User Tools

Site Tools


privacy:consent

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
privacy:consent [2026/09/05 20:01] – Audit the 313 no-interaction consentAction papers: 279 unsupported, 3 false negatives; headline, six-action table, year buckets, vantage, statefulness and limitations refreshed. Authored by Claude karel.kubicek.claudeprivacy:consent [2026/09/16 11:20] (current) – Add the boundary with privacy:data_subject_rights to the GPC section: this page sets the signal, that page owns it as an opt-out right. Authored by Claude karel.kubicek.claude
Line 6: Line 6:
  
 <WRAP important> <WRAP important>
-**The finding that should shape your methods section.** Of the **1,120** papers in [[literature:corpus|this corpus]] that ran an automated web crawl, **55 (4.9%)** say in their own words what they did about consent notices. **32** of those describe interacting with one; **22** state that they deliberately did not; 1 does both, in different arms.((Every one of the 349 papers the extraction credits with a stated consent action has now been read against its own full text — the 36 claiming an interaction on 2026-08-19, the 313 labelled //no-interaction// on 2026-09-05. **279 of those 313 say nothing about consent at all**: the label is the extractor's default, not the paper's claim. Full verdicts, one line per paper, on [[provenance:privacy:consent|the provenance page]]; see [[#Almost nobody says what they did about consent]].)) A further 8 papers say they perform no page interaction whatsoever without ever mentioning consent, which takes the lenient count to **63 (5.6%)**.+**The finding that should shape your methods section.** Of the **1,120** papers in [[literature:corpus|this corpus]] that ran an automated web crawl, **55 (4.9%)** say in their own words what they did about consent notices. **32** of those describe interacting with one; **22** state that they deliberately did not; 1 does both, in different arms.((Every one of the 349 papers the extraction credits with a stated consent action has now been read against its own full text — the 36 claiming an interaction on 2026-08-19, the 313 labelled //no-interaction// on 2026-09-05. **279 of those 313 give no evidence of their own crawl'consent action**: the label is the extractor's default, not the paper's claim. (Most of the 279 do use the word //consent// somewhere — about an IRB form, an OAuth screen, a banner ad — which is exactly how the extractor came to fill the field.) Full verdicts, one line per paper, on [[provenance:privacy:consent|the provenance page]]; see [[#Almost nobody says what they did about consent]].)) A further 8 papers say they perform no page interaction whatsoever without ever mentioning consent, which takes the lenient count to **63 (5.6%)**.
  
 That is the number to carry away: **for 1,057 of 1,120 crawling papers (94.4%) you cannot tell from the paper which web was measured** — the pre-consent one or the post-consent one. That is the number to carry away: **for 1,057 of 1,120 crawling papers (94.4%) you cannot tell from the paper which web was measured** — the pre-consent one or the post-consent one.
Line 34: Line 34:
 | **dismiss or remove** — close the banner, or delete it from the DOM | Nothing about consent. Useful only to unblock a crawl whose real subject is something else | Removing the banner from the DOM is **not** a consent choice: no consent string is written, and the site may behave as it does pre-consent. Say "we removed the overlay", never "we declined" | 3 | **0** | | **dismiss or remove** — close the banner, or delete it from the DOM | Nothing about consent. Useful only to unblock a crawl whose real subject is something else | Removing the banner from the DOM is **not** a consent choice: no consent string is written, and the site may behave as it does pre-consent. Say "we removed the overlay", never "we declined" | 3 | **0** |
  
-The //Verified// column comes from reading each of these 349 papers' own full text (see [[#Almost nobody says what they did about consent|below]] and [[provenance:privacy:consent|the provenance page]]). Two patterns in it are worth carrying away even if you never touch this corpus. **The enum is trustworthy exactly where the paper had to describe two arms**, and unreliable where a single ambiguous word in a methods paragraph could be misread. And **//no interaction// is not a finding about the field, it is a finding about the extractor**: 279 of those 313 papers never mention consent at all, and 3 of them turned out to interact with a notice after all — the notice-driving crawl of CookieEnforcer {[khandelwal2023automated]}, the BannerClick accept/reject arms of Lin et al. {[lin2024_browsing]}, and the three TCF consent modes of Morel et al. {[morel2026_tcf]}. Read a paper before you count it in either direction.+The //Verified// column comes from reading each of these 349 papers' own full text (see [[#Almost nobody says what they did about consent|below]] and [[provenance:privacy:consent|the provenance page]]). Two patterns in it are worth carrying away even if you never touch this corpus. **The enum is trustworthy exactly where the paper had to describe two arms**, and unreliable where a single ambiguous word in a methods paragraph could be misread. And **//no interaction// is not a finding about the field, it is a finding about the extractor**: 279 of those 313 papers say nothing about what their own crawl did with a notice, and a further **3** turned out to have driven one after all — the notice-driving crawl of CookieEnforcer {[khandelwal2023automated]}, the BannerClick accept/reject arms of Lin et al. {[lin2024_browsing]}, and the three TCF consent modes of Morel et al. {[morel2026_tcf]}. Read a paper before you count it in either direction.
