EDBT 2026 Demo / reviewers in the wild / expert
Konrad Kollnig
dblp:207/7892
· DBLP profile ↗
7ranked-venue papers
2as first author
7since 2021 · last 2026
0000-0002-7412-8731ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 4 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Understanding Data Collection, Brokerage, and Spam in the Lead Marketing EcosystemabstractThe lead marketing ecosystem enables collection, sale, and use of personal data submitted via web forms to deliver personalized quotes in high-value verticals such as insurance. Despite its scale and sensitivity of the collected data, this ecosystem remains largely unexplored by the research community. We present the first empirical study of privacy and spam risks in lead marketing, developing an end-toend measurement framework to trace data flows from data collection to consumer contact. Our setup instruments over 100 health-related lead-generation websites and monitors 200 controlled phone numbers and email addresses to understand downstream marketing practices. We observe sharing of highly personal and sensitive health information to more than 70 distinct third parties on these lead generation websites. By purchasing our own and other organic leads from three major lead platforms, we uncover deceptive brokerage practices, where consumer data is sold to unvetted buyers and often augmented or fabricated with attributes such as health status and weight. We received a total of over 8,000 telemarketing phone calls, 600 text messages, and 200 emails, where calls often began within seconds of form submission. Many campaigns relied on VoIP-based neighbor spoofing and high-frequency dialing, at times rendering phones unusable. Our experiments with phone and email opt-outs suggest phone-based opt-outs to help the most, although all were ineffective at completely stopping marketing communications. Analysis of 7,432 Better Business Bureau (BBB) complaints and reviews corroborates these findings from the consumer perspective. Overall, our results reveal a highly interconnected and non-compliant lead marketing ecosystem that aggressively monetizes sensitive consumer data. Yash Vekaria, Nurullah Demir, Konrad Kollnig, Zubair Shafiq |
SP | 3 |
| 2026 | Exercising the CCPA Opt-out Right on Android: Legally Mandated but Practically ChallengingabstractMany mobile apps' business model is based on sharing user data with ad networks to deliver personalized ads. The California Consumer Privacy Act (CCPA) gives California residents a right to opt out. In two experiments we evaluate to which extent popular Android apps enable California residents to exercise their right. In our first experiment—manually exercising the right via app-level UIs—we find that only 48 out of 100 apps implement a respective setting, which suggests that CCPA opt-out right compliance on the Android platform is generally low. In our second experiment—automatically exercising the opt-out right by sending Global Privacy Control (GPC) signals—we find for an app dataset of 1,811 apps that GPC is largely ineffective. While we estimate with 95% confidence that 62%-81% of apps in our app dataset must respect the CCPA opt-out right, many apps do not do so. Our evaluation of disabling apps' access to the AdID—which is technically not intended for exercising the CCPA opt-out right but could be practically effective—does not change our conclusion. For example, when sending GPC signals and disabling apps' access to the AdID, 338 apps still had the ccpa status of the ad network Vungle set to opted_in while only 26 had set it to opted_out. Overall, our results suggest a compliance gap as California residents have no effective way of exercising their CCPA opt-out right on the Android platform; neither at the app- nor at the platform-level. We think that re-purposing the Android AdID setting as an opt-out right setting with legal meaning under the CCPA and other laws could close this gap and improve users' privacy on the platform significantly. Sebastian Zimmeck, Nishant Aggarwal, Zachary Liu, Sage Altman, Konrad Kollnig |
Proc. Priv. Enhancing Technol. | 5 |
| 2025 | Can LLMs Create Legally Relevant Summaries and Analyses of Videos?abstractUnderstanding the legally relevant factual basis of an event and conveying it through text is a key skill of legal professionals. This skill is important for preparing forms (e.g., insurance claims) or other legal documents (e.g., court claims), but often presents a challenge for laypeople. Current AI approaches aim to bridge this gap, but mostly rely on the user to articulate what has happened in text, which may be challenging for many. Here, we investigate the capability of large language models (LLMs) to understand and summarize events occurring in videos. We ask an LLM to summarize and draft legal letters, based on 120 YouTube videos showing legal issues in various domains. Overall, 71.7% of the summaries were rated as of high or medium quality, which is a promising result, opening the door to a number of applications in e.g. access to justice. Lyra Hoeben-Kuil, Gijs van Dijck, Jaromír Savelka, Johanna Gunawan, Konrad Kollnig, Marta Kolacz, Mindy Duffourc, Shashank Chakravarthy, Hannes Westermann |
JURIX | 5 |
