User Tools

Site Tools


privacy:fingerprinting

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
privacy:fingerprinting [2026/09/03 03:33] – Fable generic review (step 9): fix refuted consent open question (Papadogiannakis 2021 ran it: 27,180 CMP sites, 279/285/330 by consent action); attribute the crawl-gap size to FP-Fed's top-300 pilot as well as Annamalai 2025; date the measurement surface karel.kubicek.claudeprivacy:fingerprinting [2026/09/04 17:29] (current) – Citekey consolidation 2026-09-04: repoint duplicate bibliography keys (fouad2022my/boettger2025_regional/ahmad2026_ipfp/bouhoula2024automated/lerner2016internet) to the kept key; no prose or figure changed. Authored by Claude karel.kubicek.claude
Line 226: Line 226:
 ==== Legal framing is rare ==== ==== Legal framing is rare ====
  
-Only **10 of 83** papers (12.0%) assess a law, against 6.9% corpus-wide (402 of 5,859) — so not quite twice the corpus rate, and still an outlier practice. Folded, the laws are GDPR (9 papers) and the ePrivacy Directive (4 papers, appearing under three different spellings including "European directives 2002/58/CE and 2009/136/CE"), then CCPA (3), plus one each of the UK Digital Economy Act, Brazil's LGPD, COPPA and the DSA. The papers that do it are the ones joining fingerprinting to consent: cookie respawning with fingerprinting {[fouad2022my]}, and post-cookie tracking that bypasses a GDPR consent choice {[papadogiannakis2021_user]}.+Only **10 of 83** papers (12.0%) assess a law, against 6.9% corpus-wide (402 of 5,859) — so not quite twice the corpus rate, and still an outlier practice. Folded, the laws are GDPR (9 papers) and the ePrivacy Directive (4 papers, appearing under three different spellings including "European directives 2002/58/CE and 2009/136/CE"), then CCPA (3), plus one each of the UK Digital Economy Act, Brazil's LGPD, COPPA and the DSA. The papers that do it are the ones joining fingerprinting to consent: cookie respawning with fingerprinting {[fouad2022_cookie]}, and post-cookie tracking that bypasses a GDPR consent choice {[papadogiannakis2021_user]}.
  
 This is a gap, not a finding about the law. Fingerprinting has no consent API, so the compliance question — can a technique that cannot be refused ever rest on consent? — is squarely open, and became sharper in 2025 (see below). See [[Privacy:Consent]] and [[Practices:Legal enforcement]]. This is a gap, not a finding about the law. Fingerprinting has no consent API, so the compliance question — can a technique that cannot be refused ever rest on consent? — is squarely open, and became sharper in 2025 (see below). See [[Privacy:Consent]] and [[Practices:Legal enforcement]].
Line 574: Line 574:
 ===== Related Pages ===== ===== Related Pages =====
  
-  * [[Privacy:Cookies]] — the stateful counterpart; fingerprinting and cookies are used together, and respawning links them directly {[fouad2022my]}.+  * [[Privacy:Cookies]] — the stateful counterpart; fingerprinting and cookies are used together, and respawning links them directly {[fouad2022_cookie]}.
   * [[Privacy:JavaScript]] — classifying the scripts that 39.8% of these papers are actually detecting.   * [[Privacy:JavaScript]] — classifying the scripts that 39.8% of these papers are actually detecting.
   * [[Privacy:Requests]] — the filter lists that most of this literature uses as ground truth, and why that is a compromise.   * [[Privacy:Requests]] — the filter lists that most of this literature uses as ground truth, and why that is a compromise.
privacy/fingerprinting.1788406426.txt.gz · Last modified: by karel.kubicek.claude