{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,16]],"date-time":"2026-04-16T12:35:29Z","timestamp":1776342929999,"version":"3.51.2"},"reference-count":96,"publisher":"Privacy Enhancing Technologies Symposium Advisory Board","issue":"4","license":[{"start":{"date-parts":[[2021,7,23]],"date-time":"2021-07-23T00:00:00Z","timestamp":1626998400000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by-nc-nd\/3.0"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021,10,1]]},"abstract":"<jats:title>Abstract<\/jats:title>\n               <jats:p>Privacy preference signals are digital representations of how users want their personal data to be processed. Such signals must be adopted by both the sender (users) and intended recipients (data processors). Adoption represents a coordination problem that remains unsolved despite efforts dating back to the 1990s. Browsers implemented standards like the Platform for Privacy Preferences (P3P) and Do Not Track (DNT), but vendors profiting from personal data faced few incentives to receive and respect the expressed wishes of data subjects. In the wake of recent privacy laws, a coalition of AdTech firms published the Transparency and Consent Framework (TCF), which defines an optin consent signal. This paper integrates post-GDPR developments into the wider history of privacy preference signals. Our main contribution is a high-frequency longitudinal study describing how TCF signal gained dominance as of February 2021. We explore which factors correlate with adoption at the website level. Both the number of third parties on a website and the presence of Google Ads are associated with higher adoption of TCF. Further, we show that vendors acted as early adopters of TCF 2.0 and provide two case-studies describing how Consent Management Providers shifted existing customers to TCF 2.0. We sketch ways forward for a pro-privacy signal.<\/jats:p>","DOI":"10.2478\/popets-2021-0069","type":"journal-article","created":{"date-parts":[[2021,7,24]],"date-time":"2021-07-24T23:21:27Z","timestamp":1627168887000},"page":"249-269","source":"Crossref","is-referenced-by-count":13,"title":["Privacy Preference Signals: Past, Present and Future"],"prefix":"10.56553","volume":"2021","author":[{"given":"Maximilian","family":"Hils","sequence":"first","affiliation":[{"name":"University of Innsbruck , Austria"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Daniel W.","family":"Woods","sequence":"additional","affiliation":[{"name":"University of Innsbruck , Austria"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rainer","family":"B\u00f6hme","sequence":"additional","affiliation":[{"name":"University of Innsbruck , Austria"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"35752","published-online":{"date-parts":[[2021,7,23]]},"reference":[{"key":"2022060519475835548_j_popets-2021-0069_ref_001","unstructured":"[1] Pedro Giovanni Leon, Lorrie Faith Cranor, Aleecia M Mc-Donald, and Robert McGuire. Token attempt: The misrepresentation of website privacy policies through the misuse of P3P compact policy tokens. In ACM Workshop on Privacy in the Electronic Society, pages 93\u2013104, 2010."},{"key":"2022060519475835548_j_popets-2021-0069_ref_002","unstructured":"[2] Electronic Privacy Information Center and Junkbusters. Pretty Poor Privacy: An Assessment of P3P and Internet Privacy. https:\/\/epic.org\/reports\/prettypoorprivacy.html, 2000."},{"key":"2022060519475835548_j_popets-2021-0069_ref_003","unstructured":"[3] Tracking Protection Working Group. WG closed. https:\/\/github.com\/w3c\/dnt\/commit\/5d85d6c, 2019."},{"key":"2022060519475835548_j_popets-2021-0069_ref_004","unstructured":"[4] Interactive Advertising Bureau. \u201cDo Not Track\u201d set to \u201cOn\u201d by Default in Internet Explorer 10\u2014IAB Response. https:\/\/www.iab.com\/news\/do-not-track-set-to-on-by-default-in-internet-explorer-10iab-response\/, 2012."},{"key":"2022060519475835548_j_popets-2021-0069_ref_005","unstructured":"[5] Pam Dixon. The Network Advertising Initiative: Failing at Consumer Protection and at Self-Regulation. World Privacy Forum, 2007. http:\/\/www.worldprivacyforum.org\/wp-content\/uploads\/2007\/11\/WPF_NAI_report_Nov2_2007fs.pdf."},{"key":"2022060519475835548_j_popets-2021-0069_ref_006","unstructured":"[6] Martha K. Landesberg, Toby Milgrom Levin, Caroline G. Curtin, and Ori Lev. Privacy online: A Report to Congress. US Federal Trade Commission, 1998."