  
 <WRAP important> <WRAP important>
Line 142: Line 142:
  
 DNT sent a ''DNT: 1'' request header and exposed ''navigator.doNotTrack''. It failed because nothing obliged anyone to honour it: Libert {[libert2018_automated]} found that only **7%** of privacy policies even contained the string "do not track", and of the ones that did, **64.80% explicitly said they did not honour it** against **19.46%** that committed to honouring it. Among 25 third-party data collectors, nine mentioned DNT and **none offered unqualified support**. DNT sent a ''DNT: 1'' request header and exposed ''navigator.doNotTrack''. It failed because nothing obliged anyone to honour it: Libert {[libert2018_automated]} found that only **7%** of privacy policies even contained the string "do not track", and of the ones that did, **64.80% explicitly said they did not honour it** against **19.46%** that committed to honouring it. Among 25 third-party data collectors, nine mentioned DNT and **none offered unqualified support**.
 +
 +**Where this page stops on GPC.** This section is about **setting** the signal from a crawl and reading what the site recorded. [[Privacy:Data subject rights]] owns GPC as an //opt-out right//: which statutes make it binding, the US Privacy and GPP strings that carry the opt-out onward, what the corpus has measured about whether sites honour it, and the access and deletion requests that sit beside it. If your question is "does this site comply", start there; if it is "how do I make my browser say it", stay here.
  
 It is formally dead. The W3C Tracking Protection Working Group concluded its work and republished both specifications as **W3C Working Group Notes on 17 January 2019**, saying in the status section that "there has not been sufficient deployment of these extensions (as defined) to justify further advancement".((''w3.org/TR/tracking-dnt/'', //Tracking Preference Expression (DNT)//, W3C Working Group Note 17 January 2019. Fetched 2026-08-19.)) Browsers have since diverged rather than converged: **Safari** dropped DNT alongside ITP 2.1 in 2019, and **Firefox removed the checkbox in version 135 (4 February 2025)**, whose release notes point users at "Tell websites not to sell or share my data" — which is GPC.((Mozilla, //Firefox 135.0 release notes//: "The 'Do Not Track' checkbox has been removed from preferences. If you wish to ask websites to respect your privacy, you can use the 'Tell websites not to sell or share my data' setting instead. This option is built on top of the Global Privacy Control (GPC)." Fetched 2026-08-19.)) **Chrome still exposes a DNT toggle.** If your crawl runs a default Chrome profile you may be sending ''DNT'' without meaning to; if it runs a current Firefox, the setting you find in the UI is GPC, not DNT. Check what your browser actually sends rather than what you assume. It is formally dead. The W3C Tracking Protection Working Group concluded its work and republished both specifications as **W3C Working Group Notes on 17 January 2019**, saying in the status section that "there has not been sufficient deployment of these extensions (as defined) to justify further advancement".((''w3.org/TR/tracking-dnt/'', //Tracking Preference Expression (DNT)//, W3C Working Group Note 17 January 2019. Fetched 2026-08-19.)) Browsers have since diverged rather than converged: **Safari** dropped DNT alongside ITP 2.1 in 2019, and **Firefox removed the checkbox in version 135 (4 February 2025)**, whose release notes point users at "Tell websites not to sell or share my data" — which is GPC.((Mozilla, //Firefox 135.0 release notes//: "The 'Do Not Track' checkbox has been removed from preferences. If you wish to ask websites to respect your privacy, you can use the 'Tell websites not to sell or share my data' setting instead. This option is built on top of the Global Privacy Control (GPC)." Fetched 2026-08-19.)) **Chrome still exposes a DNT toggle.** If your crawl runs a default Chrome profile you may be sending ''DNT'' without meaning to; if it runs a current Firefox, the setting you find in the UI is GPC, not DNT. Check what your browser actually sends rather than what you assume.
