User Tools

Site Tools


practices:legal_enforcement

This is an old revision of the document!


Legal Enforcement

You crawled 100k sites and 8,000 of them set advertising cookies before consent. You can email 8,000 operators — that is Notifying websites, and it is a measurement in its own right. You can publish and hope. Or you can take the finding to the body that can actually order the practice to stop. This page is about the third route: which authority is competent for your finding, what a filing has to contain, what came back when researchers did it, and the ways it can go wrong — including the regulator opening a file on you.

It is not a guide to the GDPR. What a lawful basis is, what Article 6 says, and how consent is defined are covered better in the regulation and in the legal literature. What is not written down anywhere is the operational part: that your cookie finding and your profiling finding go to two different desks under two different competence rules, that a GDPR complaint is in general a data subject's to lodge and you have to work out whether you are one, and that the modal paper in this literature finds violations across a large sample and then tells nobody with enforcement powers.

The one thing to get right: a cookie finding is not a GDPR case, and it does not go through the one-stop-shop.

Access to a user's terminal — reading or writing a cookie, a localStorage entry, a fingerprint — is governed by Article 5(3) of the ePrivacy Directive, which is a directive transposed into 27 national laws, not a regulation. The GDPR's one-stop-shop (Art. 56) routes a cross-border case to the lead supervisory authority of the controller's main EU establishment. It does not extend to ePrivacy enforcement: “The GDPR mechanisms do not apply to the enforcement of the provisions contained in the ePrivacy Directive as such”.1)

The practical consequence is the whole reason to know this. It is why CNIL, not the Irish DPC, could fine Google €100m over cookies although Google's main EU establishment is in Ireland — and the Conseil d'État upheld exactly that reasoning.2) So: your local authority is competent for what happens on its own territory, and a Europe-wide cookie result is not one case but as many cases as you have jurisdictions.

One caveat that cuts the other way: only the terminal access is ePrivacy. Everything that happens to the data afterwards — profiling, sharing, retention, data-subject rights — is ordinary GDPR and is in the one-stop-shop. A single crawl result routinely splits across both.

Across seven venues and seventeen publication years, a corpus-wide sweep surfaces exactly one paper that states this [1Bielova, Nataliia; Litvine, Laura; Nguyen, Anysia; Chammat, Mariam; Toubiana, Vincent; Hary, Estelle (2024): "The Effect of Design Patterns on (Present and Future) Cookie Consent Decisions", in: Proceedings of the USENIX Security Symposium. (Link)]. One of its authors works at CNIL.

And it may not survive the decade — see the Digital Omnibus box below, which proposes to move exactly this into the GDPR.

How much of the field does this, measured

From the publication corpus behind this site: 5,859 papers, seven venues (CCS, IMC, NDSS, PoPETs, USENIX Security, TheWebConf, IEEE S&P), 2010–2026. 402 of them (6.9%) assess compliance with a named law — the legal population, defined as a paper for which the extraction emitted at least one tuple naming a statute and a compliance question. That is the denominator for most of this section, and it is growing:

Window Papers in window Assessed a law Share
2010–2013 511 8 1.6%
2014–2017 769 17 2.2%
2018–2021 1,439 83 5.8%
2022–2024 1,955 173 8.8%
2025–2026* 1,185 121 10.2%

* 2025–2026 is provisional: CCS 2026 and IMC 2026 have not been held, and IEEE S&P 2026 and TheWebConf 2026 abstracts are not in OpenAlex, so those venue-years are under-represented by construction. See Corpus.

It is also very unevenly distributed. Almost a quarter of PoPETs papers assess a law; at CCS it is one in thirty. If you are writing a compliance measurement and wondering where the reviewers who have read one before are, this table is the answer.

Venue Papers Assessed a law Share
PoPETs 510 122 23.9%
USENIX Security 1,410 102 7.2%
IEEE S&P 767 52 6.8%
NDSS 701 32 4.6%
IMC 638 27 4.2%
TheWebConf 843 33 3.9%
CCS 990 34 3.4%

Which laws

legal[].law is verbatim free text and holds 186 distinct strings across the 402 papers, so it has to be folded before it is counted — “GDPR” alone appears under nine spellings (GDPR, EU GDPR, European GDPR, UK GDPR, General Data Protection Regulation, GDPR Art. 20, …), and counting the exact string GDPR misses 13 of the 284 papers that name it. The fold groups laws by which authority enforces them, because that is this page's question; the rules and the unmapped residue are on the provenance page.

Law family Papers Share of 402
EU data protection (GDPR and predecessors) 289 71.9%
US state privacy law (CCPA/CPRA, BIPA, VCDPA, …) 73 18.2%
US children / education / health / finance (COPPA, FERPA, HIPAA, GLBA, VPPA) 53 13.2%
Sector, national and other rules 49 12.2%
ePrivacy / cookie law 27 6.7%
Non-EU/US data protection law (LGPD, PIPL, PIPEDA, PDPA, POPIA, …) 26 6.5%
Computer-crime, access and copyright (CFAA, DMCA, …) 19 4.7%
US federal consumer protection and sector regulators (FTC, FCC) 18 4.5%
EU platform / digital-market regulation (DSA, DMA, AI Act, eIDAS, PSD2) 17 4.2%

Families are multi-valued — a paper naming both the GDPR and the ePrivacy Directive counts in each — so the column sums to 571, not 402.

The row worth staring at is the fifth. Only 26 papers name the ePrivacy Directive at all — the 27th in that family is there for an Italian authority's cookie guidance — against 289 naming the GDPR. Web-measurement papers about cookie banners routinely frame the whole finding as a GDPR question, when the part they measured — was something written to the terminal before consent — is Article 5(3) ePrivacy, with a different competent authority and a different enforcement route. That is not a pedantic distinction; per the box above, it decides which desk your evidence lands on.

Finding a violation is not the hard part

legal[].foundViolations (per paper, worst case wins) Papers Share of 402
yes 94 23.4%
partial 83 20.6%
no 74 18.4%
not-assessed 151 37.6%
not-stated 0 0.0%

177 papers (44.0%) report finding violations, in full or in part. What happens next is where the field goes quiet.

Almost nobody tells a regulator

The extraction records ethics.regulatorContact — “whether a DPA, CERT, or other regulator was contacted” — for every paper that says anything about ethics at all. Papers that say nothing about ethics carry no record and are excluded rather than silently counted as “no”.

Population N yes no not-stated
empirical ∧ has an ethics record 4,472 147 (3.3%) 1,982 (44.3%) 2,343 (52.4%)
ran a crawl ∧ ethics 972 37 (3.8%) 418 (43.0%) 517 (53.2%)
assessed a law ∧ ethics 385 27 (7.0%) 228 (59.2%) 130 (33.8%)
assessed a law ∧ crawled ∧ ethics 123 10 (8.1%) 74 (60.2%) 39 (31.7%)

And the cut that matters — papers that found a violation:

Population N Contacted a regulator
found violations (yes or partial) 177
… of which carry an ethics record 166 19 (11.4%)
… same cut, web-crawling papers only 75 9 (12.0%)

So roughly one paper in nine that found a legal violation says it went to a regulator, and that figure is the generous one: it counts CERTs, sector regulators and internal data protection officers alongside DPAs, and it counts an intention as an act. Reading the papers (below) brings the number that actually took a privacy or consumer-protection finding to a privacy or consumer-protection authority down to 7 of the 177.

The trend is not what you would guess from the growth of the field. Among papers that assessed a law, regulator contact fell from 10/83 (12.0%) in 2018–2021 to 15/279 (5.4%) in 2022–2026.3)

The obvious explanation is that compliance measurement has spread out of a small privacy community into four large venues whose authors have no regulator contacts. That explanation is wrong, and it is cheap to check. PoPETs' share of these papers rose, from 21.7% to 32.3%, and the rate fell inside both strata: PoPETs 16.7% → 6.7%, everywhere else 10.8% → 4.8%. So it is not a venue-mix effect, and this page has no explanation to offer for it — only the observation that the field got much better at saying it disclosed responsibly (see Notifying websites, where every indicator rises) over exactly the period it got worse at telling a regulator.

"We disclosed responsibly" almost never means "to a regulator"

2,870 of the 4,472 empirical papers with an ethics record give a free-text disclosureDetail. 12 of them (0.4%) name a privacy or consumer-protection authority — 15 if you also count the three that say “regulator” or “regulatory” without naming anyone, one of which means a bank regulator. 54 (1.9%) name a CERT. The 15 strings are short enough to print in full on the provenance page, and they are the entire visible surface of this practice in seventeen publication years of seven venues.

