Subscription Management Platforms under the GDPR

dc.contributor.authorRosengren, Björn
dc.contributor.authorSjögren, Sebastian
dc.contributor.departmentChalmers tekniska högskola / Institutionen för data och informationstekniksv
dc.contributor.departmentChalmers University of Technology / Department of Computer Science and Engineeringen
dc.contributor.examinerRusso, Alejandro
dc.contributor.supervisorMorell, Victor
dc.date.accessioned2025-05-21T11:02:43Z
dc.date.issued2024
dc.date.submitted
dc.description.abstractIn recent times there has been an increase in cookie tracking, where users’ data are collected through web cookies. Due to privacy concerns, many regulations have been developed — such as the General Data Protection Regulation (GDPR) —, to regulate information gathering. To ensure compliance with the GDPR, cookies tend to be managed through cookie banners, where users can 1) accept all, 2) reject all, or 3) customize their choice regarding which data can be collected. Recently, there has developed a new cookie paywall, where instead the choices are to either 1) accept all tracking or 2) subscribe to a service to avoid tracking and advertisements. The services providing these cookie paywalls have been named Subscription Management Platforms (SMPs), and the goal of this thesis is to discover what SMPs are technically and legally under the GDPR, and how they relate to standard cookie banners. The results show that SMPs can work as a wrapper to existing cookie banners, where all subscribed users automatically reject all cookies but the non-subscribed must accept all cookies. In this case, the legal responsibility falls to the cookie banner, as the SMP does not handle the consent signal. Additionally, we found that SMPs can collect at least as much information and personal data as regular cookie banners. We also raise several questions about the nature and ethics of SMPs. As SMPs force users who do not pay to accept all tracking, they essentially make privacy a luxury and may increase cookie tracking.
dc.identifier.coursecodeDATX05
dc.identifier.urihttp://hdl.handle.net/20.500.12380/309313
dc.language.isoeng
dc.relation.ispartofseriesCSE 24-106
dc.setspec.uppsokTechnology
dc.subjectCookies, Cookie tracking, SMP, CMP, GDPR, CNAME cloaking, contentpass
dc.titleSubscription Management Platforms under the GDPR
dc.type.degreeExamensarbete för masterexamensv
dc.type.degreeMaster's Thesisen
dc.type.uppsokH
local.programmeComputer science – algorithms, languages and logic (MPALG), MSc

Ladda ner

Original bundle

Visar 1 - 1 av 1
Hämtar...
Bild (thumbnail)
Namn:
CSE 24-106 BR SS.pdf
Storlek:
1.65 MB
Format:
Adobe Portable Document Format

License bundle

Visar 1 - 1 av 1
Hämtar...
Bild (thumbnail)
Namn:
license.txt
Storlek:
2.35 KB
Format:
Item-specific license agreed upon to submission
Beskrivning: