[go: up one dir, main page]
More Web Proxy on the site http://driver.im/ skip to main content
10.1145/3463676.3485603acmconferencesArticle/Chapter ViewAbstractPublication PagesccsConference Proceedingsconference-collections
research-article

In-Depth Technical and Legal Analysis of Tracking on Health Related Websites with ERNIE Extension

Published: 15 November 2021 Publication History

Abstract

Searching the Web to find doctors and make appointments online is a common practice nowadays. However, simply visiting a doctors website might disclose health related information. As the GDPR only allows processing of health data with explicit user consent, health related websites must ask consent before any data processing, in particular when they embed third party trackers.Admittedly, it is very hard for owners of such websites to both detect the complex tracking practices that exist today and to ensure legal compliance.
In this paper, we present ERNIE, a browser extension we designed to visualise six state-of-the-art tracking techniques based on cookies. Using ERNIE, we analysed 385 health related websites that users would visit when searching for doctors in Germany, Austria, France, Belgium, and Ireland. More specifically, we explored the tracking behavior before any interaction with the consent pop-up and after rejection of cookies on websites of doctors, hospitals, and health related online phone-books. We found that at least one form of tracking occurs on 62% of the websites before interacting with the consent pop-up, and 15% of websites include tracking after rejection. Finally, we performed a detailed technical and legal analysis of three health related websites that demonstrate impactful legal violations.
This paper shows that while, from a legal point of view, health related websites are more privacy-sensitive than other kinds of websites, they are exposed to the same technical difficulties to implement a legally compliant website. We believe ERNIE, the browser extension we developed, to be an invaluable tool for policy-makers and regulators to improve detection and visualization of the complex tracking techniques used on these websites.

Supplementary Material

MP4 File (WPES21-wpes18.mp4)
This presentation on the paper ?In-Depth Technical and Legal Analysis of Tracking on Health Related Websites with ERNIE Extension? introduces the Firefox and Chrome extension ERNIE and presents a study of tracking on health related websites in five European countries.