},{"key":"2022060519475835548_j_popets-2021-0069_ref_007","unstructured":"[7] Christine Utz, Martin Degeling, Sascha Fahl, Florian Schaub, and Thorsten Holz. (Un)informed Consent: Studying GDPR Consent Notices in the Field. In Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, CCS \u201919, pages 973\u2013990. ACM, 2019."},{"key":"2022060519475835548_j_popets-2021-0069_ref_008","doi-asserted-by":"crossref","unstructured":"[8] C\u00e9lestin Matte, Nataliia Bielova, and Cristiana Santos. Do Cookie Banners Respect my Choice? Measuring Legal Compliance of Banners from IAB Europe\u2019s Transparency and Consent Framework. In IEEE Symposium on Security and Privacy, pages 791\u2013809. IEEE, 2020.10.1109\/SP40000.2020.00076","DOI":"10.1109\/SP40000.2020.00076"},{"key":"2022060519475835548_j_popets-2021-0069_ref_009","doi-asserted-by":"crossref","unstructured":"[9] Midas Nouwens, Ilaria Liccardi, Michael Veale, David Karger, and Lalana Kagal. Dark Patterns after the GDPR: Scraping Consent Pop-Ups and Demonstrating Their Influence. In Proceedings of the 2020 CHI Conference on Human Factors in Computing Systems, CHI \u201920. ACM, 2020.10.1145\/3313831.3376321","DOI":"10.1145\/3313831.3376321"},{"key":"2022060519475835548_j_popets-2021-0069_ref_010","doi-asserted-by":"crossref","unstructured":"[10] Dominique Machuletz and Rainer B\u00f6hme. Multiple Purposes, Multiple Problems: A User Study of Consent Dialogs after GDPR. Proceedings on Privacy Enhancing Technologies, (2):481\u2013498, 2020.","DOI":"10.2478\/popets-2020-0037"},{"key":"2022060519475835548_j_popets-2021-0069_ref_011","doi-asserted-by":"crossref","unstructured":"[11] Hana Habib, Sarah Pearman, Jiamin Wang, Yixin Zou, Alessandro Acquisti, Lorrie Faith Cranor, Norman Sadeh, and Florian Schaub. \"It\u2019s a Scavenger Hunt\": Usability of Websites\u2019 Opt-Out and Data Deletion Choices. In Proceedings of the 2020 CHI Conference on Human Factors in Computing Systems, CHI \u201920. ACM, 2020.10.1145\/3313831.3376511","DOI":"10.1145\/3313831.3376511"},{"key":"2022060519475835548_j_popets-2021-0069_ref_012","doi-asserted-by":"crossref","unstructured":"[12] Sean O\u2019Connor, Ryan Nurwono, and Eleanor Birrell. (Un)clear and (In)conspicuous: The right to opt-out of sale under CCPA, 2020.10.1145\/3463676.3485598","DOI":"10.1145\/3463676.3485598"},{"key":"2022060519475835548_j_popets-2021-0069_ref_013","unstructured":"[13] Maximilian Hils, Daniel W Woods, and Rainer B\u00f6hme. Measuring the Emergence of Consent Management on the Web. In Proceedings of the Internet Measurement Conference 2020, IMC \u201920. ACM, 2020."},{"key":"2022060519475835548_j_popets-2021-0069_ref_014","unstructured":"[14] Daniel W Woods and Rainer B\u00f6hme. The commodification of consent. In 20th Annual Workshop on the Economics of Information Security, WEIS, 2020."},{"key":"2022060519475835548_j_popets-2021-0069_ref_015","doi-asserted-by":"crossref","unstructured":"[15] Gunes Acar, Christian Eubank, Steven Englehardt, Marc Juarez, Arvind Narayanan, and Claudia Diaz. The Web Never Forgets: Persistent Tracking Mechanisms in the Wild. In Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security, CCS \u201914, pages 674\u2013689. ACM, 2014.10.1145\/2660267.2660347","DOI":"10.1145\/2660267.2660347"},{"key":"2022060519475835548_j_popets-2021-0069_ref_016","doi-asserted-by":"crossref","unstructured":"[16] Steven Englehardt, Dillon Reisman, Christian Eubank, Peter Zimmerman, Jonathan Mayer, Arvind Narayanan, and Edward W. Felten. Cookies That Give You Away: The Surveil-lance Implications of Web Tracking. In Proceedings of the 24th International Conference on World Wide Web, WWW \u201915, pages 289\u2013299, Republic and Canton of Geneva, CHE, 2015. International World Wide Web Conferences Steering Committee.10.1145\/2736277.2741679","DOI":"10.1145\/2736277.2741679"},{"key":"2022060519475835548_j_popets-2021-0069_ref_017","doi-asserted-by":"crossref","unstructured":"[17] Steven Englehardt and Arvind Narayanan. Online Tracking: A 1-Million-Site Measurement and Analysis. In Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, CCS \u201916, pages 1388\u20131401. ACM, 2016.10.1145\/2976749.2978313","DOI":"10.1145\/2976749.2978313"},{"key":"2022060519475835548_j_popets-2021-0069_ref_018","doi-asserted-by":"crossref","unstructured":"[18] Pierre Laperdrix, Nataliia Bielova, Benoit Baudry, and Gildas Avoine. Browser Fingerprinting: A Survey. ACM Trans. Web, 14(2), April 