Proposal on How to Assess Effectiveness of Consent: Measuring the Actual Understanding of Risks After User Interaction with Information and Consent Dialogues

The present conformity assessment program was developed within the framework of the “Sicher im Datenverkehr” (Safe in Data Traffic) research project, funded by the German Federal Ministry of Research, Technology and Space (Bundesministerium Forschung, Technologie und Raumfahrt – BMFTR). The primary aim of the project was to examine users’ perceptions of data protection risks in the context of online advertisement and the processing of their data for personalisation purposes. The project concluded that a proper understanding of these risks must be an integral component of information dialogues to ensure that users can provide truly informed consent to data processing as well as meaningfully exercise their data subject’s rights. This conformity assessment programme was designed and developed based on the findings of the project. It provides a module that can either form part of a GDPR-specific conformity assessment programme, covering the obligations on transparency and intervenability, or serve as a materialisation of these obligations within a general programme. This supports the design of GDPR-compliant and legally safe information and consent dialogues in practice. The programme covers the assessment of information and consent dialogues, such as cookie banners, consent management systems and privacy dashboards, as applied by data controllers seeking a certificate of compliance and efficacy for their systems. The programme’s central methodological innovation is a participatory assessment approach that measures the effectiveness of these dialogues by comparing the understanding and ability of lay users to act on information about data processing with that of experts, rather than relying on an absolute measure. Additionally, the programme specifies the relevant test properties and permissible assessment methods, the types and forms of evidence to be provided, and the methodologies for verifying them.

Authors

Institutions

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-09-14
DOI
https://doi.org/10.5281/zenodo.22655604
Primary Topic
Privacy, Security, and Data Protection
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Proposal on How to Assess Effectiveness of Consent: Measuring the Actual Understanding of Risks After User Interaction with Information and Consent Dialogues

Maurice Stenzel, Philipp Hagen, Jörg Pohle, Daniel Guagnin
Zenodo (CERN European Organization for Nuclear Research)
Privacy, Security, and Data Protection
article

Proposal on How to Assess Effectiveness of Consent: Measuring the Actual Understanding of Risks After User Interaction with Information and Consent Dialogues

Maurice Stenzel, Philipp Hagen, Jörg Pohle, Daniel Guagnin
article en

Abstract

The present conformity assessment program was developed within the framework of the “Sicher im Datenverkehr” (Safe in Data Traffic) research project, funded by the German Federal Ministry of Research, Technology and Space (Bundesministerium Forschung, Technologie und Raumfahrt – BMFTR). The primary aim of the project was to examine users’ perceptions of data protection risks in the context of online advertisement and the processing of their data for personalisation purposes. The project concluded that a proper understanding of these risks must be an integral component of information dialogues to ensure that users can provide truly informed consent to data processing as well as meaningfully exercise their data subject’s rights. This conformity assessment programme was designed and developed based on the findings of the project. It provides a module that can either form part of a GDPR-specific conformity assessment programme, covering the obligations on transparency and intervenability, or serve as a materialisation of these obligations within a general programme. This supports the design of GDPR-compliant and legally safe information and consent dialogues in practice. The programme covers the assessment of information and consent dialogues, such as cookie banners, consent management systems and privacy dashboards, as applied by data controllers seeking a certificate of compliance and efficacy for their systems. The programme’s central methodological innovation is a participatory assessment approach that measures the effectiveness of these dialogues by comparing the understanding and ability of lay users to act on information about data processing with that of experts, rather than relying on an absolute measure. Additionally, the programme specifies the relevant test properties and permissible assessment methods, the types and forms of evidence to be provided, and the methodologies for verifying them.

Zenodo (CERN European Organization for Nuclear Research)
Ministry of Economy (MK), Alexander von Humboldt Institute for Internet and Society (DE), Nexus Institute for Cooperation Management and Interdisciplinary Research (DE)
Openalex Percentile: Top 4%
Privacy, Security, and Data Protection
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.