- What frameworks are top publishers adopting? GPP? USP?
- Do publishers that have adopted the Global Privacy Platform (GPP) handle the Opt Out signal correctly?
- How is user preference handled differently across states? Which state privacy laws apply to a given publisher?
(incomplete)
-
gather a csv dataset of top publishers from Tranco (https://tranco-list.eu/)
- determine number of top publishers to crawl (1M or 10K)
- narrow down list (only websites that load ??)
- consider also adding domains of common data brokers (see methodology)
Methodology
Johnny Still Can’t Opt-out: Assessing the IAB CCPA Compliance Framework
To gather data for this study, we chose to crawl the top 10 K domains from the Tranco list [36].7 We focus on the top 10 K domains because Van Nortwick and Wilson [60] found that the CCPA and CPRA were unlikely to apply to websites that fell below this level of popularity since they did not receive enough unique visitors from California to meet the laws’ eligibility criteria (see § 2.3).
That said, the CCPA and CPRA may not apply to all domains in this list—e.g., domains owned by non-pro�t organizations—and thus we refrain from asserting whether speci�c websites are in compliance with the CCPA or CPRA (see § 3.5). Rather, the goal of our study is to assess the overall adoption of the CCPA Framework and �ows of consent information, a goal for which it is su�cient for us to cover popular websites.
Setting the Bar Low: Are Websites Complying With the Minimum Requirements of the CCPA?
To build our corpus, we joined the top 1 million domains from the research-oriented Tranco6 domain popularity ranking [60]...
... with 2,902 domains that were identified as third-party trackers and/or advertisers by Bashir et al. [15].7
To further narrow this list, we performed an initial crawl in which we attempted to resolve each domain to a website, scrape its homepage, extract the page’s text, and then analyze the text with the Python langdetect library. Our crawler failed to retrieve a non-empty webpage from 267,718 (27%) of the domains in our initial list due to a variety of errors, including DNS resolution failure, connection failures, TLS errors, and HTTP 4XX and 5XX responses...
Our final corpus of 497,870 domains includes those that successfully returned an HTML webpage containing English text.
Initial Challenges : What string do we look for in a website to detect presence of GPP, and where do we look for it? Headers, console, cookies?
- First try : Use console to run the following script : try { __gpp('ping', (data, success) => { console.log(data); }); } catch (error) { console.log(error); } Two possible responses: - Something similar to this : Pt {gppVersion: '1.1', cmpStatus: 'loaded', cmpDisplayStatus: 'hidden', signalStatus: 'ready', supportedAPIs: Array(9), …} - An error -
establish an IP address
- by default, use a California VPN to assess widespread adoption; focus on state-level analysis later
Methodology
Setting the Bar Low: Are Websites Complying With the Minimum Requirements of the CCPA?
All crawls were conducted using virtual machines from Amazon Web Services with IP addresses in California.
We assessed the impact of anti-crawler countermeasures on our crawler by manually revisiting 200 randomly selected websites, weighted by Tranco rank, from Crawl 3 and Crawl 4, using the same IP addresses as the crawler used.
-
determine which websites use GPP/USP
- preliminary work needed for general information (cookies, inclusion trees, etc)
Preliminary Work Methodology
Johnny Still Can’t Opt-out: Assessing the IAB CCPA Compliance Framework
We used custom scripts, written in Python and JavaScript, to drive and instrument an instance of Chrome8 using the Chrome DevTools Protocol [13]. We left Chrome at its default settings, except during crawls where we varied HTTP headers, as described below.
During each crawl of the Tranco top 10 K, our crawler visited each domain one-by-one. For each domain, we programmed the crawler to load the domain’s homepage,9 scroll to the bottom of the page, then sleep for 25 seconds. Further, we programmed our crawler to select nine internal hyperlinks at random from the home-page and crawl them using the same load, scroll, and sleep approach.
inclusion trees
Our crawler recorded detailed information during each visit to a webpage, including all HTTP request and response headers and all cookies that were set. Furthermore, our crawler recorded the resource inclusion tree for each webpage [3, 6]... We decompose the inclusion tree for each webpage into inclusion chains, where each chain corresponds to a unique path from root to leaf in the given tree [5].