2020.10.1145\/3386040","DOI":"10.1145\/3386040"},{"key":"2022060519475835548_j_popets-2021-0069_ref_019","doi-asserted-by":"crossref","unstructured":"[19] T. Bujlow, V. Carela-Espa\u00f1ol, J. Sol\u00e9-Pareta, and P. Barlet-Ros. A Survey on Web Tracking: Mechanisms, Implications, and Defenses. Proceedings of the IEEE, 105(8):1476\u20131510, 2017.","DOI":"10.1109\/JPROC.2016.2637878"},{"key":"2022060519475835548_j_popets-2021-0069_ref_020","doi-asserted-by":"crossref","unstructured":"[20] Simon Byers, Lorrie Faith Cranor, and David Kormann. Automated analysis of P3P-enabled web sites. In Proceedings of the 5th International Conference on Electronic Commerce, pages 326\u2013338, 2003.10.1145\/948005.948048","DOI":"10.1145\/948005.948048"},{"key":"2022060519475835548_j_popets-2021-0069_ref_021","doi-asserted-by":"crossref","unstructured":"[21] Patricia Beatty, Ian Reay, Scott Dick, and James Miller. P3P adoption on e-commerce web sites: a survey and analysis. IEEE Internet Computing, 11(2):65\u201371, 2007.","DOI":"10.1109\/MIC.2007.45"},{"key":"2022060519475835548_j_popets-2021-0069_ref_022","doi-asserted-by":"crossref","unstructured":"[22] Ian Reay, Patricia Beatty, Scott Dick, and James Miller. Privacy policies and national culture on the internet. Information Systems Frontiers, 15(2):279\u2013292, 2013.10.1007\/s10796-011-9336-7","DOI":"10.1007\/s10796-011-9336-7"},{"key":"2022060519475835548_j_popets-2021-0069_ref_023","unstructured":"[23] Riva Richmond. A loophole big enough for a cookie to fit through. New York Times, 2010. https:\/\/nyti.ms\/2mDvTBQ."},{"key":"2022060519475835548_j_popets-2021-0069_ref_024","doi-asserted-by":"crossref","unstructured":"[24] Lorrie Faith Cranor, Manjula Arjula, and Praveen Guduru. Use of a P3P user agent by early adopters. In Proceedings of the 2002 ACM Workshop on Privacy in the Electronic Society, pages 1\u201310, 2002.10.1145\/644527.644528","DOI":"10.1145\/644527.644528"},{"key":"2022060519475835548_j_popets-2021-0069_ref_025","unstructured":"[25] World Wide Web Consortium. Tracking Protection Working Group. https:\/\/www.w3.org\/2011\/tracking-protection\/, 2011."},{"key":"2022060519475835548_j_popets-2021-0069_ref_026","unstructured":"[26] Julia Angwin. Microsoft\u2019s \u201cDo Not Track\u201d Move Angers Advertising Industry. https:\/\/www.wsj.com\/articles\/BLDGB-24506, 2012."},{"key":"2022060519475835548_j_popets-2021-0069_ref_027","unstructured":"[27] Chrome Blog. Longer battery life and easier website permissions. https:\/\/chrome.googleblog.com\/2012\/11\/longer-battery-life-and-easier-website.html, 2012."},{"key":"2022060519475835548_j_popets-2021-0069_ref_028","unstructured":"[28] Future of Privacy Forum. Companies that have implemented Do Not Track. https:\/\/allaboutdnt.com\/companies\/, 2020."},{"key":"2022060519475835548_j_popets-2021-0069_ref_029","unstructured":"[29] Alex Fowler. Mozilla\u2019s new Do Not Track dashboard: Firefox users continue to seek out and enable DNT. https:\/\/blog.mozilla.org\/netpolicy\/2013\/05\/03\/mozillasnew-do-not-track-dashboard-firefox-users-continue-to-seek-out-and-enable-dnt\/, 2013."},{"key":"2022060519475835548_j_popets-2021-0069_ref_030","unstructured":"[30] Robin Berjon, Sebastian Zimmeck, Ashkan Soltani, David Harbage, and Peter Synder. Global Privacy Control (GPC) Unofficial Draft 15 October 2020. https:\/\/globalprivacycontrol.github.io\/gpc-spec\/, 2020."},{"key":"2022060519475835548_j_popets-2021-0069_ref_031","unstructured":"[31] IAB Europe. What is the Transparency and Consent Framework (TCF)? https:\/\/iabeurope.eu\/transparency-consent-framework\/, 2020."},{"key":"2022060519475835548_j_popets-2021-0069_ref_032","doi-asserted-by":"crossref","unstructured":"[32] J. R. Mayer and J. C. Mitchell. Third-party web tracking: Policy and technology. In 2012 IEEE Symposium on Security and Privacy, pages 413\u2013427. IEEE, 2012.10.1109\/SP.2012.47","DOI":"10.1109\/SP.2012.47"},{"key":"2022060519475835548_j_popets-2021-0069_ref_033","doi-asserted-by":"crossref","unstructured":"[33] Balachander Krishnamurthy and Craig E Wills. On the leakage of personally identifiable information via online social networks. In Proceedings of the 2nd ACM workshop on online social networks, pages 7\u201312, 2009.10.1145\/1592665.1592668","DOI":"10.1145\/1592665.1592668"},{"key":"2022060519475835548_j_popets-2021-0069_ref_034","doi-asserted-by":"crossref","unstructured":"[34] Gunes Acar, Steven Englehardt, and Arvind Narayanan. No