References

[1]
Alexa Top Sites. https://www.alexa.com/topsites.
[2]
Alexa websites visited. https://www.dropbox.com/sh/nwjw7ggcx08o1x7/ AACYrHqsxo7DcZjbVArE5Fxua?dl=0.
[3]
Contextual Identities. https://developer.mozilla.org/en-US/docs/Mozilla/Add- ons/WebExtensions/API/contextualIdentities.
[4]
Cookie Guide. https://developers.google.com/authorized-buyers/rtb/cookie-guide.
[5]
Enhanced tracking protection in Firefox for desktop. https://support.mozilla.org/ en-US/kb/enhanced-tracking-protection-firefox-desktop.
[6]
Google Cookie Types. https://policies.google.com/technologies/types.
[7]
List of websites visited. https://www.dropbox.com/s/l1ebx791ipp12xn/visited_ urls.txt?dl=0.
[8]
Pupeteer. https://github.com/puppeteer/puppeteer.
[9]
Guidance on the use of cookies and similar technologies, 2019. https://ico.org.uk/media/for-organisations/guide-to-pecr/guidance-on-the-use-of-cookies-and-similar-technologies-1-0.pdf.
[10]
Judgment in Case C-673/17 Bundesverband der Verbraucherzentralen und Ver- braucherverbände -- Verbraucherzentrale Bundesverband eV v Planet49 GmbH, 2019. http://curia.europa.eu/juris/documents.jsf?num=C-673/17.
[11]
118000.fr website. https://www.118000.fr/v_paris_75/c_gynecologue-obstetricien-medecin-specialiste-en-gynecologie-obstetrique.
[12]
29WP Opinion 03/2016 on the evaluation and review of the ePrivacy Directive (2002/58/EC), Adopted on 19 July 2016,. https://ec.europa.eu/justice/article- 29/documentation/opinion-recommendation/files/2016/wp240_en.pdf.
[13]
Gunes Acar, Christian Eubank, Steven Englehardt, Marc Juárez, Arvind Narayanan, and Claudia Díaz. The Web Never Forgets: Persistent Tracking Mechanisms in the Wild. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security, pages 674--689, 2014.
[14]
Guide on use of cookies, 2021. https://www.aepd.es/sites/default/files/2021- 01/guia-cookies-en.pdf.
[15]
Article 29 Working Party. Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation 2016/679 (WP251 rev.01).
[16]
Article 29 Working Party. Guidelines on Personal data breach notification under Regulation 2016/679. https://ec.europa.eu/newsroom/article29/items/612052/en.
[17]
Article 29 Working Party. Opinion 04/2012 on Cookie Consent Exemption (WP 194).
[18]
Article 29 Working Party. WP 248 Guidelines on Data Protection Impact Assessment (DPIA) and determining whether processing is ?likely to result in a high risk" for the purposes of Regulation 2016/679.
[19]
Bing policy. https://www.timeshighereducation.com/cookie-policy.
[20]
European Data Protection Board. Guidelines 03/2020 on the processing of data concerning health for the purpose of scientific research in the context of the COVID-19 outbreak, Adopted on 21 April 2020. https://edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines_ 202003_healthdatascientificresearchcovid19_en.pdf.
[21]
J. Cabañas, Ángel Cuevas, and R. C. Rumín. Unveiling and Quantifying Facebook Exploitation of Sensitive Personal Data for Advertising Purposes. In USENIX Security Symposium, 2018.
[22]
Microsoft Clarity Cookie List. https://docs.microsoft.com/en-us/clarity/cookie- list, accesed 16. July 2021.
[23]
CNIL: Délibération de la formation restreinte n°san-2020-008 du 18 novembre 2020 concernant la société CARREFOUR FRANCE. https://www.legifrance.gouv. fr/cnil/id/CNILTEXT000042563756. Accessed on 19 March, 2021.
[24]
Qu'est-ce ce qu'une donnée de santé? https://www.cnil.fr/fr/quest-ce-ce-quune- donnee-de-sante. Accessed on 18 May 2021.
[25]
Code de la santé publique, version in effect as of February 27, 2021. https: //www.legifrance.gouv.fr/codes/article_lc/LEGIARTI000036515027/. Translated with DeepL https://www.deepl.com on February 27, 2021.
[26]
Commission Nationale de l'Informatique et des Libertés (French DPA). French guidelines on cookies: Deliberation No 2020-091 of September 17, 2020 adopting guidelines relating to the application of article 82 of the law of January 6, 1978 amended to read and write operations in a user's terminal (in particular to "cookies and other tracers"), 2020. https://www.legifrance.gouv.fr/jorf/id/ JORFTEXT000042388179.
[27]
Consent-O-Matic browser extension. matic/mdjildafknihdffpkfmmpnpoiajf jnjd.
[28]
Cookiebot. Cookie Scanner for GDPR/ePR and CCPA Compliance. https://www. cookiebot.com/en/cookie-scanner/.
[29]
Court of Justice of the EU. C-101/01, LINDQUIST, 6.11.2003 ECLI:EU:C:2003:596. https://curia.europa.eu/juris/liste.jsf?num=C-101/01.
[30]
Martin Degeling, Christine Utz, Christopher Lentzsch, Henry Hosseini, Florian Schaub, and Thorsten Holz. We Value Your Privacy... Now Take Some Cookies: Measuring the GDPR's Impact on Web Privacy.
[31]
