Me want cookie! Towards automated and transparent data governance on the Web

Jesse Wright,Beatriz Esteves,Rui Zhao
2024-08-17
Abstract:This paper presents a sociotechnical vision for managing personal data, including cookies, within Web browsers. We first present our vision for a future of semi-automated data governance on the Web, using policy languages to describe data terms of use, and having browsers act on behalf of users to enact policy-based controls. Then, we present an overview of the technical research required to {prove} that existing policy languages express a sufficient range of concepts for describing cookie policies on the Web today. We view this work as a stepping stone towards a future of semi-automated data governance at Web-scale, which in the long term will also be used by next-generation Web technologies such as Web agents and Solid.
Human-Computer Interaction,Computers and Society
What problem does this paper attempt to address?
The paper attempts to address a series of challenges in the management and governance of personal data (especially data collected through browser cookies) in the current network environment. Specifically, the paper focuses on the following aspects: 1. **Insufficient user privacy control**: Despite legislative attempts to give users more control over data collected through cookies, in practice, users are often overwhelmed by numerous, complex, and hard-to-understand cookie notification pop-ups that usually do not align with their preferences. 2. **Mismatch between existing technologies and regulations**: Existing technical means (such as the P3P protocol) have encountered obstacles in implementation and adoption, failing to effectively address privacy protection issues. Meanwhile, with the development of privacy protection regulations (such as GDPR, CCPA, etc.), new technical solutions are needed to ensure that websites can comply with these regulations. 3. **Need for automated data governance**: The paper proposes a vision of semi-automated data governance, aiming to describe data usage terms through policy languages (such as ODRL, DToU, and DPV) and enable browsers to execute policy-based controls on behalf of users, thereby simplifying the user experience and enhancing user control over web privacy. 4. **Support for future web technologies**: The paper argues that by applying the aforementioned technologies to existing cookie management, a foundation can be laid for data governance in next-generation web technologies (such as Web Agents and Solid), achieving larger-scale automated data governance. In summary, the main goal of the paper is to improve the user experience of privacy control on the web by introducing standardized, machine-readable data usage terms and developing corresponding technical frameworks, while also helping businesses and regulatory bodies better comply with privacy protection regulations.