boundaries: data exfiltration by third parties embedded on web pages. Proceedings on Privacy Enhancing Technologies, 2020(4):220 \u2013 238, 2020.","DOI":"10.2478\/popets-2020-0070"},{"key":"2022060519475835548_j_popets-2021-0069_ref_035","doi-asserted-by":"crossref","unstructured":"[35] Shehroze Farooqi, Maaz Musa, Zubair Shafiq, and Fareed Zaffar. Canarytrap: Detecting data misuse by third-party apps on online social networks. Proceedings on Privacy Enhancing Technologies, 2020(4):336 \u2013 354, 2020.","DOI":"10.2478\/popets-2020-0076"},{"key":"2022060519475835548_j_popets-2021-0069_ref_036","doi-asserted-by":"crossref","unstructured":"[36] Irwin Reyes, Primal Wijesekera, Joel Reardon, Amit Elazari Bar On, Abbas Razaghpanah, Narseo Vallina-Rodriguez, and Serge Egelman. \u201cWon\u2019t Somebody Think of the Children?\u201d Examining COPPA Compliance at Scale. Proceedings on Privacy Enhancing Technologies, 2018(3):63 \u2013 83, 2018.10.1515\/popets-2018-0021","DOI":"10.1515\/popets-2018-0021"},{"key":"2022060519475835548_j_popets-2021-0069_ref_037","doi-asserted-by":"crossref","unstructured":"[37] Hamza Saleem and Muhammad Naveed. SoK: Anatomy of Data Breaches. Proceedings on Privacy Enhancing Technologies, 2020(4):153 \u2013 174, 2020.","DOI":"10.2478\/popets-2020-0067"},{"key":"2022060519475835548_j_popets-2021-0069_ref_038","doi-asserted-by":"crossref","unstructured":"[38] S\u00e9bastien Henri, Gines Garcia-Aviles, Pablo Serrano, Albert Banchs, and Patrick Thiran. Protecting against Website Fingerprinting with Multihoming. Proceedings on Privacy Enhancing Technologies, 2020(2):89 \u2013 110, 01 Apr. 2020.10.2478\/popets-2020-0019","DOI":"10.2478\/popets-2020-0019"},{"key":"2022060519475835548_j_popets-2021-0069_ref_039","doi-asserted-by":"crossref","unstructured":"[39] Miti Mazmudar and Ian Goldberg. Mitigator: Privacy policy compliance using trusted hardware. Proceedings on Privacy Enhancing Technologies, 2020(3):204 \u2013 221, 2020.","DOI":"10.2478\/popets-2020-0049"},{"key":"2022060519475835548_j_popets-2021-0069_ref_040","doi-asserted-by":"crossref","unstructured":"[40] Martino Trevisan, Stefano Traverso, Eleonora Bassi, and Marco Mellia. 4 Years of EU Cookie Law: Results and Lessons Learned. Proceedings on Privacy Enhancing Technologies, 2019(2):126 \u2013 145, 2019.","DOI":"10.2478\/popets-2019-0023"},{"key":"2022060519475835548_j_popets-2021-0069_ref_041","doi-asserted-by":"crossref","unstructured":"[41] Daniel W. Woods and Rainer B\u00f6hme. SoK: Quantifying cyber risk. In IEEE Symposium on Security and Privacy, May 2021.10.1109\/SP40001.2021.00053","DOI":"10.1109\/SP40001.2021.00053"},{"key":"2022060519475835548_j_popets-2021-0069_ref_042","doi-asserted-by":"crossref","unstructured":"[42] Laura Shipp and Jorge Blasco. How private is your period?: A systematic analysis of menstrual app privacy policies. Proceedings on Privacy Enhancing Technologies, 2020(4):491 \u2013 510, 2020.","DOI":"10.2478\/popets-2020-0083"},{"key":"2022060519475835548_j_popets-2021-0069_ref_043","doi-asserted-by":"crossref","unstructured":"[43] Ryan Amos, Gunes Acar, Elena Lucherini, Mihir Kshirsagar, Arvind Narayanan, and Jonathan Mayer. Privacy Policies over Time: Curation and Analysis of a Million-Document Dataset. arXiv preprint arXiv:2008.09159, 2020.","DOI":"10.1145\/3442381.3450048"},{"key":"2022060519475835548_j_popets-2021-0069_ref_044","doi-asserted-by":"crossref","unstructured":"[44] Martin Degeling, Christine Utz, Christopher Lentzsch, Henry Hosseini, Florian Schaub, and Thorsten Holz. We Value Your Privacy ... Now Take Some Cookies: Measuring the GDPR\u2019s Impact on Web Privacy. In 26th Annual Network and Distributed System Security Symposium, NDSS \u201919. The Internet Society, 2019.10.14722\/ndss.2019.23378","DOI":"10.14722\/ndss.2019.23378"},{"key":"2022060519475835548_j_popets-2021-0069_ref_045","doi-asserted-by":"crossref","unstructured":"[45] Thomas Linden, Rishabh Khandelwal, Hamza Harkous, and Kassem Fawaz. The Privacy Policy Landscape After the GDPR. Proceedings on Privacy Enhancing Technologies, 2020(1):47 \u2013 64, 01 Jan. 2020.10.2478\/popets-2020-0004","DOI":"10.2478\/popets-2020-0004"},{"key":"2022060519475835548_j_popets-2021-0069_ref_046","doi-asserted-by":"crossref","unstructured":"[46] Judith S Olson, Jonathan Grudin, and Eric Horvitz. A study of preferences for sharing and privacy. In CHI\u201905 extended abstracts on Human factors in Computing Systems, pages 