Back to Search Start Over

In-depth technical and legal analysis of Web tracking on health related websites with Ernie extension

Authors :
Wesselkamp, Vera
Fouad, Imane
Santos, Cristiana
Boussad, Yanis
Bielova, Nataliia
Legout, Arnaud
Privacy Models, Architectures and Tools for the Information Society (PRIVATICS)
Inria Grenoble - Rhône-Alpes
Institut National de Recherche en Informatique et en Automatique (Inria)-Institut National de Recherche en Informatique et en Automatique (Inria)-CITI Centre of Innovation in Telecommunications and Integration of services (CITI)
Institut National des Sciences Appliquées de Lyon (INSA Lyon)
Université de Lyon-Institut National des Sciences Appliquées (INSA)-Université de Lyon-Institut National des Sciences Appliquées (INSA)-Institut National de Recherche en Informatique et en Automatique (Inria)-Institut National des Sciences Appliquées de Lyon (INSA Lyon)
Université de Lyon-Institut National des Sciences Appliquées (INSA)-Université de Lyon-Institut National des Sciences Appliquées (INSA)
Utrecht University [Utrecht]
Design, Implementation and Analysis of Networking Architectures (DIANA)
Inria Sophia Antipolis - Méditerranée (CRISAM)
Institut National de Recherche en Informatique et en Automatique (Inria)-Institut National de Recherche en Informatique et en Automatique (Inria)
Commission nationale de l'informatique des libertés (Cnil)
CNIL
Source :
20th Workshop on Privacy in the Electronic Society, 20th Workshop on Privacy in the Electronic Society, Nov 2021, Seoul, South Korea
Publication Year :
2021
Publisher :
HAL CCSD, 2021.

Abstract

International audience; Searching for doctors online has become an increasingly common practice among Web users. However, when health websites owned by doctors and hospitals integrate third-party trackers, they expose their potential patients' medical secrets to third parties, thereby violating the GDPR which only allows the processing of sensitive health data with the explicit consent of a user. While previous works detected sophisticated forms of cookie syncing at scale, no tool exists as of today that would allow owners of health websites detecting complex tracking practices and ensure legal compliance. In this paper, we develop Ernie-a browser extension that visualises six tracking and complex cookie syncing state of the art techniques. We report on the analysis with Ernie on 176 websites of medical doctors and hospitals that users would visit when searching for doctors in France and Germany. At least one form of tracking or cookie syncing occurs on 64% websites before interacting with the consent banner, and 76% of these websites fail to comply with the GDPR requirements on a valid explicit consent. Furthermore, an in-depth analysis of case study websites allowed us to provide comprehensive general explanations of why tracking is embedded: for example, in all 45 webpages, where doctors include a Google map to help locating their office, tracking occurs due to the Google's cookie already present in the user's browser which is attached to a request that fetched the Google map useful content.

Details

Language :
English
Database :
OpenAIRE
Journal :
20th Workshop on Privacy in the Electronic Society, 20th Workshop on Privacy in the Electronic Society, Nov 2021, Seoul, South Korea
Accession number :
edsair.od......2592..3622b01da0582ad1d6f9046dec9891e9