About | HeinOnline Law Journal Library | HeinOnline Law Journal Library | HeinOnline



6 J. Cybersecurity 1 (2020)

handle is hein.journals/jnlocybrs6 and id is 1 raw text is: 







CYBEBSECURITY


Research paper


Has the GDPR hype affected users' reaction to

cookie disclaimers?


Oksana Kulyk,I,* Nina Gerber,2 Annika Hilt3 and Melanie Volkamer3

'IT University of Copenhagen, Rued Langgaards Vej 7 DK-2300 Copenhagen S Denmark, 2Technische Universitst
Darmstadt, Germany and 3Karlsruhe Institute of Technology, Germany

*Correspondence address. IT University of Copenhagen, Rued Langgaards Vej 7 DK-2300 Copenhagen S Denmark; E-
mail: okku@itu.dk

Received 20 February 2019; revised 15 October 2020; accepted 6 November 2020


Abstract


For  many  years, cookies have  been  widely used  by websites, storing information  about  users' be-
haviour. While  enabling additional functionality and potentially improving user experience,  cookies
can  be  a threat to  users' privacy, especially  cookies  used  by third  parties for data  analysis.
Websites  providers  are legally required to inform users about cookie  use by displaying  a so-called
cookie disclaimer. We  conducted   a survey study in 2017 to investigate how  users perceive this dis-
claimer  and whether   it affects their actual behaviour. We found  that while most  participants had
negative  feelings towards the disclaimer, the disclaimer text had no significant effect on their deci-
sion to leave the website. Since the extensive media  coverage  of data protection issues that accom-
panied  the EU  General  Data Protection Regulation  (GDPR)  entry into force in May  2018 may   have
sensitized users  to privacy protection, we  conducted   a follow-up  study  in December   2018.  Our
results suggest that users did not change  their attitude towards cookie use in favour of privacy pro-
tection, but got even more  accustomed   to the use of cookies, also by third parties. Moreover, many
users  seem  to  have  misconceptions   regarding  cookie  use. We  discuss  the implications  of our
results for the users' right to make an informed decision about their privacy.


Keywords: cookies; privacy notice; user study; GDPR


Introduction1

Since 1994, cookies have been  commonly  used on  websites.
Originally introduced in order to remember stateful information on
the websites and with this provide better user experience and add-
itional functionality, the usage of cookies has since evolved to in-
clude data collection from the user. Such data collection can
threaten the users' privacy. As the EU Data protection directive [1]
prescribes informing the users regarding the use of cookies on the
website, service providers include a corresponding disclaimer on
their website (see Fig. 1).



1  This is the extended version of the paper This website uses cookies:
   Users' perceptions and reactions to the cookie disclaimer [6], initially
   published at the EuroUSEC workshop

OThe Author(s) 2020. Published by Oxford University Press.


   Yet, research from related domains [2-4] shows that privacy and
security notices are often ineffective in their purpose. As such, they
often fail to provide the necessary information to the users in an
understandable way, in order to enable the users to make an
informed decision. Furthermore, these notices often fail to empower
the user, not providing them with meaningful choices and measures
for protecting their privacy. As the result, users often ignore the noti-
ces not perceiving them as useful, or make decisions based on them
without being aware of the consequences.
   The goal of our work is to study the effect of the cookie disclaim-
er as a privacy notice on users. As such, in order to see whether the
disclaimer succeeds in informing the users and empowering them in


This is an Open Access article distributed under the terms of the Creative Commons Attribution License (http://creativecommons.org/licenses/by/4.0/), which permits unre-
stricted reuse, distribution, and reproduction in any medium, provided the original work is properly cited.


Journal of Cybersecurity, 2020, 1-14
      doi: 10.1093/cybse c/tyaa022
                Research paper