A history of GDPR cookie banner compliance: the roles of publishers, regulators and CMPs
This paper analyzes the historical evolution of GDPR cookie banner compliance across 11,364 websites, revealing a significant increase in "reject all" options driven primarily by publisher actions and regulatory pressure, while highlighting the need for unified EU guidance and oversight of Consent Management Platforms to further enhance user privacy.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Imagine the internet as a giant, bustling marketplace. In 2018, a new set of rules called the GDPR was introduced to protect shoppers (users) from being tracked without their permission. The main tool used to enforce these rules is the Cookie Banner—that pop-up box you see on almost every website asking, "Do you want us to track you?"
This paper is like a six-year documentary (2018–2024) that watches how these pop-ups have changed, who is actually making the changes, and whether the rules are being followed. The researchers looked at over 11,000 websites across 30 European countries to tell the story.
Here is the breakdown of the story using simple analogies:
1. The Three Main Characters
The paper identifies three groups that influence how these pop-ups look and behave:
- The Publishers (Website Owners): Think of them as the Shopkeepers. They own the websites and are legally responsible for asking for permission.
- The Regulators (DPAs): Think of them as the Police Officers. They write the rules, give advice, and issue fines (tickets) to shopkeepers who break the law.
- The CMPs (Consent Management Platforms): Think of them as Pop-up Vending Machines. Many shopkeepers don't build their own pop-ups; they buy a pre-made "machine" from a company (like OneTrust or Cookiebot) that automatically displays the banner. The researchers wanted to see if these vending machine companies were helping the shopkeepers follow the rules.
2. The Big Story: Things Are Getting Better, But Slowly
At the very beginning (2018), the situation was messy. Only about 3% of websites had a "Reject All" button. Most just had a big "Accept" button, effectively tricking people into saying yes.
By 2024, the situation improved significantly. Now, about 30% of websites have a clear "Reject" button. That's a huge jump, but it means 7 out of 10 sites still aren't fully compliant.
The "Ripple Effect" of the Police:
The paper found a strong link between the "Police Officers" (Regulators) and the shopkeepers doing the right thing.
- Example: In France, the regulator (CNIL) fined Google and Meta for having pop-ups that made it hard to say "No."
- The Result: Immediately after the fines, websites in France (and even in other countries) started adding "Reject" buttons. It's like when a police officer starts ticketing people for not wearing seatbelts; suddenly, everyone starts buckling up.
- The Contrast: In countries where the regulators were quiet or didn't issue many fines (like Lithuania or Poland), the websites stayed lazy and didn't add "Reject" buttons.
3. The Surprise: The "Vending Machines" Didn't Help Much
The researchers had a theory: They thought the companies selling the pop-up software (the CMPs) would update their machines to be more privacy-friendly automatically when the laws changed.
The Reality Check:
The study found that this didn't happen.
- Some "Vending Machines" (like Cookiebot) updated their designs to include "Reject" buttons for about 55% of their customers.
- Other "Vending Machines" (like Cookies Consent) only did this for about 13% of their customers.
- The Conclusion: The CMPs mostly just sat there. They didn't force their customers to change. Instead, the Shopkeepers (Publishers) were the ones who actually went in, opened the machine, and manually changed the settings to be more compliant. The paper suggests that if a website has a good "Reject" button, it's because the website owner chose to put it there, not because the software company told them to.
4. The Current State of the Market
- Consolidation: The market for these pop-up machines is shrinking down to a few big players. Big companies like OneTrust and Cookiebot are now used by the majority of websites.
- The Problem: Because these big companies set the "default" settings, and they don't always make the most privacy-friendly choices by default, many websites end up with bad pop-ups unless the owner manually fixes them.
5. The Final Takeaway
The paper concludes that while the internet is becoming slightly more respectful of user privacy, it's happening because Shopkeepers are finally listening to the Police, not because the Vending Machine companies are being helpful.
The authors suggest that to make the internet truly safe for everyone, we need:
- More uniform rules: All the "Police Officers" across Europe need to agree on exactly what the rules are, so shopkeepers aren't confused.
- More oversight of the Vending Machines: The companies selling the pop-up software should be held more accountable. If they are the ones setting the default settings, they should be responsible for making sure those defaults are legal and fair.
In short: The rules are working, but only when the police are watching closely, and the tools being used to follow the rules need a serious upgrade.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.