1985\u20131988, 2005.10.1145\/1056808.1057073","DOI":"10.1145\/1056808.1057073"},{"key":"2022060519475835548_j_popets-2021-0069_ref_047","doi-asserted-by":"crossref","unstructured":"[47] Mark S Ackerman, Lorrie Faith Cranor, and Joseph Reagle. Privacy in e-commerce: examining user scenarios and privacy preferences. In Proceedings of the 1st ACM Conference on Electronic commerce, pages 1\u20138, 1999.10.1145\/336992.336995","DOI":"10.1145\/336992.336995"},{"key":"2022060519475835548_j_popets-2021-0069_ref_048","doi-asserted-by":"crossref","unstructured":"[48] Ben Weinshel, Miranda Wei, Mainack Mondal, Euirim Choi, Shawn Shan, Claire Dolin, Michelle L. Mazurek, and Blase Ur. Oh, the Places You\u2019ve Been! User Reactions to Longitudinal Transparency About Third-Party Web Tracking and Inferencing. In Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, CCS \u201919, pages 149\u2013166. ACM, 2019.10.1145\/3319535.3363200","DOI":"10.1145\/3319535.3363200"},{"key":"2022060519475835548_j_popets-2021-0069_ref_049","doi-asserted-by":"crossref","unstructured":"[49] Sarah Spiekermann, Jens Grossklags, and Bettina Berendt. E-Privacy in 2nd Generation E-Commerce: Privacy Preferences versus Actual Behavior. In Proceedings of the 3rd ACM Conference on Electronic Commerce, EC \u201901, pages 38\u201347. ACM, 2001.10.1145\/501158.501163","DOI":"10.1145\/501158.501163"},{"key":"2022060519475835548_j_popets-2021-0069_ref_050","doi-asserted-by":"crossref","unstructured":"[50] Susanne Barth and Menno DT De Jong. The privacy paradox \u2013 Investigating discrepancies between expressed privacy concerns and actual online behavior \u2013 A systematic literature review. Telematics and informatics, 34(7):1038\u20131058, 2017.10.1016\/j.tele.2017.04.013","DOI":"10.1016\/j.tele.2017.04.013"},{"key":"2022060519475835548_j_popets-2021-0069_ref_051","doi-asserted-by":"crossref","unstructured":"[51] Nina Gerber, Paul Gerber, and Melanie Volkamer. Explaining the privacy paradox: A systematic review of literature investigating privacy attitude and behavior. Computers & Security, 77:226\u2013261, 2018.","DOI":"10.1016\/j.cose.2018.04.002"},{"key":"2022060519475835548_j_popets-2021-0069_ref_052","doi-asserted-by":"crossref","unstructured":"[52] Lorrie Faith Cranor. P3P: Making privacy policies more useful. IEEE Security & Privacy, 1(6):50\u201355, 2003.","DOI":"10.1109\/MSECP.2003.1253568"},{"key":"2022060519475835548_j_popets-2021-0069_ref_053","doi-asserted-by":"crossref","unstructured":"[53] Rakesh Agrawal, Jerry Kiernan, Ramakrishnan Srikant, and Yirong Xu. XPref: a preference language for P3P. Computer Networks, 48(5):809 \u2013 827, 2005. Web Security.","DOI":"10.1016\/j.comnet.2005.01.004"},{"key":"2022060519475835548_j_popets-2021-0069_ref_054","doi-asserted-by":"crossref","unstructured":"[54] Johnson Iyilade and Julita Vassileva. P2U: a privacy policy specification language for secondary data sharing and usage. In 2014 IEEE Security and Privacy Workshops, pages 18\u201322. IEEE, 2014.10.1109\/SPW.2014.12","DOI":"10.1109\/SPW.2014.12"},{"key":"2022060519475835548_j_popets-2021-0069_ref_055","doi-asserted-by":"crossref","unstructured":"[55] Jean Yang, Kuat Yessenov, and Armando Solar-Lezama. A language for automatically enforcing privacy policies. ACM SIGPLAN Notices, 47(1):85\u201396, 2012.10.1145\/2103621.2103669","DOI":"10.1145\/2103621.2103669"},{"key":"2022060519475835548_j_popets-2021-0069_ref_056","doi-asserted-by":"crossref","unstructured":"[56] Monir Azraoui, Kaoutar Elkhiyaoui, Melek \u00d6nen, Karin Bernsmed, Anderson Santana De Oliveira, and Jakub Sendor. A-PPL: An Accountability Policy Language. In Data Privacy Management, Autonomous Spontaneous Security, and Security Assurance, pages 319\u2013326, Cham, 2015. Springer.10.1007\/978-3-319-17016-9_21","DOI":"10.1007\/978-3-319-17016-9_21"},{"key":"2022060519475835548_j_popets-2021-0069_ref_057","doi-asserted-by":"crossref","unstructured":"[57] Lalana Kagal, Chris Hanson, and Daniel Weitzner. Using dependency tracking to provide explanations for policy management. In 2008 IEEE Workshop on Policies for Distributed Systems and Networks, pages 54\u201361. IEEE, 2008.10.1109\/POLICY.2008.51","DOI":"10.1109\/POLICY.2008.51"},{"key":"2022060519475835548_j_popets-2021-0069_ref_058","unstructured":"[58] Ponnurangam Kumaraguru, Lorrie Cranor, Jorge Lobo, and Seraphin Calo. A survey of privacy policy languages. In Workshop on Usable IT Security Management (USM 07): Proceedings of the 3rd Symposium on Usable Privacy and Security, ACM, 2007."