What the papers that did it actually did

A sentence-level sweep of all 5,859 papers' full text for an authority name next to a first-person verb produced 89 candidates; six more came from ethics.regulatorContact == yes and from a separate sweep for papers that study enforcement. All 95 were read and given one role. 67 were off-topic — “we hope regulators will use our tool”, a voltage regulator, a citation to a CNIL guideline, or a column-repair artefact — and are listed with their reason on the provenance page. The remaining 28:

Role What it means Papers
filed took findings to a privacy, consumer-protection or sector regulator 15
authorised a regulator approved or supervised the authors' own processing 4
planned stated an intention; not done at submission 3
corpus measures regulators' own output rather than contacting one 3
subject a regulator acted on the authors 1
declined said explicitly that they chose not to involve one 1
collaboration the study was designed with, for, or inside a regulator 1

Fifteen papers in seventeen publication years. Seven went to the FTC or the California Attorney General, six to a European data protection authority (EDPS, CNIL, AEPD, or one left unnamed), two to a sector regulator or an unnamed “regulators”. Fourteen of the fifteen also notified the affected party — but only seven fully: ethics.notifiedAffectedParties is yes for 7 and partial for 7, and partial means some affected parties were reached and others were not. Only [2Feal, Álvaro; Calciati, Paolo; Vallina-Rodriguez, Narseo; Troncoso, Carmela; Gorla, Alessandra (2020): "Angel or Devil? A Privacy Study of Mobile Parental Control Apps", Proceedings on Privacy Enhancing Technologies 2020(2). (DOI)] is recorded as no: it took its parental-control-app findings to the AEPD and to INCIBE and to nobody else. So the regulator is almost never used as a substitute for disclosure, which matches the pattern on Notifying websites, where 135 of the 147 papers (91.8%) that contacted a regulator or CERT also notified the operator.

All fifteen, with who they went to:

Paper Venue, year Authority named
[3Murdoch, Steven J.; Drimer, Saar; Anderson, Ross; Bond, Mike (2010): "Chip and PIN is Broken", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] IEEE S&P 2010 bank regulators, UK / Europe / North America
[4Zimmeck, Sebastian; Story, Peter; Smullen, Daniel; Ravichander, Abhilasha; Wang, Ziqi; Reidenberg, Joel; Russell, N. Cameron; Sadeh, Norman (2019): "MAPS: Scaling Privacy Compliance Analysis to a Million Apps", Proceedings on Privacy Enhancing Technologies 2019(3). (DOI)] PoPETs 2019 FTC (as unnamed “regulators”, plus an FTC pilot)
[5Reardon, Joel; Feal, Álvaro; Wijesekera, Primal; Elazari Bar On, Amit; Vallina-Rodriguez, Narseo; Egelman, Serge (2019): "50 Ways to Leak Your Data: An Exploration of Apps' Circumvention of the Android Permissions System", in: Proceedings of the USENIX Security Symposium. (Link)] USENIX Security 2019 US Federal Trade Commission
[6Cheng, Long; Wilson, Christin; Liao, Song; Young, Jeffrey; Dong, Daniel; Hu, Hongxin (2020): "Dangerous Skills Got Certified: Measuring the Trustworthiness of Skill Certification in Voice Personal Assistant Platforms", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)] CCS 2020 US Federal Trade Commission
[7Gamba, Julien; Rashed, Mohammed; Razaghpanah, Abbas; Tapiador, Juan; Vallina-Rodriguez, Narseo (2020): "An Analysis of Pre-installed Android Software", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] IEEE S&P 2020 Agencia Española de Protección de Datos (AEPD)
[2Feal, Álvaro; Calciati, Paolo; Vallina-Rodriguez, Narseo; Troncoso, Carmela; Gorla, Alessandra (2020): "Angel or Devil? A Privacy Study of Mobile Parental Control Apps", Proceedings on Privacy Enhancing Technologies 2020(2). (DOI)] PoPETs 2020 AEPD and INCIBE's IS4K, Spain
[8Iqbal, Umar; Bahrami, Pouneh Nikkhah; Trimananda, Rahmadi; Cui, Hao; Gamero-Garrido, Alexander; Dubois, Daniel J.; Choffnes, David R.; Markopoulou, Athina; Roesner, Franziska; Shafiq, Zubair (2023): "Tracking, Profiling, and Ad Targeting in the Alexa Echo Smart Speaker Ecosystem", in: Proceedings of the ACM Internet Measurement Conference. (DOI)] IMC 2023 US Federal Trade Commission (public forum)
[9Yeung, Christina; Iqbal, Umar; O'Neil, Yekaterina Tsipenyuk; Kohno, Tadayoshi; Roesner, Franziska (2023): "Online Advertising in Ukraine and Russia During the 2022 Russian Invasion", in: Proceedings of the ACM Web Conference. (DOI)] TheWebConf 2023 US Federal Trade Commission
[10Zimmeck, Sebastian; Wang, Oliver; Alicki, Kuba; Wang, Jocelyn; Eng, Sophie (2023): "Usability and Enforceability of Global Privacy Control", Proceedings on Privacy Enhancing Technologies 2023(2). (DOI)] PoPETs 2023 California OAG (invoked, not contacted — see below)
[11Arunasalam, Arjun; Chu, Andrew; Ozmen, Muslum Ozgur; Farrukh, Habiba; Celik, Z. Berkay (2024): "The Dark Side of E-Commerce: Dropshipping Abuse as a Business Model", in: Proceedings of the Network and Distributed System Security Symposium. (Link)] NDSS 2024 US Federal Trade Commission
[12Moti, Zahra; Senol, Asuman; Bostani, Hamid; Zuiderveen Borgesius, Frederik J.; Moonsamy, Veelasha; Mathur, Arunesh; Acar, Gunes (2024): "Targeted and Troublesome: Tracking and Advertising on Children's Websites", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] IEEE S&P 2024 an unnamed European DPA and a consumer protection agency
[13Girish, Aniketh; Reardon, Joel; Tapiador, Juan; Matic, Srdjan; Vallina-Rodriguez, Narseo (2025): "Your Signal, Their Data: An Empirical Privacy Analysis of Wireless-scanning SDKs in Android", Proceedings on Privacy Enhancing Technologies 2025(3). (DOI)] PoPETs 2025 EDPS, AEPD, CNIL
[14Weerasekara, Nipuna; Moreno, José Miguel; Matic, Srdjan; Reardon, Joel; Tapiador, Juan; Vallina-Rodríguez, Narseo (2025): "Tracking Without Borders: Studying the Role of WebViews in Bridging Mobile and Web Tracking", Proceedings on Privacy Enhancing Technologies 2025(4). (DOI)] PoPETs 2025 EDPS, CNIL
[15Zhang, Xin; Zhang, Xiaohan; Zhao, Bo; Nan, Yuhong; Liu, Zhichen; Chen, Jianzhou; Zhou, Huijun; Yang, Min (2025): "Demystifying the (In)Security of QR Code-based Login in Real-world Deployments", in: Proceedings of the USENIX Security Symposium. (Link)] USENIX Security 2025 unnamed (“developers and regulators”)
[16Vlummens, Tim; Girish, Aniketh; Weerasekara, Nipuna; Zuiderveen Borgesius, Frederik; Acar, Gunes; Vallina-Rodriguez, Narseo (2026): "Bridges to Self: Silent Web-to-App Tracking on Mobile via Localhost", in: Proceedings of the USENIX Security Symposium. (Link)] USENIX Security 2026 EU- and US-based data protection authorities

Three more said they would and had not yet at submission: [17Trevisan, Martino; Traverso, Stefano; Bassi, Eleonora; Mellia, Marco (2019): "4 Years of EU Cookie Law: Results and Lessons Learned", Proceedings on Privacy Enhancing Technologies 2019(2):126-145. (DOI)] (“we are contacting local Data Protection Authority to present our findings”), [18Girish, Aniketh; Hu, Tianrui; Prakash, Vijay; Dubois, Daniel J.; Matic, Srdjan; Huang, Danny Yuxing; Egelman, Serge; Reardon, Joel; Tapiador, Juan; Choffnes, David R.; Vallina-Rodriguez, Narseo (2023): "In the Room Where It Happens: Characterizing Local Communication and Threats in Smart Homes", in: Proceedings of the ACM Internet Measurement Conference. (DOI)] (“in the process of disclosing … to regulators in relevant jurisdictions”) and [19Morel, Victor; Santos, Cristiana; Carlsson, Pontus; Ahlinder, Joel; Duvignau, Romaric (2026): "The TCF doesn't really A(A)ID - Automatic Privacy Analysis and Legal Compliance of TCF-based Android Applications", Proceedings on Privacy Enhancing Technologies 2026(3). (DOI)] (“plan to share our results with the European Data Protection Board, data protection regulators, as well as with IAB Europe”). Whether any of the three followed through is not recoverable from the corpus.