Line 198: Line 200:
 ^ Tool ^ What it actually does ^ State on 2026-08-19 ^ Use it when ^ ^ Tool ^ What it actually does ^ State on 2026-08-19 ^ Use it when ^
 | **Consent-O-Matic** ([[https://github.com/cavi-au/Consent-O-Matic|cavi-au/Consent-O-Matic]]), from the team behind {[nouwens2020_dark]} | Per-CMP declarative rules. The only widely used tool that can express **purpose-level** choices rather than just accept-or-dismiss | **Alive.** ''rules/'' holds **204** rule files; last commit on ''master'' **2025-11-07**; latest release **v1.1.5**, 2025-06-17 | You need ''cmp-specific-choices'', or a reject that is a real reject. Coverage is bounded by the 204 rules — everything else is untouched | | **Consent-O-Matic** ([[https://github.com/cavi-au/Consent-O-Matic|cavi-au/Consent-O-Matic]]), from the team behind {[nouwens2020_dark]} | Per-CMP declarative rules. The only widely used tool that can express **purpose-level** choices rather than just accept-or-dismiss | **Alive.** ''rules/'' holds **204** rule files; last commit on ''master'' **2025-11-07**; latest release **v1.1.5**, 2025-06-17 | You need ''cmp-specific-choices'', or a reject that is a real reject. Coverage is bounded by the 204 rules — everything else is untouched |
-| **autoconsent** ([[https://github.com/duckduckgo/autoconsent|duckduckgo/autoconsent]]) | A library, not an extension: detects the CMP and drives it. Ships **571** auto-generated and **331** hand-authored site rules | **Alive and the most actively maintained of the set.** Release **v16.23.0** on 2026-08-18; ''main'' committed the same day | You are embedding consent handling in your own crawler. It is a library with a stable API, which is what you want. Note the repo says the reference extension build is deliberately not published to stores — the functionality ships inside DuckDuckGo's own browsers |+| **autoconsent** ([[https://github.com/duckduckgo/autoconsent|duckduckgo/autoconsent]]) | A library, not an extension: detects the CMP and drives it. Ships **567** auto-generated and **356** hand-authored site rules (counted on 2026-09-05) | **Alive and the most actively maintained of the set.** Release **v16.37.0** on 2026-09-05 — fourteen releases in the eighteen days since this row first recorded v16.23.0, which is the rate you are committing to if you pin it | You are embedding consent handling in your own crawler. It is a library with a stable API, which is what you want. Note the repo says the reference extension build is deliberately not published to stores — the functionality ships inside DuckDuckGo's own browsers |
 | **BannerClick** ([[https://github.com/bannerclick/bannerclick|bannerclick/bannerclick]]) {[rasaii2023_thou]} | An **[[Programming:Crawler:OpenWPM|OpenWPM]] custom command**: detect the banner, then accept or reject it, with the detection and the interaction separable | **Alive.** Default branch ''bannerclick_v0.26.0'', last commit **2025-07-01**; a ''_pets25_artifact'' tag accompanies {[rasaii2025_crumbs]} | You are already on OpenWPM and want both arms. This is the lowest-friction path to an accept/reject design | | **BannerClick** ([[https://github.com/bannerclick/bannerclick|bannerclick/bannerclick]]) {[rasaii2023_thou]} | An **[[Programming:Crawler:OpenWPM|OpenWPM]] custom command**: detect the banner, then accept or reject it, with the detection and the interaction separable | **Alive.** Default branch ''bannerclick_v0.26.0'', last commit **2025-07-01**; a ''_pets25_artifact'' tag accompanies {[rasaii2025_crumbs]} | You are already on OpenWPM and want both arms. This is the lowest-friction path to an accept/reject design |
 | **Priv-Accept** ([[https://github.com/marty90/priv-accept|marty90/priv-accept]]) | Selenium plus a keyword heuristic. **Accept only** — there is no reject arm | **Stale.** Last commit on ''main'' **2022-04-13**. Not archived, but four years of Selenium and ChromeDriver drift stand between you and it | You want a cheap accept-all arm and are prepared to fix it. Two papers in this corpus still use it | | **Priv-Accept** ([[https://github.com/marty90/priv-accept|marty90/priv-accept]]) | Selenium plus a keyword heuristic. **Accept only** — there is no reject arm | **Stale.** Last commit on ''main'' **2022-04-13**. Not archived, but four years of Selenium and ChromeDriver drift stand between you and it | You want a cheap accept-all arm and are prepared to fix it. Two papers in this corpus still use it |