},{"key":"2022060519475835548_j_popets-2021-0069_ref_059","doi-asserted-by":"crossref","unstructured":"[59] Jun Zhao, Reuben Binns, Max Van Kleek, and Nigel Shad-bolt. Privacy languages: Are we there yet to enable user controls? In Proceedings of the 25th International Conference Companion on World Wide Web, WWW \u201916 Companion, pages 799\u2013806. International World Wide Web Conferences Steering Committee, 2016.10.1145\/2872518.2890590","DOI":"10.1145\/2872518.2890590"},{"key":"2022060519475835548_j_popets-2021-0069_ref_060","unstructured":"[60] Saffija Kasem-Madani and Michael Meier. Security and privacy policy languages: A survey, categorization and gap identification. CoRR, abs\/1512.00201, 2015."},{"key":"2022060519475835548_j_popets-2021-0069_ref_061","doi-asserted-by":"crossref","unstructured":"[61] Victor Morel and Ra\u00fal Pardo. SoK: Three facets of privacy policies. In WPES\u201920: Proceedings of the 19th Workshop on Privacy in the Electronic Society, Virtual Event, USA, November 9, 2020, pages 41\u201356. ACM, 2020.","DOI":"10.1145\/3411497.3420216"},{"key":"2022060519475835548_j_popets-2021-0069_ref_062","doi-asserted-by":"crossref","unstructured":"[62] Lorrie Faith Cranor, Serge Egelman, Steve Sheng, Aleecia M McDonald, and Abdur Chowdhury. P3P deployment on websites. Electronic Commerce Research and Applications, 7(3):274\u2013293, 2008.10.1016\/j.elerap.2008.04.003","DOI":"10.1016\/j.elerap.2008.04.003"},{"key":"2022060519475835548_j_popets-2021-0069_ref_063","doi-asserted-by":"crossref","unstructured":"[63] Ian Reay, Scott Dick, and James Miller. An analysis of privacy signals on the World Wide Web: Past, present and future. Inf. Sci., 179(8):1102\u20131115, 2009.","DOI":"10.1016\/j.ins.2008.12.012"},{"key":"2022060519475835548_j_popets-2021-0069_ref_064","doi-asserted-by":"crossref","unstructured":"[64] C\u00e9lestin Matte, Cristiana Santos, and Nataliia Bielova. Purposes in IAB Europe\u2019s TCF: which legal basis and how are they used by advertisers? In Annual Privacy Forum, 2020.10.1007\/978-3-030-55196-4_10","DOI":"10.1007\/978-3-030-55196-4_10"},{"key":"2022060519475835548_j_popets-2021-0069_ref_065","unstructured":"[65] Yee-Lin Lai and Kai-Lung Hui. Internet opt-in and optout: Investigating the roles of frames, defaults and privacy concerns. In Proceedings of the 2006 ACM SIGMIS CPR Conference on Computer Personnel Research, SIGMIS CPR \u201906, pages 253\u2013263. ACM, 2006."},{"key":"2022060519475835548_j_popets-2021-0069_ref_066","doi-asserted-by":"crossref","unstructured":"[66] Rainer B\u00f6hme and Stefan K\u00f6psell. Trained to accept? A field experiment on consent dialogs. In Proceedings of the SIGCHI Conference on Human Factors in Computing Systems, CHI \u201910, pages 2403\u20132406. ACM, 2010.10.1145\/1753326.1753689","DOI":"10.1145\/1753326.1753689"},{"key":"2022060519475835548_j_popets-2021-0069_ref_067","doi-asserted-by":"crossref","unstructured":"[67] Idris Adjerid, Alessandro Acquisti, Laura Brandimarte, and George Loewenstein. Sleights of privacy: Framing, disclosures, and the limits of transparency. In Proceedings of the Ninth Symposium on Usable Privacy and Security, SOUPS \u201913. ACM, 2013.10.1145\/2501604.2501613","DOI":"10.1145\/2501604.2501613"},{"key":"2022060519475835548_j_popets-2021-0069_ref_068","doi-asserted-by":"crossref","unstructured":"[68] Barry M Leiner, Vinton G Cerf, David D Clark, Robert E Kahn, Leonard Kleinrock, Daniel C Lynch, Jon Postel, Larry G Roberts, and Stephen Wolff. A brief history of the internet. ACM SIGCOMM Computer Communication Review, 39(5):22\u201331, 2009.10.1145\/1629607.1629613","DOI":"10.1145\/1629607.1629613"},{"key":"2022060519475835548_j_popets-2021-0069_ref_069","doi-asserted-by":"crossref","unstructured":"[69] Mehdi Nikkhah, Aman Mangal, Constantine Dovrolis, and Roch Gu\u00e9rin. A statistical exploration of protocol adoption. IEEE\/ACM Transactions on Networking, 25(5):2858\u20132871, 2017.10.1109\/TNET.2017.2711642","DOI":"10.1109\/TNET.2017.2711642"},{"key":"2022060519475835548_j_popets-2021-0069_ref_070","doi-asserted-by":"crossref","unstructured":"[70] Jakub Czyz, Mark Allman, Jing Zhang, Scott Iekel-Johnson, Eric Osterweil, and Michael Bailey. Measuring IPv6 adoption. SIGCOMM Comput. Commun. Rev., 44(4):87\u201398, August 2014.10.1145\/2740070.2626295","DOI":"10.1145\/2740070.2626295"},{"key":"2022060519475835548_j_popets-2021-0069_ref_071","doi-asserted-by":"crossref","unstructured":"[71] Xuequn