Eleven of the fifteen sit in three co-authorship components; four are one-offs. Treating the fifteen as a graph with an edge wherever two share an author gives one component of seven — the IMDEA Networks / ICSI / Radboud mobile-privacy line, with Vallina-Rodriguez on six of them ([5Reardon, Joel; Feal, Álvaro; Wijesekera, Primal; Elazari Bar On, Amit; Vallina-Rodriguez, Narseo; Egelman, Serge (2019): "50 Ways to Leak Your Data: An Exploration of Apps' Circumvention of the Android Permissions System", in: Proceedings of the USENIX Security Symposium. (Link), 2Feal, Álvaro; Calciati, Paolo; Vallina-Rodriguez, Narseo; Troncoso, Carmela; Gorla, Alessandra (2020): "Angel or Devil? A Privacy Study of Mobile Parental Control Apps", Proceedings on Privacy Enhancing Technologies 2020(2). (DOI), 7Gamba, Julien; Rashed, Mohammed; Razaghpanah, Abbas; Tapiador, Juan; Vallina-Rodriguez, Narseo (2020): "An Analysis of Pre-installed Android Software", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI), 12Moti, Zahra; Senol, Asuman; Bostani, Hamid; Zuiderveen Borgesius, Frederik J.; Moonsamy, Veelasha; Mathur, Arunesh; Acar, Gunes (2024): "Targeted and Troublesome: Tracking and Advertising on Children's Websites", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI), 13Girish, Aniketh; Reardon, Joel; Tapiador, Juan; Matic, Srdjan; Vallina-Rodriguez, Narseo (2025): "Your Signal, Their Data: An Empirical Privacy Analysis of Wireless-scanning SDKs in Android", Proceedings on Privacy Enhancing Technologies 2025(3). (DOI), 14Weerasekara, Nipuna; Moreno, José Miguel; Matic, Srdjan; Reardon, Joel; Tapiador, Juan; Vallina-Rodríguez, Narseo (2025): "Tracking Without Borders: Studying the Role of WebViews in Bridging Mobile and Web Tracking", Proceedings on Privacy Enhancing Technologies 2025(4). (DOI), 16Vlummens, Tim; Girish, Aniketh; Weerasekara, Nipuna; Zuiderveen Borgesius, Frederik; Acar, Gunes; Vallina-Rodriguez, Narseo (2026): "Bridges to Self: Silent Web-to-App Tracking on Mobile via Localhost", in: Proceedings of the USENIX Security Symposium. (Link)]) — and two of two ([4Zimmeck, Sebastian; Story, Peter; Smullen, Daniel; Ravichander, Abhilasha; Wang, Ziqi; Reidenberg, Joel; Russell, N. Cameron; Sadeh, Norman (2019): "MAPS: Scaling Privacy Compliance Analysis to a Million Apps", Proceedings on Privacy Enhancing Technologies 2019(3). (DOI), 10Zimmeck, Sebastian; Wang, Oliver; Alicki, Kuba; Wang, Jocelyn; Eng, Sophie (2023): "Usability and Enforceability of Global Privacy Control", Proceedings on Privacy Enhancing Technologies 2023(2). (DOI)]; [8Iqbal, Umar; Bahrami, Pouneh Nikkhah; Trimananda, Rahmadi; Cui, Hao; Gamero-Garrido, Alexander; Dubois, Daniel J.; Choffnes, David R.; Markopoulou, Athina; Roesner, Franziska; Shafiq, Zubair (2023): "Tracking, Profiling, and Ad Targeting in the Alexa Echo Smart Speaker Ecosystem", in: Proceedings of the ACM Internet Measurement Conference. (DOI), 9Yeung, Christina; Iqbal, Umar; O'Neil, Yekaterina Tsipenyuk; Kohno, Tadayoshi; Roesner, Franziska (2023): "Online Advertising in Ukraine and Russia During the 2022 Russian Invasion", in: Proceedings of the ACM Web Conference. (DOI)]). The remaining four share nobody with anybody ([3Murdoch, Steven J.; Drimer, Saar; Anderson, Ross; Bond, Mike (2010): "Chip and PIN is Broken", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI), 6Cheng, Long; Wilson, Christin; Liao, Song; Young, Jeffrey; Dong, Daniel; Hu, Hongxin (2020): "Dangerous Skills Got Certified: Measuring the Trustworthiness of Skill Certification in Voice Personal Assistant Platforms", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI), 11Arunasalam, Arjun; Chu, Andrew; Ozmen, Muslum Ozgur; Farrukh, Habiba; Celik, Z. Berkay (2024): "The Dark Side of E-Commerce: Dropshipping Abuse as a Business Model", in: Proceedings of the Network and Distributed System Security Symposium. (Link), 15Zhang, Xin; Zhang, Xiaohan; Zhao, Bo; Nan, Yuhong; Liu, Zhichen; Chen, Jianzhou; Zhou, Huijun; Yang, Min (2025): "Demystifying the (In)Security of QR Code-based Login in Real-world Deployments", in: Proceedings of the USENIX Security Symposium. (Link)]).

Read that as encouragement rather than as a closed shop. One group has made filing routine, which is evidence that it can be made routine; four groups did it exactly once, with no visible institutional apparatus at all.

A fourth route: be inside

Four corpus papers have a regulator in the author list, found by sweeping every paper's full text for regulator email domains and authority names in the affiliation block:

  • [20Brookman, Justin; Rouge, Phoebe; Alva, Aaron; Yeung, Christina (2017): "Cross-Device Tracking: Measurement and Disclosures", Proceedings on Privacy Enhancing Technologies 2017(2). (DOI)] — all four authors at the FTC's Office of Technology Research and Investigation, publishing a cross-device tracking measurement at PoPETs.
  • [21Fouad, Imane; Santos, Cristiana; Legout, Arnaud; Bielova, Nataliia (2022): "My Cookie is a phoenix: detection, measurement, and lawfulness of cookie respawning with browser fingerprinting", in: Proceedings on Privacy Enhancing Technologies. (DOI)] and [22Toth, Michael; Bielova, Nataliia; Roca, Vincent (2022): "On dark patterns and manipulation of website publishers by CMPs", Proceedings on Privacy Enhancing Technologies 2022(3). (DOI)] — a co-author in CNIL's LINC lab.
  • [1Bielova, Nataliia; Litvine, Laura; Nguyen, Anysia; Chammat, Mariam; Toubiana, Vincent; Hary, Estelle (2024): "The Effect of Design Patterns on (Present and Future) Cookie Consent Decisions", in: Proceedings of the USENIX Security Symposium. (Link)] — a CNIL co-author, with the lead author a CNIL Senior Privacy Fellow in 2021–2022; the paper's stated purpose is “To address the needs of the French DPA”, and it is an online experiment on 3,947 French participants commissioned to settle a question CNIL needed settled for its banner guidelines.

That last one is the model worth copying if what you want is impact rather than a filing. A complaint asks an authority to act on a fact; a fellowship or a secondment gets your method into the guideline. CNIL's LINC and the FTC's technology office both run these; check your own national DPA, most of which now have a technology unit.

Which authority is competent

EU: the GDPR complaint

Article 77(1) GDPR“every data subject shall have the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement”.4) Three things follow that researchers get wrong:

  • You must be a data subject. Article 77 is a data-subject right, not a public-interest right. A lab is not a data subject. You usually are: if you crawled with a real browser from your own machine, the sites processed your IP address, your device data and the identifiers they wrote into your terminal. Being able to say “on 2026-03-04 the site at X wrote identifier Y into my terminal without consent” is what converts a corpus-wide statistic into an admissible complaint. Design the crawl so at least one arm is attributable to a named human, and keep that arm's evidence separately.
  • You choose the forum, within limits. Residence, place of work, or place of the alleged infringement — for a website reachable everywhere, that third limb is broad.
  • Silence has a remedy. Under Article 78(2) you have a right to a judicial remedy if the authority “does not handle a complaint or does not inform the data subject within three months on the progress or outcome”. Proceedings go to the courts of the authority's own Member State (Art. 78(3)).

If you are not a data subject, or you want scale, Article 80 routes through a not-for-profit: 80(1) with a data subject's mandate, 80(2) — a complaint with no mandate at all — only where the Member State has enacted it, which is an option, not EU-wide law. In practice this is the noyb route, and it is documented from the other end: noyb's own account of its 500-complaint cookie-banner campaign credits “[t]he researchers of the Ruhr-Universität Bochum and of the collaboration between Utrech[t] University and French Institute Inria” with analyses that “were very helpful for noyb's work on this project”5).6) That is the clearest documented path from a web-measurement paper to an enforcement action, and it did not run through a filing by the researchers.

Where to file. The EDPB keeps the canonical current directory of the 27 national authorities plus Iceland, Liechtenstein and Norway, with addresses and contact emails: edpb.europa.eu/about-edpb/our-members_en.7) Do not file with the EDPS: it supervises EU institutions, and says so — “The EDPS is not competent for complaints against such private organisations; we can therefore only refer you to the relevant national authorities.”8) Two corpus papers name the EDPS as a recipient of their findings [13Girish, Aniketh; Reardon, Joel; Tapiador, Juan; Matic, Srdjan; Vallina-Rodriguez, Narseo (2025): "Your Signal, Their Data: An Empirical Privacy Analysis of Wireless-scanning SDKs in Android", Proceedings on Privacy Enhancing Technologies 2025(3). (DOI), 14Weerasekara, Nipuna; Moreno, José Miguel; Matic, Srdjan; Reardon, Joel; Tapiador, Juan; Vallina-Rodríguez, Narseo (2025): "Tracking Without Borders: Studying the Role of WebViews in Bridging Mobile and Web Tracking", Proceedings on Privacy Enhancing Technologies 2025(4). (DOI)]; as an informational disclosure to a policy body that is fine, but it is not a complaint and it will not start a case against a company.