 | **CookieBlock** ([[https://github.com/dibollinger/CookieBlock|dibollinger/CookieBlock]]) {[bollinger2022automating]} | Not a banner tool. It **classifies cookies by purpose and deletes the ones you rejected** — the enforcement half, not the interaction half | **Stale, and a Manifest V2 extension.** Last commit **2023-12-08**; the crawler **2023-06-03**; the published AMO build dates from 2022 | You want purpose labels for observed cookies. See [[Privacy:Cookies|Classifying Cookies]]. Do not assume the shipped extension still loads in a current Chrome | | **CookieBlock** ([[https://github.com/dibollinger/CookieBlock|dibollinger/CookieBlock]]) {[bollinger2022automating]} | Not a banner tool. It **classifies cookies by purpose and deletes the ones you rejected** — the enforcement half, not the interaction half | **Stale, and a Manifest V2 extension.** Last commit **2023-12-08**; the crawler **2023-06-03**; the published AMO build dates from 2022 | You want purpose labels for observed cookies. See [[Privacy:Cookies|Classifying Cookies]]. Do not assume the shipped extension still loads in a current Chrome |
-| **"I don't care about cookies"** | **Hides** banners far more often than it answers them. Acquired by Avast | **Original stale** (published build last updated 2023-11). The maintained Manifest V3 successor is the community fork [[https://github.com/OhMyGuus/I-Still-Dont-Care-About-Cookies|OhMyGuus/I-Still-Dont-Care-About-Cookies]], last commit **2026-06-21** | Almost never, in research. Hiding a banner is ''dismiss-or-remove'', not consent — see the warning below |+| **"I don't care about cookies"** | **Hides** banners far more often than it answers them. Acquired by Avast | **Original stale** (the Firefox build on addons.mozilla.org is **v3.5.0**, last updated **2023-12-06**, checked 2026-09-05). The maintained Manifest V3 successor is the community fork [[https://github.com/OhMyGuus/I-Still-Dont-Care-About-Cookies|OhMyGuus/I-Still-Dont-Care-About-Cookies]], last commit **2026-06-21** | Almost never, in research. Hiding a banner is ''dismiss-or-remove'', not consent — see the warning below |
 | **Ninja Cookie** | Rule-driven banner rejection | **Abandoned.** The project domain is parked, the GitLab repository has been silent since **2022-02**, and the Firefox listing is gone | Never. It appears in {[demir2024_bannertools]}, which is why it is here — do not carry it forward from that paper into a 2026 crawl | | **Ninja Cookie** | Rule-driven banner rejection | **Abandoned.** The project domain is parked, the GitLab repository has been silent since **2022-02**, and the Firefox listing is gone | Never. It appears in {[demir2024_bannertools]}, which is why it is here — do not carry it forward from that paper into a 2026 crawl |
 | **Super Agent** | Commercial, closed-source consent automation | Live commercial product | Not as a research instrument: you cannot pin its version or read its rules | | **Super Agent** | Commercial, closed-source consent automation | Live commercial product | Not as a research instrument: you cannot pin its version or read its rules |
Line 364: Line 366:
   * **Free-text names were folded before counting, and the residue is printed.** The consent-tool fold leaves 5 distinct unmapped names over 5 papers, all of them IAB artefacts that are not banner-interaction tools (''IAB ads.txt crawler'', ''IAB anti-ad-block script'', the IAB content taxonomy). The law fold leaves 2 (''Digital Economy Act 2017'', ''Act against Unfair Competition (UWG)''). The vantage fold leaves 5 strings that name no place (''different continents'', ''various geographic regions'').   * **Free-text names were folded before counting, and the residue is printed.** The consent-tool fold leaves 5 distinct unmapped names over 5 papers, all of them IAB artefacts that are not banner-interaction tools (''IAB ads.txt crawler'', ''IAB anti-ad-block script'', the IAB content taxonomy). The law fold leaves 2 (''Digital Economy Act 2017'', ''Act against Unfair Competition (UWG)''). The vantage fold leaves 5 strings that name no place (''different continents'', ''various geographic regions'').
   * **Every per-paper figure on this page was checked against the paper's own text**, not against the extraction's summary of it. The check covers 61 literals — a superset of what is published, since ten were checked and then cut — and found 60 in both the column-repaired and the plain rendering, 1 in the column-repaired rendering only, and **0 not found**. That pass caught two errors in an earlier draft of this page — a figure attributed to Bouhoula et al. that the paper writes without a thousands separator, and a Matte et al. percentage this page had rounded to the wrong decimal.   * **Every per-paper figure on this page was checked against the paper's own text**, not against the extraction's summary of it. The check covers 61 literals — a superset of what is published, since ten were checked and then cut — and found 60 in both the column-repaired and the plain rendering, 1 in the column-repaired rendering only, and **0 not found**. That pass caught two errors in an earlier draft of this page — a figure attributed to Bouhoula et al. that the paper writes without a thousands separator, and a Matte et al. percentage this page had rounded to the wrong decimal.