Furthermore... we isolated A&A chains that correspond to the serving of an ad or a tracker. We label a given inclusion chain as an A&A chain if (1) there was at least one HTTP request in the chain that matched a rule in the EasyList or EasyPrivacy block lists,10 or (2) the chain terminated in the loading of a 1⇥1 tracking pixel [21]. We use these A&A chains in § 4 to analyze the sources and destinations of HTTP requests that included the USP String, i.e., to understand how this consent signal is being passed from one party to another.
manual verification and accounting for error (extra)
We assessed the impact of anti-crawler countermeasures on our crawler by manually revisiting 200 randomly selected websites, weighted by Tranco rank... using the same IP addresses as the crawler used. We received CAPTCHA challenges on two of the websites that prevented them from loading normally. Thus, we estimate that around 1% of websites in our sample were impacted by anti-crawler countermeasures.
USP API Detection Methodology
Johnny Still Can’t Opt-out: Assessing the IAB CCPA Compliance Framework
CCPA framework and recommendations
Specifcally, the CCPA Framework requires that a JavaScript method called
__uspapi()be instantiated in the first-party context. This method must support agetUSPDatacommand that returns auspDataobject containing the USP String [31]. This method can be called directly by third parties present in the first-party context, or indirectly using the JavaScriptpostMessageDOM API to communicate with a special__uspapiLocatoriframe.The CCPA Framework recommends that the USP String be stored in a first-party cookie named
usprivacyand that it be shared using a URL parameter with the nameus_privacy.detecting USP API
To understand which publishers support this API and what default value the USP String had been set to, we programmed our crawler to inject a content script into the first- party execution context of each crawled webpage 25 seconds after loading the page. Our script first attempted to detect the presence of the
__uspapi()method. If it was present, then our script called the method and recorded the resulting USP String.manual verification and accounting for error (extra)
To assess false positives we randomly selected 50 websites, weighted by Tranco rank... where our crawler detected the USP API and revisited them manually in Chrome using an IP address in California. Our crawler successfully detected the USP API on 49 websites, yielding a false positive rate of 2%. Furthermore, the value of the USP String recorded by our crawler matched our manual observation of the value (in the Chrome developer tools) of the USP String in 96% of cases... To assess false negatives we randomly selected 50 websites, weighted by Tranco rank, from Crawl 4 where our crawler did not detect the USP API and did detect at least one embedded resource from an A&A company. We manually revisited these websites and found zero false negatives.
extra analysis for cookies (probably unneeded)
To understand which parties were writing first-party cookies, we instrumented our crawler to record all accesses to the DOM
cookie.setmethod...GPP API Detection Methodology
Similarly to the CCPA Framework, GPP specifies that every consent manager must provide the
__gppAPI function. https://github.com/InteractiveAdvertisingBureau/Global-Privacy-Platform/blob/main/Core/CMP%20API%20Specification.mdEvery consent manager must provide the following API function:
__gpp(command, callback, parameter, [version])Requirements for the interface:
- The
__gppfunction must always be a function and cannot be any other type, even if only temporarily on initialization – the API must be able to handle calls at all times. - The command must always be a string.
- The callback must always be a function.
- Parameter can be of mixed type depending on used command
- The
__gppfunction does not have a return value - If a CMP cannot immediately respond to a query, the CMP must queue all calls to the function and execute them later. The CMP must execute the commands in the same order in which the function was called.
- A CMP must support all generic commands. All generic commands must always be available when a
__gppfunction is present on the page. This means that “stub code” that supports all generic commands must be in place before/during CMP load.
The
pingcommand can be used to determine the state of the CMP. The callback shall be called with a PingReturn object as the value of thedataparameter. A value offalsewill be passed as the argument to thesuccessparameter if the CMP fails to process this command.argument type value commandstring "ping" callbackfunction function (data: PingReturn, success: boolean) parameternot used Example:
__gpp('ping', myFunction);
This object contains information about the loading status and configuration of the CMP.