| 2024 | KOALA Hero Toolkit: A New Approach to Inform Families of Mobile Datafication RisksabstractChildren today are deeply immersed in the online world, where their activities are routinely tracked, analysed, and monetised. This exposes them to various datafication risks, including harmful profiling, micro-targeting and behavioural engineering. Most existing measures focus on immediate online threats, rather than informing children about these implicit risks. In this paper, we present The KOALA Hero Toolkit, a hybrid toolkit designed to help children and parents jointly understand the datafication risks posed by their mobile apps. Through user studies involving 17 families we evaluate how the toolkit influenced families’ thought processes, perceptions and decision-making regarding mobile datafication risks. Our findings show that KOALA Hero supports families’ critical thinking and promotes family engagement. We identify future design recommendations for family support, featuring ideas such as integrating triggering moments and bonding moments in toolkit designs. This work provides timely inputs on global efforts aimed at addressing datafication risks and underscores the importance of strengthening legislative and policy enforcement of ethical data governance. Ge Wang 0004, Jun Zhao 0003, Konrad Kollnig, Adrien Zier, Blanche Duron, Zhilin Zhang 0004, Max Van Kleek, Nigel Shadbolt |
CHI | 3 |
| 2024 | Privacy in Chinese iOS apps and impact of the personal information protection lawabstractPrivacy in apps is a topic of widespread interest because many apps collect and share large amounts of highly sensitive information. In response, the Chinese legislator introduced a range of new data protection laws over recent years, notably the Personal Information Protection Law (PIPL) in 2021. So far, there exists limited research on the impacts of these new laws on apps’ privacy practices. To address this gap, this paper analyses data collection in pairs of 634 Chinese iOS apps, one version from early 2020 and one from late 2021. Our work finds that many more apps now implement consent. Yet, those end-users that decline consent will often be forced to exit the app. Fewer apps now collect data without consent but many still integrate tracking libraries. Market concentration in app data collection has seen limited change. At the same time, there exists a larger number of influential and equal market participants than in the West. Among them, Apple was the only relevant foreign company. We see our findings characteristic of a first iteration at Chinese data regulation with room for improvement. With the help of enhanced technological capabilities, we expect increased enforcement of the new data rules. There is also room to refine the new laws and make them more targeted at mobile apps and the online sphere, particularly through clear and up-to-date technical specifications for software developers. As such, our findings could also be motivation for non-Chinese policy- and lawmakers to enhance their own data protection regimes. Konrad Kollnig, Lu Zhang 0073, Jun Zhao 0003, Nigel Shadbolt |
Comput. Law Secur. Rev. | 1 |
| 2022 | Mind-proofing Your Phone: Navigating the Digital Minefield with GreaseTerminatorabstractDigital harms are widespread in the mobile ecosystem. As these devices gain ever more prominence in our daily lives, so too increases the potential for malicious attacks against individuals. The last line of defense against a range of digital harms – including digital distraction, political polarisation through hate speech, and children being exposed to damaging material – is the user interface. This work introduces GreaseTerminator to enable researchers to develop, deploy, and test interventions against these harms with end-users. We demonstrate the ease of intervention development and deployment, as well as the broad range of harms potentially covered with GreaseTerminator in five in-depth case studies. Siddhartha Datta, Konrad Kollnig, Nigel Shadbolt |
IUI | 2 |
| 2022 | Are iPhones Really Better for Privacy? A Comparative Study of iOS and Android AppsabstractAbstract While many studies have looked at privacy properties of the Android and Google Play app ecosystem, comparatively much less is known about iOS and the Apple App Store, the most widely used ecosystem in the US. At the same time, there is increasing competition around privacy between these smartphone operating system providers. In this paper, we present a study of 24k Android and iOS apps from 2020 along several dimensions relating to user privacy. We find that third-party tracking and the sharing of unique user identifiers was widespread in apps from both ecosystems, even in apps aimed at children. In the children’s category, iOS apps tended to use fewer advertising-related tracking than their Android counterparts, but could more often access children’s location. Across all studied apps, our study highlights widespread potential violations of US, EU and UK privacy law, including 1) the use of third-party tracking without user consent, 2) the lack of parental consent before sharing personally identifiable information (PII) with third-parties in children’s apps, 3) the non-data-minimising configuration of tracking libraries, 4) the sending of personal data to countries without an adequate level of data protection, and 5) the continued absence of transparency around tracking, partly due to design decisions by Apple and Google. Overall, we find that neither platform is clearly better than the other for privacy across the dimensions we studied. Konrad Kollnig, Anastasia Shuba, Reuben Binns, Max Van Kleek, Nigel Shadbolt |
Proc. Priv. Enhancing Technol. | 1 |