-  * **''consentAction'' was audited paper by paper, in both directions, and it needed to be.** The schema's stability comparison puts it in the reliable band — an independent extraction run over the same text agrees with it on 93% of papers — but that measures whether two runs agree, not whether either is right, and it was measured on the earlier 4,322-paper corpus. Reading all 36 interacting papers found **7 false positives (19.4%)**, concentrated in ''accept-all'' and ''dismiss-or-remove''. Reading all 313 ''no-interaction'' papers found **279 (89.1%) that make no consent claim at all** and **3 (1.0%) that in fact interact**. The two error modes are different in kind: on the interacting side the extractor misreads a word, on the ''no-interaction'' side it supplies a default where the paper is silent — which is why the second error is twenty times more common and matters more, since it is what inflates every "share of papers that report X" figure. **Note also that the field's own evidence quote cannot catch either**: ''crawlConfig'' carries one quote for the whole configuration object, so the quote behind a ''consentAction'' value usually evidences statefulness or crawl depth instead. Spot-checking quotes, which is the standard check on this site, is structurally blind here.+  * **''consentAction'' was audited paper by paper, in both directions, and it needed to be.** The schema's stability comparison puts it in the reliable band — an independent extraction run over the same text agrees with it on 93% of papers — but that measures whether two runs agree, not whether either is right, and it was measured on the earlier 4,322-paper corpus. Reading all 36 interacting papers found **7 false positives (19.4%)**, concentrated in ''accept-all'' and ''dismiss-or-remove''. Reading all 313 ''no-interaction'' papers found **279 (89.1%) that make no claim about their own crawl's consent action** and **3 (1.0%) that in fact drove a notice**. The two error modes are different in kind: on the interacting side the extractor misreads a word, on the ''no-interaction'' side it supplies a default where the paper is silent — which is why the second error is twenty times more common and matters more, since it is what inflates every "share of papers that report X" figure. **Note also that the field's own evidence quote cannot catch either**: ''crawlConfig'' carries one quote for the whole configuration object, so the quote behind a ''consentAction'' value usually evidences statefulness or crawl depth instead. Spot-checking quotes, which is the standard check on this site, is structurally blind here.
   * **Venue coverage.** Seven venues only. **CHI, SOUPS, EuroS&P, ACSAC, RAID, AsiaCCS and WPES are absent**, and that bites harder on this page than on most: the usable-privacy half of the consent literature (Nouwens et al., Habib et al., Utz et al.'s follow-ups) is largely CHI and SOUPS work. Every count here is a lower bound.   * **Venue coverage.** Seven venues only. **CHI, SOUPS, EuroS&P, ACSAC, RAID, AsiaCCS and WPES are absent**, and that bites harder on this page than on most: the usable-privacy half of the consent literature (Nouwens et al., Habib et al., Utz et al.'s follow-ups) is largely CHI and SOUPS work. Every count here is a lower bound.
  
Line 391: Line 393:
   * **Consent revocation is nearly unstudied.** One paper {[kancherla2025_johnny]}, 158 sites. Withdrawal is as legally required as consent and is far harder to automate.   * **Consent revocation is nearly unstudied.** One paper {[kancherla2025_johnny]}, 158 sites. Withdrawal is as legally required as consent and is far harder to automate.
   * **No shared benchmark exists.** There is no public, versioned set of annotated consent notices that a new detector can report against, which is why every paper reports precision and recall on its own hand-labelled sample and none of them are comparable. Building one would be a bigger contribution than most new detectors.   * **No shared benchmark exists.** There is no public, versioned set of annotated consent notices that a new detector can report against, which is why every paper reports precision and recall on its own hand-labelled sample and none of them are comparable. Building one would be a bigger contribution than most new detectors.
-  * **The reporting gap itself.** 44.2% of crawling papers say nothing about consent, and the share that says //something// is no higher in 2025–2026 than it was in 2014–2017. A one-line methods sentence would fix it; the question is why sixteen years of the field have not produced one.+  * **The reporting gap itself.** On the audited figures, **94.4% of crawling papers leave the reader unable to tell what their crawl did with a notice**, and the share that does say is under one in ten even in the newest bucket. A one-line methods sentence would fix it; the question is why sixteen years of the field have not produced one. (The 44.2% ''not-stated'' row is the extraction's own count for that population and was **not** audited — after what the ''no-interaction'' audit found, no unaudited row on this page should be read as a claim about the papers.)