Dermatologie-weissensee.de website. https://www.dermatologie-weissensee.de/ termine/.
[32]
Disconnect Official website. https://disconnect.me/.
[33]
Guidance note on the use of cookies and other tracking technologies, 2020. https://www.dataprotection.ie/sites/default/files/uploads/2020-04/Guidance% 20note%20on%20cookies%20and%20other%20tracking%20technologies.pdf .
[34]
Report by the Data Protection Commission on the use of cookies and other tracking technologies, 2016. https://www.dataprotection.ie/sites/default/files/ uploads/2020-04/Report%20by%20the%20DPC%20on%20the%20use%20of%20cookies%20and%20other%20tracking%20technologies.pdf.
[35]
EFF. Privacy Badger. https://privacybadger.org/.
[36]
Steven Englehardt and Arvind Narayanan. Online Tracking: A 1-million-site Measurement and Analysis. In Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security ACM CCS, pages 1388--1401, 2016.
[37]
Steven Englehardt, Dillon Reisman, Christian Eubank, Peter Zimmerman, Jonathan Mayer, Arvind Narayanan, and Edward W. Felten. Cookies That Give You Away: The Surveillance Implications of Web Tracking. In Proceedings of WWW 2015, pages 289--299, 2015.
[38]
Directive 2009/136/EC of the European Parliament and of the Council of 25 November 2009 amending Directive 2002/22/EC on universal service and users' rights relating to electronic communications networks and services, Directive 2002/58/EC concerning the processing of personal data and the protection of privacy in the electronic communications sector and Regulation (EC) No 2006/2004 on cooperation between national authorities responsible for the enforcement of consumer protection laws (Text with EEA relevance). Directive 2009/136/EC, 2009. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32009L0136.
[39]
European Data Protection Board. Opinion 4/2007 on the concept of personal data (WP 136), adopted on 20.06.2007. https://ec.europa.eu/justice/article-29/documentation/opinionrecommendation/files/2007/wp136_en.pdf .
[40]
European Data Protection Board. Guidelines 05/2020 on consent, Version 1.1, adopted on 4 May 2020, 2020. https://edpb.europa.eu/sites/edpb/files/files/file1/ edpb_guidelines_202005_consent_en.pdf.
[41]
European Data Protection Board (EDPB). Opinion 2/2010 on online behavioural advertising, 22 June 2010, WP171, p. 10.
[42]
European Data Protection Board (EDPB). Guidelines 05/2020 on consent under Regulation 2016/679, 2020.
[43]
EZIGDPR. GDPR Website Compliance Check. https://www.ezigdpr.com/products/gdpr-website-compliance-checker.
[44]
Facebook Privacy Policy. https://www.facebook.com/policies/cookies.
[45]
Imane Fouad, Nataliia Bielova, Arnaud Legout, and Natasa Sarafijanovic-Djukic. Missed by Filter Lists: Detecting Unknown Third-Party Trackers with Invisible Pixels. Proceedings on Privacy Enhancing Technologies (PoPETs), 2020, 2020. Published online: 08 May 2020, https://doi.org/10.2478/popets-2020-0038.
[46]
Imane Fouad, Cristiana Santos, Feras Al Kassar, Nataliia Bielova, and Stefano Calzavara. On Compliance of Cookie Purposes with the Purpose Specification Principle. In 2020 International Workshop on Privacy Engineering, IWPE, 2020. https://hal.inria.fr/hal-02567022.
[47]
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (Text with EEA relevance). https: //eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:32016R0679.
[48]
Ghostery Official website. https://www.ghostery.com/.
[49]
SAP Advanced Cookie Reference. https://help.sap.com/ viewer/8b8d6fffe113457094a17701f63e3d6a/GIGYA/en-US/ 41419ee070b21014bbc5a10ce4041860.html, accessed 16. July 2021.
[50]
Google analytics solutions. https://www.google.com/analytics.
[51]
Google.com cookie usage. https://developers.google.com/analytics/devguides/ collection/analyticsjs/cookie-usage.
[52]
Google policy. hhttps://policies.google.com/technologies/cookies?hl=en-US.
[53]
Colin Gray, Cristiana Santos, Nataliia Bielova, Michael Toth, and Damien Clifford. Dark Patterns and the Legal Requirements of Consent Banners: An Interaction Criticism Perspective. In ACM CHI 2021, 2020. https://arxiv.org/abs/2009.10194.
[54]
Greek DPA (HDPA). Guidelines on Cookies and Trackers, 2020. http://www.dpa.gr/APDPXPortlets/htdocs/documentSDisplay.jsp?docid= 84,221,176,170,98,24,72,223.
[55]
Harward Business Review. What Patients Like - and Dislike - About Telemedicine. https://hbr.org/2020/12/what-patients-like-and-dislike-about-telemedicine accessed on 27 February 2021.
[56]
Raymond Hill and Contributors. uBlock Origin. https://github.com/gorhill/uBlock/.
[57]
Information Commissioner's Office. Article 29 WP, Annex 2015), 2015. https://ec.europa.eu/justice/article-29/documentation/other-document/files/ 2015/20150205_letter_art29wp_ec_health_data_after_plenary_annex_en.pdf.
