2021
DOI: 10.2478/popets-2022-0030
|View full text |Cite
|
Sign up to set email alerts
|

Setting the Bar Low: Are Websites Complying With the Minimum Requirements of the CCPA?

Abstract: On June 28, 2018, the California State Legislature passed the California Consumer Privacy Act (CCPA), arguably the most comprehensive piece of online privacy legislation in the United States. Online services covered by the CCPA are required to provide a hyperlink on their homepage with the text “Do Not Sell My Personal Information” (DNSMPI). The CCPA went into effect on January 1, 2020, a date that was chosen to give data collectors time to study the new law and bring themselves into compliance. … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
2
1

Citation Types

0
33
0

Year Published

2022
2022
2024
2024

Publication Types

Select...
3
2
1

Relationship

0
6

Authors

Journals

citations
Cited by 15 publications
(33 citation statements)
references
References 41 publications
(55 reference statements)
0
33
0
Order By: Relevance
“…Prior research has identified that online services design unintuitive and hard to navigate interfaces [39,52], trick users into giving positive consent [59], and do not include controls to opt-out of data selling [67]. Alizadeh et al [39] conducted a user study to understand data rights under GDPR and identified that the participants find data access interfaces unintuitive and hard to navigate.…”
Section: Related Workmentioning
confidence: 99%
See 4 more Smart Citations
“…Prior research has identified that online services design unintuitive and hard to navigate interfaces [39,52], trick users into giving positive consent [59], and do not include controls to opt-out of data selling [67]. Alizadeh et al [39] conducted a user study to understand data rights under GDPR and identified that the participants find data access interfaces unintuitive and hard to navigate.…”
Section: Related Workmentioning
confidence: 99%
“…Specifically, websites often register consent before the user has made any choice, register positive consent regardless of user's choice, or nudge users to give pre-selected positive consent. More recently, Nortwick and Wilson [67], conducted a measurement study of top 500K English websites and identified that only 2% of the websites provided controls to users to opt-out of data selling, i.e., "Do Not Sell My Personal Information" (DNSMPI), under CCPA.…”
Section: Related Workmentioning
confidence: 99%
See 3 more Smart Citations