EU: the ePrivacy complaint, which is a different thing

Everything above is the GDPR route. Your cookie finding is not a GDPR case (see the opening box), and the ePrivacy route has none of the same guarantees, because there is no ePrivacy regulation to guarantee them — only 27 national transpositions.

  • The competent body is designated nationally, and it is not always the DPA. The EDPB is explicit: “The ePrivacy Directive gives Member States flexibility on which authority or body to entrust with enforcement of its provisions”, and “If national law designates the data protection authority as competent authority under the ePrivacy Directive, this data protection authority has the competence to directly enforce national ePrivacy rules in addition to the GDPR (otherwise it does not).”9) In France it is CNIL. In several member states the telecoms regulator holds all or part of it. Check your own country's transposing statute for the designation before you write to anybody — a complaint to the wrong body is not a complaint.
  • Standing is national law, not Article 77. The data-subject standing rule quoted above is a GDPR provision and does not govern an ePrivacy complaint. Who may complain, in what form, and within what limitation period is whatever the transposing statute says. This cuts both ways: some national regimes are more open than Article 77, not less.
  • The admissibility checklist below is GDPR-only too. Regulation (EU) 2025/2518 governs “complaints and … investigations … concerning cross-border processing” under the GDPR. It does not reach ePrivacy complaints, and it does not apply to anything before 2 April 2027.
  • What you gain in exchange is the thing the opening box is about: no lead authority, no three-week hand-off, no queue behind an Irish or Luxembourgish docket. Your national body decides your national case.

In practice most measurement findings are both at once — an unlawful cookie write and unlawful profiling of what it collects — and the two halves go to two places under two rules. Say in the paper which half you filed where.

The one-stop-shop, and when it swallows your complaint

For cross-border processing — Art. 4(23): more than one establishment, or a single establishment whose processing “substantially affects … data subjects in more than one Member State” — Art. 56(1) makes the supervisory authority of the controller's main establishment the lead, and Art. 56(6) makes it “the sole interlocutor of the controller”. You still file locally; your authority then informs the lead, which has three weeks to decide whether to take the case (Art. 56(3)). If it takes it, Art. 60 applies and your own authority's role shrinks to notifying you of the outcome (Art. 60(7)) — unless the complaint is dismissed, in which case your local authority adopts and notifies that decision itself (Art. 60(8)).

The escape hatch is Art. 56(2): each authority “shall be competent to handle a complaint lodged with it … if the subject matter relates only to an establishment in its Member State or substantially affects data subjects only in its Member State.” If your finding is genuinely local — a national news site, a government portal, a country-specific CMP deployment — say so explicitly in the complaint, because it is the difference between a case your authority decides and a case that joins a queue in Dublin or Luxembourg.

Adopted but not yet in force: Regulation (EU) 2025/2518. The GDPR procedural regulation was signed on 26 November 2025 and published in the Official Journal on 12 December 2025, but it applies only from 2 April 2027.10) Until then, the Art. 56/60/65 mechanics above are what actually happens. From April 2027 it fixes an exhaustive admissibility list for a cross-border complaint — name and contact details; proof of constitution and, under Art. 80(1), of mandate for an NGO; “information which facilitates the identification of the controller or processor”; and “a description of the alleged infringement” — and says “No information additional to that … shall be required”, with a two-week deadline for the authority to declare a complaint inadmissible. Its Art. 4(3) also settles a question this page otherwise cannot: you are not required to have contacted the controller before lodging a complaint (except where the complaint is about a data-subject request you had to make first). If you are planning a filing that will land after April 2027, write it to that list.

Proposed, and it would reverse the box at the top of this page: the Digital Omnibus. On 19 November 2025 the Commission proposed a regulation that lifts terminal-equipment consent out of ePrivacy and into the GDPR. Its explanatory memorandum: “A new Article 88a is inserted in Regulation (EU) 2016/679 … which lays down the consent requirement for the storing or accessing of personal data on the terminal equipment of natural persons and which brings the processing of personal data on and from terminal equipment within the rules of Regulation (EU) 2016/679”. The enacting text does it by subtraction on the other side: “After Article 5(3), the following subparagraph is added: 'This paragraph shall not apply if the subscriber or user is a natural person, and the information stored or accessed constitutes or leads to the processing of personal data.'”11)

If adopted as drafted, a cookie finding about a natural person's personal data becomes a GDPR case and therefore enters the one-stop-shop — the Irish DPC, not CNIL, for a controller established in Ireland. Only non-personal terminal data would stay under ePrivacy Art. 5(3).

It is a proposal, not law. As of 2026-08-18 the European Parliament's Legislative Observatory records procedure 2025/0360(COD) as “Awaiting committee decision”: referred to committee on 19 January 2026, ITRE rapporteur appointed 25 February 2026, no first-reading position.12) So everything in the box at the top of this page is the law today. But if you are writing a compliance paper whose legal analysis has to survive review in 2027, cite the date you checked and say which regime you assumed.

The DSA, and the data-access route

If your finding is about a platform rather than a website's tracking — recommender systems, ad repositories, illegal content, dark patterns in a VLOP interface — the instrument is the DSA (Regulation (EU) 2022/2065), not the GDPR. Article 53 gives recipients of the service, and mandated bodies, the right to complain to the Digital Services Coordinator of the Member State where they are located, which then assesses it and may transmit it to the DSC of establishment — the same shape as Art. 60, with the local filing point preserved. The Commission publishes the DSC list at digital-strategy.ec.europa.eu/en/policies/dsa-dscs.

More interesting for a measurement group is Article 40, the vetted-researcher data access route, which is now operational rather than aspirational: Commission Delegated Regulation (EU) 2025/2050 of 1 July 2025 is in force, and the DSA data access portal at data-access.dsa.ec.europa.eu is live.13) Access runs through the DSC of establishment on a reasoned request, for research into systemic risks under Art. 34(1). No paper in this corpus reports using it. A sweep for the Art. 40 vocabulary returns seven papers and all seven are something else — Censys' own vetted-researcher programme, an artifact-release policy, a trusted-flagger mention, an advocacy citation.14) Most of the corpus's submission cycles close before the portal opened in late 2025, though the 2026 venue-years do not, so this is a “not yet”, not a “nobody wants it”. Either way this page cannot tell you what the experience is like, only that the door now exists.

United States

  • FTC. The public intake is reportfraud.ftc.gov, which is a consumer-fraud form and a poor fit for a 40-page measurement. Seven corpus papers reached the FTC anyway, and the routes they used were a research relationship, a preprint, and a public forum, not the form: [5Reardon, Joel; Feal, Álvaro; Wijesekera, Primal; Elazari Bar On, Amit; Vallina-Rodriguez, Narseo; Egelman, Serge (2019): "50 Ways to Leak Your Data: An Exploration of Apps' Circumvention of the Android Permissions System", in: Proceedings of the USENIX Security Symposium. (Link)] disclosed to Google and the FTC together; [6Cheng, Long; Wilson, Christin; Liao, Song; Young, Jeffrey; Dong, Daniel; Hu, Hongxin (2020): "Dangerous Skills Got Certified: Measuring the Trustworthiness of Skill Certification in Voice Personal Assistant Platforms", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)] “shared our results to Federal Trade Commission (FTC) researchers”; [8Iqbal, Umar; Bahrami, Pouneh Nikkhah; Trimananda, Rahmadi; Cui, Hao; Gamero-Garrido, Alexander; Dubois, Daniel J.; Choffnes, David R.; Markopoulou, Athina; Roesner, Franziska; Shafiq, Zubair (2023): "Tracking, Profiling, and Ad Targeting in the Alexa Echo Smart Speaker Ecosystem", in: Proceedings of the ACM Internet Measurement Conference. (DOI)] presented at an FTC public forum. The FTC's own standing invitation is to its technology office — but go to the current one, not the one the invitation names. The FTC's PrivacyCon call page still invites researchers to “reach out to … the Office of Technology Research and Investigation”; that office no longer exists under that name. Since February 2023 the FTC has run an Office of Technology (ftc.gov/office-technology).15)
  • California. Two bodies, both taking complaints: the Attorney General (oag.ca.gov/privacy/ccpa) and the CPPA (cppa.ca.gov/webapplications/complaint). The AG is explicit about what it is doing with your complaint: “The Attorney General does not represent individual California consumers. Using consumer complaints and other information, the Attorney General may identify patterns of misconduct that may lead to investigations and actions on behalf of the collective legal interests of the people of California.”. A systematic measurement across hundreds of businesses is exactly a pattern, which makes this a better fit than the fraud-report shape of the FTC form.
  • The 30-day cure period is gone, and a 2023 paper relied on it. [10Zimmeck, Sebastian; Wang, Oliver; Alicki, Kuba; Wang, Jocelyn; Eng, Sophie (2023): "Usability and Enforceability of Global Privacy Control", Proceedings on Privacy Enhancing Technologies 2023(2). (DOI)] notified 47 non-compliant sites and told them the email “may serve as a notice for triggering the 30-day cure period per the CCPA to prepare potential enforcement actions by the OAG” — an elegant move that turned a research notification into a statutory clock. Do not copy it. The CPRA deleted the mandatory cure period with effect from 1 January 2023, and AB 137 (2025) reorganised enforcement into Cal. Civ. Code § 1798.155 (CPPA administrative fines) and § 1798.199.90 (AG civil penalties) without reinstating it.16) A notification today is a notification; it starts no clock.
  • COPPA. If your population is children's sites or apps, the FTC's amended COPPA Rule is in force: published 22 April 2025, effective 23 June 2025, general compliance date 22 April 2026 — in the past.17) A COPPA measurement whose legal analysis is written against the pre-2025 Rule is measuring against a superseded text — this is the single most likely way for a children's-privacy paper submitted in 2026 to be wrong about the law.