[58]
Information Commissioner's Office. Update report into adtech and real time bidding. https://ico.org.uk/media/about-the-ico/documents/2615156/adtech-real-time-bidding-report-201906.pdf, accessed on 2019.07.10, 2019.
[59]
Information Commissioner's Office. Hellenic Data Protection Authority guidance on the use of cookies (and similar technologies), 2020. https://iapp.org/resources/article/cookie-guidance-from-greece/.
[60]
Information Commissioner's Office. ICO guide on special category of data, 2020. https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/special-category-data/what-is-special-category-data/#scd5.
[61]
Timothy Libert. Privacy implications of health information seeking on the web. Communications of the ACM, 58(3):68--77, 2015.
[62]
LINC. Cookieviz 2: new features to observe hidden web practices. https://linc. cnil.fr/fr/cookieviz-2-new-features-observe-hidden-web-practices.
[63]
Célestin Matte, Nataliia Bielova, and Cristiana Santos. Do Cookie Banners Respect my Choice? Measuring Legal Compliance of Banners from IAB Europe's Transparency and Consent Framework. In IEEE Symposium on Security and Privacy (IEEE S&P 2020), 2020.
[64]
McAfee categorization service. https://www.trustedsource.org/.
[65]
Description of McAfee categories. https://www.trustedsource.org/download/ts_ wd_reference_guide.pdf.
[66]
Mozilla. Lightbeam 3.0. https://addons.mozilla.org/en-GB/firefox/addon/ lightbeam-3-0/.
[67]
Midas Nouwens, Ilaria Liccardi, Michael Veale, David Karger, and Lalana Kagal. Dark Patterns after the GDPR: Scraping Consent Pop-ups and Demonstrating their Influence. In CHI, 2020.
[68]
Emmanouil Papadogiannakis, Panagiotis Papadopoulos, Nicolas Kourtellis, and Evangelos P. Markatos. User Tracking in the Post-cookie Era: How Websites Bypass GDPR Consent to Track Users. In Proceedings of WWW 2021, 2021. https://arxiv.org/abs/2102.08779.
[69]
Panagiotis Papadopoulos, Nicolas Kourtellis, and Evangelos P. Markatos. Cookie Synchronization: Everything You Always Wanted to Know But Were Afraid to Ask. In The World Wide Web Conference, WWW 2019, San Francisco, CA, USA, May 13-17, 2019, pages 1432--1442, 2019.
[70]
Article 29 Data Protection Working Party. Opinion 2/2010 on online behavioural advertising, Adopted on 22 June 2010. https://ec.europa.eu/justice/article-29/ documentation/opinion-recommendation/files/2010/wp171_en.pdf .
[71]
Piwik. Free Online Cookie Scanner. https://piwik.pro/cookie-scanner/.
[72]
PrivateVPN website. https://privatevpn.com/.
[73]
Iskander Sánchez-Rola, Matteo Dell'Amico, Platon Kotzias, Davide Balzarotti, Leyla Bilge, Pierre-Antoine Vervier, and Igor Santos. Can I Opt Out Yet?: GDPR and the Global Illusion of Cookie Control. In Proceedings of the ACM Asia Conference Computer and Communications Security, pages 340--351, 2019.
[74]
Cristiana Santos, Nataliia Bielova, and Célestin Matte. Are cookie banners indeed compliant with the law? Deciphering EU legal requirements on consent and technical means to verify compliance of cookie banners, journal=Technology and Regulation. pages 91--135, 2020.
[75]
Matic Srdjan, Iordanou Costas, Smaragdakis Georgios, and Nikolaos Laoutaris. Identifying Sensitive URLs at Web-Scale. In ACM Internet Measurement Conference (ACM IMC 2020), 2020.
[76]
Starofservice website. https://www.starofservice.com/annubis/ile-de-france/ paris/paris/pediatrie.
[77]
European Data Protection Supervisor. EDPS Inspection Software. https://edps. europa.eu/press-publications/edps-inspection-software_en.
[78]
Tribalfusion policy. https://www.havaianas-store.com/fr/Cookies+policy.html.
[79]
Christopher Uner, Lee A. Bygrave, Christopher Docksey, Laura Drechsler, and Luca Tosoni. The EU General Data Protection Regulation: A Commentary/Update of Selected Articles. 2021. https://global.oup.com/academic/product/the-eu-general-data-protection-regulation-gdpr-9780198826491?cc=pt&lang=en&.
[80]
Tobias Urban, Martin Degeling, Thorsten Holz, and Norbert Pohlmann. Beyond the Front Page: Measuring Third Party Dynamics in the Field. In Yennun Huang, Irwin King, Tie-Yan Liu, and Maarten van Steen, editors, WWW '20: The Web Conference 2020, Taipei, Taiwan, April 20-24, 2020, pages 1275--1286. ACM / IW3C2, 2020.
[81]
Pelayo Vallina, Álvaro Feal, Julien Gamba, Narseo Vallina-Rodriguez, and Antonio Fernández Anta. Tales from the porn: A comprehensive privacy analysis of the web porn ecosystem. In Proceedings of the Internet Measurement Conference, pages 245--258, 2019.
[82]
Webcookies. Web Cookies Scanner. https://webcookies.org/.
[83]
Eva Wolfangel. Ist Ihr Arzttermin sicher?, Jun 2021.