   * **All 349 papers the extraction credits with a stated consent action have now been read**, so the figures above are hand verdicts rather than extractor output. What that cannot fix is the other direction: a paper that clicked a banner and never wrote it down is invisible here by construction, and the 495 ''not-stated'' and 236 ''not-applicable'' papers were **not** read — a false ''not-stated'' would be a further undercount. **32 is a floor on the true number of interacting papers, not an estimate of it.** Two of the three false negatives were found only because a named tool (BannerClick, CookieEnforcer) appears in the text; a paper that rolled its own clicking and described it in one unremarkable sentence would still be missed.   * **All 349 papers the extraction credits with a stated consent action have now been read**, so the figures above are hand verdicts rather than extractor output. What that cannot fix is the other direction: a paper that clicked a banner and never wrote it down is invisible here by construction, and the 495 ''not-stated'' and 236 ''not-applicable'' papers were **not** read — a false ''not-stated'' would be a further undercount. **32 is a floor on the true number of interacting papers, not an estimate of it.** Two of the three false negatives were found only because a named tool (BannerClick, CookieEnforcer) appears in the text; a paper that rolled its own clicking and described it in one unremarkable sentence would still be missed.
 </WRAP> </WRAP>
Line 399: Line 401:
   * [[Privacy:Requests#Cookie Notices and Their Interactive Elements|Classifying Web Requests]] — detecting the notice and labelling its buttons, with the comparison table of detectors.   * [[Privacy:Requests#Cookie Notices and Their Interactive Elements|Classifying Web Requests]] — detecting the notice and labelling its buttons, with the comparison table of detectors.
   * [[Privacy:Cookies|Classifying Cookies]] — what the cookies you observe before and after the click actually are, and the CookieBlock/Cookiepedia label sources.   * [[Privacy:Cookies|Classifying Cookies]] — what the cookies you observe before and after the click actually are, and the CookieBlock/Cookiepedia label sources.
 +  * [[Privacy:Policies|Measuring Privacy Policies and Terms]] — the long document behind the banner. A banner is a UI measurement; a policy is a document-retrieval and NLP measurement, with its own tool lineage and its own denominators, and the two literatures barely cite each other.
   * [[Privacy:TCF Consent Strings|Decoding TCF Consent Strings]] — the TC string and Google's Additional Consent string as artefacts: bit layout, where they hide, decoding them reproducibly, and what they do and do not prove.   * [[Privacy:TCF Consent Strings|Decoding TCF Consent Strings]] — the TC string and Google's Additional Consent string as artefacts: bit layout, where they hide, decoding them reproducibly, and what they do and do not prove.
   * [[Programming:Interaction|Interaction with websites]] and [[Programming:Stateful Stateless|Stateful and stateless crawling]] — the crawler-side mechanics this page assumes.   * [[Programming:Interaction|Interaction with websites]] and [[Programming:Stateful Stateless|Stateful and stateless crawling]] — the crawler-side mechanics this page assumes.
   * [[Programming:Crawler|Comparison of crawling libraries]] — which crawlers ship a consent-interaction step.   * [[Programming:Crawler|Comparison of crawling libraries]] — which crawlers ship a consent-interaction step.
   * [[Design:Crawling location|Crawling location]] — why the vantage point changes which banner you get.   * [[Design:Crawling location|Crawling location]] — why the vantage point changes which banner you get.
 +  * [[Privacy:Age assurance|Age assurance]] — the other dismissable overlay on the first load, and one that usually writes a cookie //before// the banner is touched, so it is a confounder for anything counted pre-consent.
   * [[Practices:Legal enforcement|Legal enforcement]] — what to do with a violation once you have found one, and which authority is competent.   * [[Practices:Legal enforcement|Legal enforcement]] — what to do with a violation once you have found one, and which authority is competent.
   * [[Practices:Ethics|Ethics]] — clicking //Accept// at scale on behalf of nobody is a decision with an ethical dimension; it is discussed there.   * [[Practices:Ethics|Ethics]] — clicking //Accept// at scale on behalf of nobody is a decision with an ethical dimension; it is discussed there.
privacy/consent.1788638479.txt.gz · Last modified: by karel.kubicek.claude