Elsewhere

26 corpus papers assess a non-EU, non-US data protection law, and the enforcement models differ enough that a European intuition transfers badly. [23Jing, Tao; Li, Yao; Ye, Jingzhou; Wang, Jie; Wang, Xueqiang (2025): "Privacy Law Enforcement Under Centralized Governance: A Qualitative Analysis of Four Years' Special Privacy Rectification Campaigns", in: Proceedings of the USENIX Security Symposium. (Link)] is the one study in the corpus of a regime built the other way round: China's Special Privacy Rectification Campaigns, “characterized by large-scale privacy reviews and strict sanctions, under the strong control of central authorities” — enforcement as a periodic centrally-run sweep of the app ecosystem rather than as a response to individual complaints. If you are measuring compliance outside the EU/US, read it before assuming there is a complaint form at all.

What a filing has to contain

The corpus cannot tell you this — no paper reproduces its filing. What it can be reconstructed from is the admissibility list in Reg. (EU) 2025/2518 Art. 4 (above), what DPAs say makes a case investigable, and what the papers that got a response had in common. That list is for cross-border GDPR complaints from April 2027; for an ePrivacy complaint today the form is whatever the national transposing statute says, and the items below are a working checklist rather than an admissibility test. Treat none of it as authority:

  1. A named complainant who is a data subject, with the evidence that they are one. Not “we crawled 100k sites” but “the following was written into my terminal at this timestamp”.
  2. The controller, identified. Reg. 2025/2518 Art. 4(1)(d) asks for “information which facilitates the identification of the controller or processor”. For a third-party tracker this is real work: the domain is not the company. See webXray for the ownership databases and how much they disagree.
  3. The provision breached, named as an article of the national law. “Art. 5(3) ePrivacy Directive, as transposed by § 25 TDDDG” is a case; “the site is not GDPR compliant” is not. This is also where the ePrivacy/GDPR split has to be made explicit — and note that the German provision is the same example this page would have written as “§ 25 TTDSG” two years ago: the statute was renamed to TDDDG in 2024, section number unchanged.18)
  4. Reproducible evidence, not a table of percentages. A HAR or a request log with timestamps, the screenshots of the banner state, the exact user journey, and the crawler configuration. See Traffic files and Automated measurements.
  5. The measurement's own error rate. Your detector's false-positive rate is now the authority's evidentiary problem. Give it, and give the manual validation behind it — see Website classification for what a validation section should look like.
  6. Why it is a local case, if it is (Art. 56(2)), or an acknowledgement that it is cross-border and will go to the lead authority.
  7. The scale, separately from the individual case. The individual complaint is what makes it admissible; the corpus-wide result is what makes it worth an authority's time. Attach the paper, but do not make the paper the complaint.
  8. Whether you also notified the operators, and what happened. Art. 4(3) of Reg. 2025/2518 will confirm from April 2027 that you do not have to have done so — for cross-border GDPR complaints only — but an authority weighing whether to open a file will want to know either way.

What came back

The honest answer is: the literature almost never says. Of the fifteen papers that filed, most report the act and not the outcome. What outcomes are reported:

  • A regulator published its own report on the back of the paper. [7Gamba, Julien; Rashed, Mohammed; Razaghpanah, Abbas; Tapiador, Juan; Vallina-Rodriguez, Narseo (2020): "An Analysis of Pre-installed Android Software", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)], on pre-installed Android software: “Our work was also the basis of a report produced by the Spanish Data Protection Agency (AEPD)”. This is the strongest documented outcome in the corpus, and it took the form of the authority adopting the analysis rather than opening a case.
  • Findings reached an authority already investigating. [13Girish, Aniketh; Reardon, Joel; Tapiador, Juan; Matic, Srdjan; Vallina-Rodriguez, Narseo (2025): "Your Signal, Their Data: An Empirical Privacy Analysis of Wireless-scanning SDKs in Android", Proceedings on Privacy Enhancing Technologies 2025(3). (DOI)] shared a preprint with the EDPS, AEPD and CNIL, and separately notes that a specific SDK behaviour it measured “was investigated by the Spanish Data Protection Agency (AEPD)”.
  • Bug bounties and vendor fixes, from the platform arm rather than the regulator arm. [5Reardon, Joel; Feal, Álvaro; Wijesekera, Primal; Elazari Bar On, Amit; Vallina-Rodriguez, Narseo; Egelman, Serge (2019): "50 Ways to Leak Your Data: An Exploration of Apps' Circumvention of the Android Permissions System", in: Proceedings of the USENIX Security Symposium. (Link)] “responsibly disclosed our findings to Google and the U.S. Federal Trade Commission (FTC), and received a bug bounty”; [14Weerasekara, Nipuna; Moreno, José Miguel; Matic, Srdjan; Reardon, Joel; Tapiador, Juan; Vallina-Rodríguez, Narseo (2025): "Tracking Without Borders: Studying the Role of WebViews in Bridging Mobile and Web Tracking", Proceedings on Privacy Enhancing Technologies 2025(4). (DOI)] received an Android bounty for canvas fingerprinting in WebViews and reported the results to the EDPS and CNIL, while the Android Security Team “considered [the other reports] infeasible to fix so they remain exploitable in Android 16”. In both cases the measurable outcome came from the vendor, not the authority.
  • The one large, multi-armed disclosure. [16Vlummens, Tim; Girish, Aniketh; Weerasekara, Nipuna; Zuiderveen Borgesius, Frederik; Acar, Gunes; Vallina-Rodriguez, Narseo (2026): "Bridges to Self: Silent Web-to-App Tracking on Mobile via Localhost", in: Proceedings of the USENIX Security Symposium. (Link)] disclosed localhost web-to-app tracking to browser and OS vendors first and “to EU- and US-based data protection authorities” second, with “detailed technical reports, proof-of-concept applications, screen captures, and analysis scripts to support independent validation”. The paper reports that the process “led to mitigations deployed by major browser vendors, and the termination of tracking campaigns by Yandex and Meta”, and that the findings “have since informed public accountability mechanisms, including class action lawsuits in multiple jurisdictions, expert testimony before the Spanish Congress in the context of the Digital Service Act (DSA), and technical discussions at IETF and W3C. Note what it does not claim: it does not attribute those outcomes to the DPA filings specifically. The disclosure was to vendors, regulators and press at once, and the paper is careful not to separate their contributions. Neither should you when you cite it.
  • Nothing, or nothing stated. The remaining nine say only that they filed. [10Zimmeck, Sebastian; Wang, Oliver; Alicki, Kuba; Wang, Jocelyn; Eng, Sophie (2023): "Usability and Enforceability of Global Privacy Control", Proceedings on Privacy Enhancing Technologies 2023(2). (DOI)] is a tenth case of a different kind: it reports its operators' response rate in detail and has nothing to report from the OAG, because it never wrote to the OAG.

So the realistic expectation to plan around is: a filing is unlikely to produce a visible outcome within a paper's lifetime, and the outcomes that do appear come faster from platform vendors. That is an argument for doing both, in the order [16Vlummens, Tim; Girish, Aniketh; Weerasekara, Nipuna; Zuiderveen Borgesius, Frederik; Acar, Gunes; Vallina-Rodriguez, Narseo (2026): "Bridges to Self: Silent Web-to-App Tracking on Mobile via Localhost", in: Proceedings of the USENIX Security Symposium. (Link)] used — vendors first, because they can deploy a fix in weeks; authorities in parallel, because they are the only party that can make the practice unlawful for everyone.

What regulators act on, measured

Two corpus papers analyse enforcement output rather than producing it, and both bear on whether a complaint is worth writing.

[24Saemann, Marlene; Theis, Daniel; Urban, Tobias; Degeling, Martin (2022): "Investigating GDPR Fines in the Light of Data Flows", Proceedings on Privacy Enhancing Technologies 2022(4). (DOI)] coded 856 GDPR fines from the CMS Enforcement Tracker. They could identify the cause of the investigation for 295 of 856 (34%) — the rest of the summaries do not say — and among the causes they report, “45 fines (18%) are caused by complaints of other companies”, “61 fines (25%) caused by data subject complaints; 9 of them (15%) reported by (former) employees and 52 (85%) by customers”, and 111 (45%) where the authority acted on its own initiative after personal data was published somewhere public. Their overall conclusion is that “respective DPA actions are primarily based on customer complaints and unwanted disclosure of data”.19) Both of the two large causes are open to a researcher: file a complaint, or make the violation public. Publishing is an enforcement route in this data.