Wang and Sebastian Zander. Extending the model of internet standards adoption: A cross-country comparison of IPv6 adoption. Information & Management, 55(4):450 \u2013 460, 2018.","DOI":"10.1016\/j.im.2017.10.005"},{"key":"2022060519475835548_j_popets-2021-0069_ref_072","doi-asserted-by":"crossref","unstructured":"[72] M. Nikkhah and R. Gu\u00e9rin. Migrating the Internet to IPv6: An Exploration of the When and Why. IEEE\/ACM Transactions on Networking, 24(4):2291\u20132304, 2016.","DOI":"10.1109\/TNET.2015.2453338"},{"key":"2022060519475835548_j_popets-2021-0069_ref_073","doi-asserted-by":"crossref","unstructured":"[73] Ralph Holz, Lothar Braun, Nils Kammenhuber, and Georg Carle. The SSL Landscape: A Thorough Analysis of the x.509 PKI Using Active and Passive Measurements. In Proceedings of the 2011 ACM SIGCOMM Conference on Internet Measurement Conference, IMC \u201911, pages 427\u2013444. ACM, 2011.10.1145\/2068816.2068856","DOI":"10.1145\/2068816.2068856"},{"key":"2022060519475835548_j_popets-2021-0069_ref_074","unstructured":"[74] Andy Ozment and Stuart E Schechter. Bootstrapping the adoption of internet security protocols. In 5th Annual Workshop on the Economics of Information Security, WEIS, 2006."},{"key":"2022060519475835548_j_popets-2021-0069_ref_075","unstructured":"[75] Adrienne Porter Felt, Richard Barnes, April King, Chris Palmer, Chris Bentzel, and Parisa Tabriz. Measuring HTTPS adoption on the web. In Proceedings of the USENIX Security Symposium (USENIX Security 17), pages 1323\u20131338, 2017."},{"key":"2022060519475835548_j_popets-2021-0069_ref_076","doi-asserted-by":"crossref","unstructured":"[76] Victor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski, and Wouter Joosen. Tranco: A research-oriented top sites ranking hardened against manipulation. In 26th Annual Network and Distributed System Security Symposium, NDSS \u201919. The Internet Society, 2019.10.14722\/ndss.2019.23386","DOI":"10.14722\/ndss.2019.23386"},{"key":"2022060519475835548_j_popets-2021-0069_ref_077","unstructured":"[77] Symantec. Symantec RuleSpace: URL categorization database, 2020."},{"key":"2022060519475835548_j_popets-2021-0069_ref_078","doi-asserted-by":"crossref","unstructured":"[78] Iskander Sanchez-Rola, Matteo Dell\u2019Amico, Platon Kotzias, Davide Balzarotti, Leyla Bilge, Pierre-Antoine Vervier, and Igor Santos. Can I Opt Out Yet? GDPR and the Global Illusion of Cookie Control. In Proceedings of the 2019 ACM Asia Conference on Computer and Communications Security, Asia CCS \u201919, pages 340\u2013351. ACM, 2019.10.1145\/3321705.3329806","DOI":"10.1145\/3321705.3329806"},{"key":"2022060519475835548_j_popets-2021-0069_ref_079","doi-asserted-by":"crossref","unstructured":"[79] Pelayo Vallina, Victor Le Pochat, \u00c1lvaro Feal, Marius Paraschiv, Julien Gamba, Tim Burke, Oliver Hohlfeld, Juan Tapiador, and Narseo Vallina-Rodriguez. Mis-shapes, Mistakes, Misfits: An Analysis of Domain Classification Services. In Proceedings of the Internet Measurement Conference 2020, IMC \u201920. ACM, 2020.10.1145\/3419394.3423660","DOI":"10.1145\/3419394.3423660"},{"key":"2022060519475835548_j_popets-2021-0069_ref_080","unstructured":"[80] Mozilla Foundation. Public suffix list. https:\/\/publicsuffix.org\/, 2007\u20132020."},{"key":"2022060519475835548_j_popets-2021-0069_ref_081","doi-asserted-by":"crossref","unstructured":"[81] Yana Dimova, Gunes Acar, Lukasz Olejnik, Wouter Joosen, and Tom van Goethem. The CNAME of the Game: Large-scale Analysis of DNS-based Tracking Evasion. Proceedings on Privacy Enhancing Technologies, 2021.10.2478\/popets-2021-0053","DOI":"10.2478\/popets-2021-0053"},{"key":"2022060519475835548_j_popets-2021-0069_ref_082","unstructured":"[82] Inside Privacy. Digital Advertising Alliance Leaves Do Not Track Group. https:\/\/www.insideprivacy.com\/advertising-marketing\/digital-advertising-alliance-leaves-do-not-track-group-2\/, 2013."},{"key":"2022060519475835548_j_popets-2021-0069_ref_083","unstructured":"[83] IAB Tech Lab. Global Privacy Working Group. https:\/\/iabtechlab.com\/working-groups\/global-privacy-working-group\/, 2011."