Skip to main content
QUICK REVIEW

[论文解读] The Unwanted Sharing Economy: An Analysis of Cookie Syncing and User Transparency under GDPR

Tobias Urban, Dennis Tatang|arXiv (Cornell University)|Nov 21, 2018
Privacy, Security, and Data Protection参考文献 12被引用 12
一句话总结

本研究分析了《通用数据保护条例》(GDPR)对在线广告的影响,重点关注Cookie同步和用户数据可携性问题。通过对400个浏览器配置文件进行实证测量,作者发现GDPR实施后,第三方Cookie同步连接减少了40%,但底层的星型拓扑网络结构基本保持不变。尽管有法律要求,仍有58%的公司未能在GDPR规定的30天期限内回应数据访问请求,且许多公司设置了不成比例的验证障碍。

ABSTRACT

The European General Data Protection Regulation (GDPR), which went into effect in May 2018, leads to important changes in this area: companies are now required to ask for users' consent before collecting and sharing personal data and by law users now have the right to gain access to the personal information collected about them. In this paper, we study and evaluate the effect of the GDPR on the online advertising ecosystem. In a first step, we measure the impact of the legislation on the connections (regarding cookie syncing) between third-parties and show that the general structure how the entities are arranged is not affected by the GDPR. However, we find that the new regulation has a statistically significant impact on the number of connections, which shrinks by around 40%. Furthermore, we analyze the right to data portability by evaluating the subject access right process of popular companies in this ecosystem and observe differences between the processes implemented by the companies and how they interpret the new legislation. We exercised our right of access under GDPR with 36 companies that had tracked us online. Although 32 companies (89%) we inquired replied within the period defined by law, only 21 (58%) finished the process by the deadline set in the GDPR. Our work has implications regarding the implementation of privacy law as well as what online tracking companies should do to be more compliant with the new regulation.

研究动机与目标

  • 评估GDPR对在线广告生态系统中第三方Cookie同步的影响。
  • 评估主要在线服务在数据可携性和主体访问请求(SAR)权利方面对GDPR的合规情况。
  • 调查公司如何解读并实施有关数据共享和用户透明度的新法律义务。
  • 识别第三方数据共享网络中的结构模式,并评估GDPR下的用户控制能力。

提出的方法

  • 基于在400个浏览器配置文件访问数百个网站过程中观察到的Cookie同步,构建了一个无向图以建模第三方关系。
  • 在GDPR实施前后六个月内收集数据,以测量连接频率和网络结构的变化。
  • 通过向39家公司在GDPR下的访问权行使SAR,记录响应时间、所需验证步骤及提供的数据格式。
  • 分析隐私政策和SAR回复,以评估透明度、数据披露程度以及对GDPR解释标准的合规性。
  • 识别第三方服务中的网络拓扑结构(如星型配置),以理解间接数据共享风险。
  • 比较GDPR下“提供数据”定义的法律解释,区分直接提交的数据与通过跟踪推断的数据。

实验结果

研究问题

  • RQ1GDPR在多大程度上减少了在线广告生态系统中第三方Cookie同步连接的数量?
  • RQ2公司在如何解读和实施GDPR的主体访问请求(SAR)流程方面表现如何?他们对用户设置了哪些障碍?
  • RQ3第三方服务之间的数据共享具有何种结构模式?这些模式如何影响用户数据的透明度和控制权?
  • RQ4公司在披露其第三方数据共享合作伙伴方面的一致性如何?隐私政策与SAR回复中提供的信息有何差异?
  • RQ5公司在SAR响应方面对GDPR规定的30天截止期限的遵守程度如何?

主要发现

  • GDPR导致第三方Cookie同步连接数量显著减少了40%,但整体网络结构——主要为星型拓扑——基本保持不变。
  • 尽管有法律要求,仍有58%的公司未能在GDPR规定的30天时限内完成主体访问请求流程。
  • 许多公司设置了不成比例的验证要求,例如要求提供官方身份证件扫描件或签署的宣誓书,作者认为这些要求不相称。
  • 仅有三家公司在其回复中明确列出了所有与用户数据共享的第三方;其他公司要么列出了数百个合作伙伴,要么完全未披露。
  • 隐私政策通常未能提供足够的数据共享实践细节,削弱了用户透明度和知情同意。
  • 本研究揭示了公司在解读和应用GDPR条款方面存在显著不一致,特别是在数据可携性和‘提供数据’定义方面。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。