[25Sun, Chen; Jacobs, Evan; Lehmann, Daniel; Crouse, Andrew; Shastri, Supreeth (2023): "GDPRxiv: Establishing the State of the Art in GDPR Enforcement", Proceedings on Privacy Enhancing Technologies 2023(4). (DOI)] built a crawler over DPA, EDPB and court sources and reports the scale of the machine you are filing into: “On average, 2 enforcement decisions are issued every day”, and “Three countries (ESP, DNK, POL) account for 54% of all GDPR enforcements”. That concentration is worth knowing when you choose a forum for a genuinely local case.

The other direction: when the authority opens a file on you

A data protection authority is not only a recipient. It also regulates your study.

[26Utz, Christine; Amft, Sabrina; Degeling, Martin; Holz, Thorsten; Fahl, Sascha; Schaub, Florian (2023): "Privacy Rarely Considered: Exploring Considerations in the Adoption of Third-Party Services by Websites", Proceedings on Privacy Enhancing Technologies 2023(1):5-28. (DOI)] recruited website operators via GitHub for a survey. “Despite these efforts, one recipient filed a complaint with our state's data protection authority, upon which we immediately stopped recruitment via GitHub, rather than waiting for the outcome.” And then the part that should be on the wall of every group doing this work: “Three months later the DPA informed us that they did not consider the GDPR's research privilege to apply.”

That is one paper, one German state authority, one recruitment method. But it is the only documented case in the corpus of a DPA ruling on academic web-measurement recruitment, and it went against the researchers. The research derogations are not a blanket exemption, they are conditional and largely delegated to national law, and an authority can be asked to decide whether they apply by anybody who receives your email.

Four papers show the constructive version of the same relationship — a regulator authorising the study up front:

  • [27Bogdanov, Dan; Kamm, Liina; Kubo, Baldur; Rebane, Reimo; Sokk, Ville; Talviste, Riivo (2016): "Students and Taxes: a Privacy-Preserving Study Using Secure Computation", Proceedings on Privacy Enhancing Technologies 2016(3). (DOI)] — the Estonian Data Protection Inspectorate reviewed the secure-computation design and “indicated that we did not require a permission to process personal data”. An advance ruling that you do not need permission is worth as much as one that you do.
  • [28Singh, Rajkarn; Fiore, Marco; Marina, Mahesh K.; Tarable, Alberto; Nordio, Alessandro (2019): "Urban Vibes and Rural Charms: Analysis of Geographic Diversity in Mobile Service Usage at National Scale", in: Proceedings of the ACM Web Conference. (DOI)] and [29Zanella, André Felipe; Bazco-Nogueras, Antonio; Ziemlicki, Cezary; Fiore, Marco (2023): "Characterizing and Modeling Session-Level Mobile Traffic Demands from Large-Scale Measurements", in: Proceedings of the ACM Internet Measurement Conference. (DOI)] — mobile-operator datasets used under CNIL approval.
  • [30Li, Ruixuan; Xiao, Shaodong; Liu, Baojun; Lin, Yanzhong; Duan, Haixin; Pan, Qingfeng; Chen, Jianjun; Zhang, Jia; Liu, Ximeng; Lu, Xiuqi; Shao, Jun (2024): "Bounce in the Wild: A Deep Dive into Email Delivery Failures from a Large Email Service Provider", in: Proceedings of the ACM Internet Measurement Conference. (DOI)] — an email-provider partnership “authorized and supervised by the network management department and regulatory authority of our partner”, at an institution with no IRB.

If your study needs data that an operator cannot lawfully hand over on its own judgement, going to the authority first is the mechanism that makes it possible. See Ethics.

And the argument for not filing

[31Nguyen, Trung Tin; Backes, Michael; Marnau, Ninja; Stock, Ben (2021): "Share First, Ask Later (or Never?) Studying Violations of GDPR's Explicit Consent in Android Apps", in: Proceedings of the USENIX Security Symposium. (Link)], having found GDPR consent violations across Android apps, wrote down the reasoning most papers leave implicit: “Since disclosing the findings to authorities (e.g., regulators, Google) might cause financial harm to developers, we consciously decided not to involve authorities but rather notify developers directly to remedy compliance issues.”

This is a defensible position and it is the one most of the field takes silently. The difference between [31Nguyen, Trung Tin; Backes, Michael; Marnau, Ninja; Stock, Ben (2021): "Share First, Ask Later (or Never?) Studying Violations of GDPR's Explicit Consent in Android Apps", in: Proceedings of the USENIX Security Symposium. (Link)] and the 130 papers that assessed a law and said nothing about a regulator is that this one argued it. If you decide not to file — because your population is small operators rather than platforms, because the violation is ambiguous, because your detector's precision does not justify exposing individuals to fines — say so and say why. A reviewer will accept a reasoned decision not to escalate; the corpus suggests they rarely see one.

A reporting checklist

What to put in the paper, drawn from what the fifteen filings report and what the 170 violation-finding papers that did not file omit. (Note that it is 170 and not 177 − 15: only 7 of the fifteen filers are themselves in the violation-finding population — the rest found a vulnerability or a policy gap rather than a legal breach.)

  1. Which law, by article. Not “GDPR” — the article, and for terminal access, the national transposition of ePrivacy Art. 5(3). Your legal section is unreadable to a lawyer without it.
  2. Which authority is competent for your finding, and why: one-stop-shop or not, local case under Art. 56(2) or not.
  3. Whether you contacted one, which one, on what date, and through what channel. “We disclosed responsibly” is not an answer to this question, and it is where the modal paper stops: of the 2,870 empirical papers that give any free-text disclosure detail, 12 (0.4%) name a privacy or consumer-protection authority.
  4. What came back, including nothing. A filing with no response after eight months is a finding about the enforcement system; report it.
  5. Whether you also notified the operators, and how the two channels were sequenced.
  6. Your reasoning if you did not file. See above.
  7. Any regulator involvement in your own study: authorisation, DPO sign-off, a complaint against you, a national research derogation you relied on and its legal basis.
  8. Your detector's precision, again — the number that decides whether a complaint is evidence or an accusation.
  9. The date you checked the law. COPPA changed in 2025, the CCPA cure period vanished in 2023, and Reg. (EU) 2025/2518 changes complaint handling in April 2027. A legal analysis with no date on it is unciteable a year later.

Papers to read first

If you read three: [1Bielova, Nataliia; Litvine, Laura; Nguyen, Anysia; Chammat, Mariam; Toubiana, Vincent; Hary, Estelle (2024): "The Effect of Design Patterns on (Present and Future) Cookie Consent Decisions", in: Proceedings of the USENIX Security Symposium. (Link)] for the one clear statement in the corpus of the ePrivacy/one-stop-shop split, and for what a regulator-commissioned study looks like; [26Utz, Christine; Amft, Sabrina; Degeling, Martin; Holz, Thorsten; Fahl, Sascha; Schaub, Florian (2023): "Privacy Rarely Considered: Exploring Considerations in the Adoption of Third-Party Services by Websites", Proceedings on Privacy Enhancing Technologies 2023(1):5-28. (DOI)] for the DPA complaint filed against researchers and the research-privilege ruling; and [16Vlummens, Tim; Girish, Aniketh; Weerasekara, Nipuna; Zuiderveen Borgesius, Frederik; Acar, Gunes; Vallina-Rodriguez, Narseo (2026): "Bridges to Self: Silent Web-to-App Tracking on Mobile via Localhost", in: Proceedings of the USENIX Security Symposium. (Link)] for the most fully documented multi-party disclosure, with its timeline table. Then [24Saemann, Marlene; Theis, Daniel; Urban, Tobias; Degeling, Martin (2022): "Investigating GDPR Fines in the Light of Data Flows", Proceedings on Privacy Enhancing Technologies 2022(4). (DOI)] and [25Sun, Chen; Jacobs, Evan; Lehmann, Daniel; Crouse, Andrew; Shastri, Supreeth (2023): "GDPRxiv: Establishing the State of the Art in GDPR Enforcement", Proceedings on Privacy Enhancing Technologies 2023(4). (DOI)] for what regulators actually act on and at what rate, [10Zimmeck, Sebastian; Wang, Oliver; Alicki, Kuba; Wang, Jocelyn; Eng, Sophie (2023): "Usability and Enforceability of Global Privacy Control", Proceedings on Privacy Enhancing Technologies 2023(2). (DOI)] for the notification-as-statutory-trigger design (and for why it no longer works), [7Gamba, Julien; Rashed, Mohammed; Razaghpanah, Abbas; Tapiador, Juan; Vallina-Rodriguez, Narseo (2020): "An Analysis of Pre-installed Android Software", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] for the one case where an authority adopted the analysis, and [31Nguyen, Trung Tin; Backes, Michael; Marnau, Ninja; Stock, Ben (2021): "Share First, Ask Later (or Never?) Studying Violations of GDPR's Explicit Consent in Android Apps", in: Proceedings of the USENIX Security Symposium. (Link)] for the reasoned decision not to escalate.

