Blog posts

Is tracking data linked with cookie and fingerprinting IDs personal data under the GDPR?

Is tracking data linked with cookie and fingerprinting IDs personal data under the GDPR?

Tracking companies collect vast amounts of data about individuals with dangerous implications, all while usually not knowing their names. I comprehensively analyzed whether tracking data linked to cookie and fingerprinting IDs constitutes personal data under the GDPR, reviewing relevant case law, legal literature, and data protection authority guidance.

Tweasel update: Request database, tracker documentation and legal research

Our tweasel updates are back after the summer. We have made our request data publicly available, such that anyone can run SQL queries against our datasets. We have also better documented many of our TrackHAR adapters. Furthermore, we have begun doing legal research to inform our decisions on how to establish tracker IDs as personal data in our complaints.

Tweasel update: Switching to a better unpinning script, fixing bugs and writing docs

The third installment of our semi-regular updates on the development of the tweasel project. This time, we have switched to a different certificate pinning bypass script and fixed various bugs on different platforms and devices. We have also continued working on our documentation and outreach, and collected new traffic data for our TrackHAR adapters.

Tweasel update: Building libraries and automating setup

I gave an update on our progress with the tweasel project. We have released first versions of our libraries and tools for instrumenting and analyzing mobile apps and their traffic. We have worked on automating the installation of dependencies and device setup. We have launched our documentation website for tracking endpoints and their data. We have also given a talk at the FireShonks event and a presentation to the EDPB tech advisory board.

Legal requirements for tracking and consent dialogs under the GDPR and ePrivacy directive

Legal requirements for tracking and consent dialogs under the GDPR and ePrivacy directive

Tracking and consent dialogs have become ubiquitous with seemingly every website and app pleading users to agree to their personal data being processed and their behaviour being tracked, often with the help of tens or even hundreds of third-party companies. But the bar for legally performing tracking in the EU is high. In this post, I detail both the legal requirements for tracking and collecting consent in general and present a comprehensive list of criteria for a legally compliant consent dialog.

Worrying confessions: A look at data safety labels on Android

Worrying confessions: A look at data safety labels on Android

I analyzed the new data safety section on the Google Play Store for datarequests.org and found popular apps admitting to collecting and sharing highly sensitive data for advertising and tracking. More than one quarter of apps transmitted tracking data not declared in their data safety label.

Page 1 of 2 Next Page