Cited By

View all
  • (2024)Third-Party Data Leaks in the Websites of Finnish Social and Healthcare DistrictsGood Practices and New Perspectives in Information Systems and Technologies10.1007/978-3-031-60215-3_14(139-152)Online publication date: 11-May-2024
  • (2023)Data Leaks to Third-Party Services on Medical Websites2023 16th International Conference on Security of Information and Networks (SIN)10.1109/SIN60469.2023.10475119(1-7)Online publication date: 20-Nov-2023
  • (2022)Privacy, Permissions, and the Health App Ecosystem: A Stack Overflow ExplorationProceedings of the 2022 European Symposium on Usable Security10.1145/3549015.3555669(117-130)Online publication date: 29-Sep-2022
  • Show More Cited By

Recommendations

Comments

Please enable JavaScript to view thecomments powered by Disqus.

Information & Contributors

Information

Published In

cover image ACM Conferences
WPES '21: Proceedings of the 20th Workshop on Workshop on Privacy in the Electronic Society
November 2021
257 pages
ISBN:9781450385275
DOI:10.1145/3463676
  • General Chairs:
  • Yongdae Kim,
  • Jong Kim,
  • Program Chairs:
  • Giovanni Livraga,
  • Noseong Park
Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than the author(s) must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected].

Sponsors

Publisher

Association for Computing Machinery

New York, NY, United States

Publication History

Published: 15 November 2021

Permissions

Request permissions for this article.

Check for updates

Author Tags

  1. browser extension
  2. explicit consent
  3. gdpr
  4. health data
  5. tracking

Qualifiers

  • Research-article

Funding Sources

  • ANR JCJC project PrivaWeb
  • DATA4US Exploratory Action
  • ANSWERproject PIA FSN2

Conference

CCS '21
Sponsor:

Acceptance Rates

Overall Acceptance Rate 106 of 355 submissions, 30%

Upcoming Conference

CCS '25

Contributors

Other Metrics

Bibliometrics & Citations

Bibliometrics

Article Metrics

  • Downloads (Last 12 months)54
  • Downloads (Last 6 weeks)5
Reflects downloads up to 10 Dec 2024

Other Metrics

Citations

Cited By

View all
  • (2024)Third-Party Data Leaks in the Websites of Finnish Social and Healthcare DistrictsGood Practices and New Perspectives in Information Systems and Technologies10.1007/978-3-031-60215-3_14(139-152)Online publication date: 11-May-2024
  • (2023)Data Leaks to Third-Party Services on Medical Websites2023 16th International Conference on Security of Information and Networks (SIN)10.1109/SIN60469.2023.10475119(1-7)Online publication date: 20-Nov-2023
  • (2022)Privacy, Permissions, and the Health App Ecosystem: A Stack Overflow ExplorationProceedings of the 2022 European Symposium on Usable Security10.1145/3549015.3555669(117-130)Online publication date: 29-Sep-2022
  • (2022)Redress for Dark Patterns Privacy Harms? A Case Study on Consent InteractionsProceedings of the 2022 Symposium on Computer Science and Law10.1145/3511265.3550448(181-194)Online publication date: 1-Nov-2022
  • (2022)Got Sick and Tracked: Privacy Analysis of Hospital Websites2022 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)10.1109/EuroSPW55150.2022.00034(278-286)Online publication date: Jun-2022

View Options

Login options

View options

PDF

View or Download as a PDF file.

PDF

eReader

View online with eReader.

eReader

Media

Figures

Other

Tables

Share

Share

Share this Publication link

Share on social media