PingReturn = { gppVersion : String, // must be “Version.Subversion”, current: “1.1” cmpStatus : String, // possible values: stub, loading, loaded, error cmpDisplayStatus: String, // possible values: hidden, visible, disabled signalStatus : String, // possible values: not ready, ready // List of supported APIs (section ids and prefix strings). // Example: ["2:tcfeuv2","6:uspv1"] supportedAPIs : Array of string, // IAB assigned CMP ID, may be 0 during stub/loading. Refer the above CMP ID section for additional information. cmpId : Number, sectionList : Array of Number, // may be empty during loading of the CMP // Section ID considered to be in force for this transaction. // In most cases, this field should have a single section ID. In rare occasions where such a single section ID // can not be determined, the field may contain up to 2 values. During the transition period which ends on // September 30, 2023, the legacy USPrivacy section may be determined as applicable along with another US section. // In this case, the field may contain up to 3 values where one of the values is 6, representing the // legacy USPrivacy section. The value can be 0 or a Section ID specified by the Publisher / Advertiser, during // stub / load. // When no section is applicable, the value will be [-1]. applicableSections: Array of Number, gppString: String // the complete encoded GPP string, may be empty during CMP load // The parsedSections property represents an object of all parsed sections of the gppString property that are supported // by the API on this page (see supportedAPIs property). The object contains one property for each supported API with // the name of the API as the property name and the value as a parsed representation of this section with exactly the // same return as the getSection command, which may include subsections. If a section is supported but not represented // in the gppString, it is omitted in the parsedSections object. // Please refer to each section's spec for the exact field names and data types in JavaScript. The sections here should // be consistent with the GPP string, not placeholder values. parsedSections: Object }
-
Compile csv dataset of publishers who use the GPP API.
-
Data Analysis
Methodology
(incomplete)
Crawl 2 Tasks - Do publishers that have adopted GPP handle the Opt Out signal correctly? (API OPT-OUT)
- gather csv of publishers who use GPP API (dependent on dataset aquired from Crawl 1)
Crawl 3 Tasks - Do publishers that have adopted GPP handle the Opt Out signal correctly? (GPC OPT-OUT)
-
gather csv of publishers who use GPP API (dependent on dataset aquired from Crawl 1)
- same methodology from Crawl 2, except use GPC for opt-out
Methodology
Johnny Still Can’t Opt-out: Assessing the IAB CCPA Compliance Framework
During Crawl 3, we enabled GPC in our crawler by adding the
Sec-GPC: 1header to all HTTP requests and setting the navigator.globalPrivacyControlproperty to true. We manually validated our crawler’s ability to detect the USP API when GPC was enabled. To assess false positives we randomly selected 50 websites, weighted by Tranco rank, from Crawl 3 where our crawler had detected the USP API. We manually revisited these websites using an IP address in California and enabled GPC in our browser. Our crawler successfully detected the USP API on 47 websites, yielding a false positive rate of 6%. Additionally, we confirmed that the GPC functionality of our crawler worked by having it visit the offcial GPC validation website [24].In Crawl 3, when GPC was enabled, 380 out of 825 (46.1%) publishers with the USP API set the USP String to opt-out.20 ... Collectively, these results suggest that some publishers are reacting to the GPC signal by correctly setting the USP String to opt-out—thus helping to convey the users’ opt-out intent to third parties— but more than half are not.
-
gather csv of publishers who use GPP API (dependent on dataset aquired from Crawl 1)
-
establish an IP address
- there will be IP addresses from different states that complete this crawl
-
inject simulated GPP API before webpage loads
-
similar to Crawl 2 in seeing if correct state-specific information is being passed to third-parties through cookies and url parameters... (more research needed)
This analysis can be accomplished independently of any crawls.
- determine state laws for compliance (3 different qualifiers)
- gather user count data from external resource $$$
- gather state populations
- complete analysis based on population assumptions
(incomplete)(copy over from Project Proposal)
- https://github.com/InteractiveAdvertisingBureau/Global-Privacy-Platform/blob/main/Core/Consent%20String%20Specification.md
- https://github.com/InteractiveAdvertisingBureau/Global-Privacy-Platform/blob/main/Core/CMP%20API%20Specification.md
- https://github.com/IABTechLab/iabgpp-es more specific documentation
- https://github.com/InteractiveAdvertisingBureau/Global-Privacy-Platform/pull/130/files#diff-9f74c1a0c743e0806094e699709db1dcce8eb54e56b25d34608e0cce715759b1 un-merged GPP Implementation Guidelines
-Johnny Still Can't Opt Out
-A Study of GDPR Compliance under the Transparency and Consent Framework
-Websites’ Global Privacy Control Compliance at Scale and over Time