries, suggesting compliance with GDPR-specific requirements for EU users.
- Tall banners are more common on Belgian and Dutch websites, aligning with stricter national enforcement and guidance from national data protection authorities.
- The number of links on cookie banners has increased since GDPR implementation, possibly reflecting efforts to meet legal requirements for clear consent mechanisms.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.