},{"key":"2022060519475835548_j_popets-2021-0069_ref_084","doi-asserted-by":"crossref","unstructured":"[84] Andrew L Russell. \u2018Rough consensus and running code\u2019 and the Internet-OSI standards war. IEEE Annals of the History of Computing, 28(3):48\u201361, 2006.10.1109\/MAHC.2006.42","DOI":"10.1109\/MAHC.2006.42"},{"key":"2022060519475835548_j_popets-2021-0069_ref_085","unstructured":"[85] Christopher Soghoian. The History of the Do Not Track Header. http:\/\/paranoia.dubfire.net\/2011\/01\/history-of-donot-track-header.html, 2011."},{"key":"2022060519475835548_j_popets-2021-0069_ref_086","unstructured":"[86] Carl Shapiro, Shapiro Carl, Hal R Varian, et al. Information rules: a strategic guide to the network economy. Harvard Business Press, 1998."},{"key":"2022060519475835548_j_popets-2021-0069_ref_087","unstructured":"[87] Kochava Inc. Quantcast and Kochava Partnership Delivers Combined Web and Mobile App Solution for CCPA. https:\/\/www.businesswire.com\/news\/home\/20200207005054\/en\/Quantcast-and-Kochava-Partnership-Delivers-Combined-Web-and-Mobile-App-Solution-for-CCPA, 2018."},{"key":"2022060519475835548_j_popets-2021-0069_ref_088","unstructured":"[88] Johnny Ryan. Regulatory complaint concerning massive, web-wide data breach by Google and other \u201cad tech\u201d companies under Europe\u2019s GDPR. https:\/\/brave.com\/adtech-data-breach-complaint\/, 2018."},{"key":"2022060519475835548_j_popets-2021-0069_ref_089","unstructured":"[89] Natasha Lomas. Brave Accueses European governments of GDPR resourcing failure. https:\/\/techcrunch.com\/2020\/04\/27\/brave-accuses-european-governments-of-gdpr-resourcing-failure\/, 2020."},{"key":"2022060519475835548_j_popets-2021-0069_ref_090","unstructured":"[90] Johnny Ryan. Formal GDPR complaint against IAB Europe\u2019s \u201ccookie wall\u201d and GDPR consent guidance. https:\/\/brave.com\/iab-cookie-wall\/, 2019."},{"key":"2022060519475835548_j_popets-2021-0069_ref_091","unstructured":"[91] Tue Goldschmieding. New important decision on cookies from the Danish Data Protection Agency. https:\/\/gorrissenfederspiel.com\/en\/knowledge\/news\/new-important-decision-on-cookies-from-the-danish-data-protection-agency, 2020."},{"key":"2022060519475835548_j_popets-2021-0069_ref_092","doi-asserted-by":"crossref","unstructured":"[92] Aaron Ceross and Andrew Simpson. Rethinking the Proposition of Privacy Engineering. In Proceedings of the New Security Paradigms Workshop, NSPW \u201918, pages 89\u2013102. ACM, 2018.10.1145\/3285002.3285006","DOI":"10.1145\/3285002.3285006"},{"key":"2022060519475835548_j_popets-2021-0069_ref_093","doi-asserted-by":"crossref","unstructured":"[93] Carl Shapiro and Hal R Varian. The art of standards wars. California Management Review, 41(2):8\u201332, 1999.10.2307\/41165984","DOI":"10.2307\/41165984"},{"key":"2022060519475835548_j_popets-2021-0069_ref_094","doi-asserted-by":"crossref","unstructured":"[94] Christoph B\u00f6sch, Benjamin Erb, Frank Kargl, Henning Kopp, and Stefan Pfattheicher. Tales from the dark side: Privacy dark strategies and privacy dark patterns. Proceedings on Privacy Enhancing Technologies, 2016(4):237\u2013254, 2016.","DOI":"10.1515\/popets-2016-0038"},{"key":"2022060519475835548_j_popets-2021-0069_ref_095","doi-asserted-by":"crossref","unstructured":"[95] Arunesh Mathur, Gunes Acar, Michael J Friedman, Elena Lucherini, Jonathan Mayer, Marshini Chetty, and Arvind Narayanan. Dark patterns at scale: Findings from a crawl of 11k shopping websites. Proceedings of the ACM on Human-Computer Interaction, 3(CSCW):1\u201332, 2019.","DOI":"10.1145\/3359183"},{"key":"2022060519475835548_j_popets-2021-0069_ref_096","doi-asserted-by":"crossref","unstructured":"[96] Arvind Narayanan, Arunesh Mathur, Marshini Chetty, and Mihir Kshirsagar. Dark Patterns: Past, Present, and Future. ACM Queue, 18(2):67\u201392, 2020.","DOI":"10.1145\/3400899.3400901"}],"container-title":["Proceedings on Privacy Enhancing Technologies"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.sciendo.com\/pdf\/10.2478\/popets-2021-0069","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,7,20]],"date-time":"2022-07-20T16:31:42Z","timestamp":1658334702000},"score":1,"resource":{"primary":{"URL":"https:\/\/petsymposium.org\/popets\/2021\/popets-2021-0069.php"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,7,23]]},"references-count":96,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2021,7,23]]},"published-print":{"date-parts":[[2021,10,1]]}},"alternative-id":["10.2478\/popets-2021-0069"],"URL":"https:\/\/doi.org\/10.2478\/popets-2021-0069","relation":{},"ISSN":["2299-0984"],"issn-type":[{"value":"2299-0984","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,7,23]]}}}