  • Notifying websites — the operator-facing channel, contact discovery, response rates and control groups. Read it first if you have not decided which route you are taking.
  • Ethics — approval, harm from crawling, and the legal aspects of the crawl itself.
  • Consent — what you are measuring when you measure a cookie banner.
  • Cookies and Requests — the classification your legal claim rests on.
  • Crawling location — the vantage point determines which national transposition applies to what you observed.
  • Public relations — publication as the other enforcement route, per [24Saemann, Marlene; Theis, Daniel; Urban, Tobias; Degeling, Martin (2022): "Investigating GDPR Fines in the Light of Data Flows", Proceedings on Privacy Enhancing Technologies 2022(4). (DOI)].
  • Artifacts — the evidence pack and the crawl configuration a regulator would need.

Methodology and limitations of these figures

Every corpus figure above comes from scripts/report_legal_enforcement.mjs over data/extract/run1 (5,859 papers, 2010–2026). Four limits carry directly:

  • Seven venues only. EuroS&P, ACSAC, RAID, AsiaCCS, CHI and SOUPS are absent, and so is the entire legal literature: this is a claim about what computer science venues report, not about what happens at data protection authorities. A page on DPA practice written from law reviews would look completely different.
  • ethics.regulatorContact conflates three different things — a CERT, a sector regulator and a data protection authority — into one enum. Every figure derived from it is an upper bound on “went to a privacy regulator”. The hand-coded map exists because of this, and it cuts the count from 27 to 15.
  • The hand-coded map is a sweep plus reading, not a census, and fifteen is not a hard number. 95 papers were read out of 5,859; the sweep that produced 89 of them requires an authority name and a first-person verb in the same sentence, and it demonstrably missed six papers that other routes found — so recall pushes the count up. Coding generosity pushes it down: [10Zimmeck, Sebastian; Wang, Oliver; Alicki, Kuba; Wang, Jocelyn; Eng, Sophie (2023): "Usability and Enforceability of Global Privacy Control", Proceedings on Privacy Enhancing Technologies 2023(2). (DOI)] is counted as a filing although it wrote to operators and only invoked the OAG, and a reasonable person would exclude it. Read the number as “about fifteen, of which fourteen are unambiguous”.
  • The external legal material is not from the corpus and is dated. Every statute, decision and URL in the sections above was fetched from a primary source on 2026-08-18 and is cited with that date. Law moves: three items on this page changed within the last three years, one changes in April 2027, and one live legislative proposal would reverse the page's opening claim.

The complete query log, the report script with its unedited output, the law fold with its unmapped residue, all 34 quotes with their verification verdict, the 67 off-topic papers with the reason each was excluded, and every external source with how it was verified are on legal_enforcement. Corpus-wide caveats are on Corpus.

References

[1]
Bielova, Nataliia; Litvine, Laura; Nguyen, Anysia; Chammat, Mariam; Toubiana, Vincent; Hary, Estelle (2024): "The Effect of Design Patterns on (Present and Future) Cookie Consent Decisions", in: Proceedings of the USENIX Security Symposium. (Link)
[2]
Feal, Álvaro; Calciati, Paolo; Vallina-Rodriguez, Narseo; Troncoso, Carmela; Gorla, Alessandra (2020): "Angel or Devil? A Privacy Study of Mobile Parental Control Apps", Proceedings on Privacy Enhancing Technologies 2020(2). (DOI)
[3]
Murdoch, Steven J.; Drimer, Saar; Anderson, Ross; Bond, Mike (2010): "Chip and PIN is Broken", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)
[4]
Zimmeck, Sebastian; Story, Peter; Smullen, Daniel; Ravichander, Abhilasha; Wang, Ziqi; Reidenberg, Joel; Russell, N. Cameron; Sadeh, Norman (2019): "MAPS: Scaling Privacy Compliance Analysis to a Million Apps", Proceedings on Privacy Enhancing Technologies 2019(3). (DOI)
[5]
Reardon, Joel; Feal, Álvaro; Wijesekera, Primal; Elazari Bar On, Amit; Vallina-Rodriguez, Narseo; Egelman, Serge (2019): "50 Ways to Leak Your Data: An Exploration of Apps' Circumvention of the Android Permissions System", in: Proceedings of the USENIX Security Symposium. (Link)
[6]
Cheng, Long; Wilson, Christin; Liao, Song; Young, Jeffrey; Dong, Daniel; Hu, Hongxin (2020): "Dangerous Skills Got Certified: Measuring the Trustworthiness of Skill Certification in Voice Personal Assistant Platforms", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)
[7]
Gamba, Julien; Rashed, Mohammed; Razaghpanah, Abbas; Tapiador, Juan; Vallina-Rodriguez, Narseo (2020): "An Analysis of Pre-installed Android Software", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)
[8]
Iqbal, Umar; Bahrami, Pouneh Nikkhah; Trimananda, Rahmadi; Cui, Hao; Gamero-Garrido, Alexander; Dubois, Daniel J.; Choffnes, David R.; Markopoulou, Athina; Roesner, Franziska; Shafiq, Zubair (2023): "Tracking, Profiling, and Ad Targeting in the Alexa Echo Smart Speaker Ecosystem", in: Proceedings of the ACM Internet Measurement Conference. (DOI)
[9]
Yeung, Christina; Iqbal, Umar; O'Neil, Yekaterina Tsipenyuk; Kohno, Tadayoshi; Roesner, Franziska (2023): "Online Advertising in Ukraine and Russia During the 2022 Russian Invasion", in: Proceedings of the ACM Web Conference. (DOI)
[10]
Zimmeck, Sebastian; Wang, Oliver; Alicki, Kuba; Wang, Jocelyn; Eng, Sophie (2023): "Usability and Enforceability of Global Privacy Control", Proceedings on Privacy Enhancing Technologies 2023(2). (DOI)
[11]
Arunasalam, Arjun; Chu, Andrew; Ozmen, Muslum Ozgur; Farrukh, Habiba; Celik, Z. Berkay (2024): "The Dark Side of E-Commerce: Dropshipping Abuse as a Business Model", in: Proceedings of the Network and Distributed System Security Symposium. (Link)
[12]
Moti, Zahra; Senol, Asuman; Bostani, Hamid; Zuiderveen Borgesius, Frederik J.; Moonsamy, Veelasha; Mathur, Arunesh; Acar, Gunes (2024): "Targeted and Troublesome: Tracking and Advertising on Children's Websites", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)
[13]
Girish, Aniketh; Reardon, Joel; Tapiador, Juan; Matic, Srdjan; Vallina-Rodriguez, Narseo (2025): "Your Signal, Their Data: An Empirical Privacy Analysis of Wireless-scanning SDKs in Android", Proceedings on Privacy Enhancing Technologies 2025(3). (DOI)
[14]
Weerasekara, Nipuna; Moreno, José Miguel; Matic, Srdjan; Reardon, Joel; Tapiador, Juan; Vallina-Rodríguez, Narseo (2025): "Tracking Without Borders: Studying the Role of WebViews in Bridging Mobile and Web Tracking", Proceedings on Privacy Enhancing Technologies 2025(4). (DOI)
[15]
Zhang, Xin; Zhang, Xiaohan; Zhao, Bo; Nan, Yuhong; Liu, Zhichen; Chen, Jianzhou; Zhou, Huijun; Yang, Min (2025): "Demystifying the (In)Security of QR Code-based Login in Real-world Deployments", in: Proceedings of the USENIX Security Symposium. (Link)
[16]
Vlummens, Tim; Girish, Aniketh; Weerasekara, Nipuna; Zuiderveen Borgesius, Frederik; Acar, Gunes; Vallina-Rodriguez, Narseo (2026): "Bridges to Self: Silent Web-to-App Tracking on Mobile via Localhost", in: Proceedings of the USENIX Security Symposium. (Link)
[17]
Trevisan, Martino; Traverso, Stefano; Bassi, Eleonora; Mellia, Marco (2019): "4 Years of EU Cookie Law: Results and Lessons Learned", Proceedings on Privacy Enhancing Technologies 2019(2):126-145. (DOI)
[18]
Girish, Aniketh; Hu, Tianrui; Prakash, Vijay; Dubois, Daniel J.; Matic, Srdjan; Huang, Danny Yuxing; Egelman, Serge; Reardon, Joel; Tapiador, Juan; Choffnes, David R.; Vallina-Rodriguez, Narseo (2023): "In the Room Where It Happens: Characterizing Local Communication and Threats in Smart Homes", in: Proceedings of the ACM Internet Measurement Conference. (DOI)
[19]
Morel, Victor; Santos, Cristiana; Carlsson, Pontus; Ahlinder, Joel; Duvignau, Romaric (2026): "The TCF doesn't really A(A)ID - Automatic Privacy Analysis and Legal Compliance of TCF-based Android Applications", Proceedings on Privacy Enhancing Technologies 2026(3). (DOI)
[20]
Brookman, Justin; Rouge, Phoebe; Alva, Aaron; Yeung, Christina (2017): "Cross-Device Tracking: Measurement and Disclosures", Proceedings on Privacy Enhancing Technologies 2017(2). (DOI)
[21]
Fouad, Imane; Santos, Cristiana; Legout, Arnaud; Bielova, Nataliia (2022): "My Cookie is a phoenix: detection, measurement, and lawfulness of cookie respawning with browser fingerprinting", in: Proceedings on Privacy Enhancing Technologies. (DOI)
[22]
Toth, Michael; Bielova, Nataliia; Roca, Vincent (2022): "On dark patterns and manipulation of website publishers by CMPs", Proceedings on Privacy Enhancing Technologies 2022(3). (DOI)
[23]
Jing, Tao; Li, Yao; Ye, Jingzhou; Wang, Jie; Wang, Xueqiang (2025): "Privacy Law Enforcement Under Centralized Governance: A Qualitative Analysis of Four Years' Special Privacy Rectification Campaigns", in: Proceedings of the USENIX Security Symposium. (Link)
[24]
Saemann, Marlene; Theis, Daniel; Urban, Tobias; Degeling, Martin (2022): "Investigating GDPR Fines in the Light of Data Flows", Proceedings on Privacy Enhancing Technologies 2022(4). (DOI)
[25]
Sun, Chen; Jacobs, Evan; Lehmann, Daniel; Crouse, Andrew; Shastri, Supreeth (2023): "GDPRxiv: Establishing the State of the Art in GDPR Enforcement", Proceedings on Privacy Enhancing Technologies 2023(4). (DOI)
[26]
Utz, Christine; Amft, Sabrina; Degeling, Martin; Holz, Thorsten; Fahl, Sascha; Schaub, Florian (2023): "Privacy Rarely Considered: Exploring Considerations in the Adoption of Third-Party Services by Websites", Proceedings on Privacy Enhancing Technologies 2023(1):5-28. (DOI)
[27]
Bogdanov, Dan; Kamm, Liina; Kubo, Baldur; Rebane, Reimo; Sokk, Ville; Talviste, Riivo (2016): "Students and Taxes: a Privacy-Preserving Study Using Secure Computation", Proceedings on Privacy Enhancing Technologies 2016(3). (DOI)
[28]
Singh, Rajkarn; Fiore, Marco; Marina, Mahesh K.; Tarable, Alberto; Nordio, Alessandro (2019): "Urban Vibes and Rural Charms: Analysis of Geographic Diversity in Mobile Service Usage at National Scale", in: Proceedings of the ACM Web Conference. (DOI)
[29]
Zanella, André Felipe; Bazco-Nogueras, Antonio; Ziemlicki, Cezary; Fiore, Marco (2023): "Characterizing and Modeling Session-Level Mobile Traffic Demands from Large-Scale Measurements", in: Proceedings of the ACM Internet Measurement Conference. (DOI)
[30]
Li, Ruixuan; Xiao, Shaodong; Liu, Baojun; Lin, Yanzhong; Duan, Haixin; Pan, Qingfeng; Chen, Jianjun; Zhang, Jia; Liu, Ximeng; Lu, Xiuqi; Shao, Jun (2024): "Bounce in the Wild: A Deep Dive into Email Delivery Failures from a Large Email Service Provider", in: Proceedings of the ACM Internet Measurement Conference. (DOI)
[31]
Nguyen, Trung Tin; Backes, Michael; Marnau, Ninja; Stock, Ben (2021): "Share First, Ask Later (or Never?) Studying Violations of GDPR's Explicit Consent in Android Apps", in: Proceedings of the USENIX Security Symposium. (Link)
1)
European Data Protection Board, Opinion 5/2019 on the interplay between the ePrivacy Directive and the GDPR, adopted 12 March 2019, §80 and §91. PDF, read 2026-08-18; the older /sites/default/files/… path 302-redirects here.
2)
Conseil d'État, decision n° 449209 of 28 January 2022 (and the earlier interim ruling n° 449212 of 4 March 2021 in the same case): “il n'a pas été prévu l'application du mécanisme dit du 'guichet unique' applicable aux traitements transfrontaliers, défini à l'article 56 de ce règlement, pour les mesures de mise en oeuvre et de contrôle de la directive 2002/58/CE du 12 juillet 2002, qui relèvent de la compétence des autorités nationales de contrôle en vertu de l'article 15 bis de cette directive”, citing CJEU Planet49 (C-673/17) and Facebook Ireland (C-645/19). conseil-etat.fr, read 2026-08-18.
3)
Fisher's exact test, two-sided, p = 0.047. This is a post-hoc split chosen after looking at the per-window table, on small counts, and it is the only test on this page — read it as “the decline is probably not pure noise”, not as a result. The year-by-year table is on legal_enforcement.
4)
Regulation (EU) 2016/679, retrieved from the EU Publications Office CELLAR service (publications.europa.eu/resource/celex/32016R0679) on 2026-08-18; EUR-Lex's own HTML front end returns an HTTP 202 bot challenge to automated fetchers.
5)
The source page reads “Utrech University”; the missing t is noyb's typo, not a transcription error here.
6)
noyb, noyb aims to end “cookie banner terror” and issues more than 500 GDPR complaints, noyb.eu, read 2026-08-18. noyb publishes no general submission portal for researchers; its “About us” and FAQ pages describe mission, funding and membership only, so the route is a direct approach, not a form.
7)
The older /about-edpb/about-edpb/members_en path now 301-redirects here; checked 2026-08-18.
8)
EDPS, Private organisation, edps.europa.eu.
9)
EDPB Opinion 5/2019, §§64 and 90.
10)
Regulation (EU) 2025/2518 laying down additional procedural rules on the enforcement of Regulation (EU) 2016/679, OJ L, 2025/2518, 12.12.2025, Art. 37(2): “This Regulation shall apply from 2 April 2027.” Retrieved from the Publications Office CELLAR service on 2026-08-18.
11)
COM(2025) 837 final, Brussels 19.11.2025, procedure 2025/0360(COD), Digital Omnibus (Omnibus VII); retrieved from the Publications Office CELLAR service on 2026-08-18. The proposal also adds an Article 88b on machine-readable consent signalling.
12)
Read from oeil.secure.europarl.europa.eu on 2026-08-18.
13)
Commission Delegated Regulation (EU) 2025/2050 of 1 July 2025 supplementing Regulation (EU) 2022/2065 …, OJ L, 2025/2050, 9.10.2025, in force twenty days after publication (29 October 2025); retrieved from the Publications Office CELLAR service on 2026-08-18. Announcement: digital-strategy.ec.europa.eu; portal returning HTTP 200 on 2026-08-18.
14)
report_legal_enforcement.mjs section F2; the seven keys and the reason each was rejected are on legal_enforcement.
15)
The call page at ftc.gov/privacycon-call-for-presentations is stale in three ways at once: it names a superseded office, names an “Acting Chief” of it, and carries submission deadlines from 2016. The last PrivacyCon with a live FTC event page is 6 March 2024; /2025/03/privacycon-2025 and /2026/03/privacycon-2026 both return 404, although ftc.gov's events index still calls PrivacyCon annual. All checked 2026-08-18. Note ftc.gov returns HTTP 403 to a bare curl; a browser User-Agent gets 200.
16)
Current statutory text of Cal. Civ. Code §§ 1798.155 and 1798.199.90, both “Amended by Stats. 2025, Ch. 20, Sec. 1./Sec. 4. (AB 137) Effective June 30, 2025”, retrieved from leginfo.legislature.ca.gov on 2026-08-18: neither section contains any cure language. A narrower cure opportunity survives only in the § 1798.150 private right of action for data breaches, which is a different provision.
17)
90 Fed. Reg. 16918 (22 April 2025), govinfo.gov. Biometric identifiers are now “personal information”; separate verifiable parental consent is required for disclosures not integral to the service; written security-programme and retention-policy requirements are new.
18)
Verified 2026-08-18 at gesetze-im-internet.de, whose URL path still reads ttdsg while the heading reads “§ 25 TDDDG — Gesetz über den Datenschutz und den Schutz der Privatsphäre in der Telekommunikation und bei digitalen Diensten”.
19)
The three percentages Saemann et al. report are internally consistent with a base of about 245, not the 295 they give for the identifiable-cause set; the paper does not reconcile them. The shape is safe to use, the exact base is not — see legal_enforcement.
You could leave a comment if you were logged in.
practices/legal_enforcement.1787052116.txt.gz · Last modified: by karel.kubicek.claude

Except where otherwise noted, content on this wiki is licensed under the following license: CC BY-NC-SA 4.0
CC BY-NC-SA 4.0 Donate Powered by PHP Valid HTML5 Valid CSS Driven by DokuWiki