EDBT 2026 Demo / reviewers in the wild / expert
Cristiana Teixeira Santos
dblp:319/2886
· DBLP profile ↗
17ranked-venue papers
0as first author
10since 2021 · last 2026
0000-0003-0712-2038ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 5 since 2021Human-computer interaction and ubiquitous computing · 5 · 5 since 2021Applied, interdisciplinary, general and emerging computing · 4
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Dark Patterns and the EU Digital Services Act: Mapping Autonomy Violations and Design FactorsabstractDark patterns are design practices that undermine users' ability to make autonomous and informed choices in digital experiences. The EU Digital Services Act (DSA) seeks to protect users from such designs and their effects, with Article 25 prohibiting three autonomy violation types: deception, manipulation and distortion/impairment. Demonstrating such regulatory violations, however, requires design-oriented reasoning necessary to articulate why an observed design practice constitutes a specific autonomy violation type. This paper maps 59 known dark patterns onto the three autonomy violation types from the DSA and identifies eight new design factors which can help determine when a dark pattern violates autonomy. Our mapping of dark patterns to autonomy violations grounds ongoing regulatory debates in design while opening pathways for translational research that reimagines how HCI engages with the governance of design practices. Sanju Ahuja, Johanna Gunawan, Nataliia Bielova, Cristiana Teixeira Santos |
CHI | 4 |
| 2026 | The TCF doesn't really A(A)ID - Automatic Privacy Analysis and Legal Compliance of TCF-based Android ApplicationsabstractThe Transparency and Consent Framework (TCF), developed by the Interactive Advertising Bureau (IAB) Europe, provides a de facto standard for requesting, recording, and managing user consent from European end-users. Its goal is to help organizations comply with the General Data Protection Regulation (GDPR) and the ePrivacy Directive (ePD). This framework has previously been found to infringe European data protection law and has subsequently been regularly updated. Previous research on the TCF focused exclusively on web contexts, with no attention given to its implementation in mobile apps. No work has systematically studied the compliance implications of the TCF on Android apps. To address this gap, we investigate the prevalence of the TCF in popular Android apps from the Play Store, and assess whether these apps respect users’ consent banner choices. The TCF introduced minor changes in its new version (v.2.3) on March 1st, 2026, aimed at reducing ambiguity for vendors; these changes do not impact our results. We scraped and downloaded 4482 of the most popular Google Play Store apps on an emulated Android device. We automatically identified that 576 (12.85%) of the 4482 downloadable apps implemented the TCF, and we detected potential legal violations within this subset. By automatically interacting with consent banners, we observed that in 15 (2.6%) of these apps, users’ choices are stored only when consent is granted. Users who refuse consent are shown the consent banner again each time they launch the app. We analyzed the apps’ traffic in two different stages, passive (post interaction with the banner) and active (during banner interaction and post user choices). Network analysis conducted during the passive stage reveals that 66.2% of the analyzed TCF-based apps share personal data through the Google Advertising ID (AAID) without consent – the lawful basis for such processing. Furthermore, 55.3% of apps analyzed during the active stage share AAID before users interact with the apps’ consent banners, violating the prior consent requirement. We further expose concerns regarding Google as the dominant Consent Management Provider (CMP) in our dataset (89.76%), structurally accommodating potential legal violations. Our results suggest that mobile implementations of the TCF are prone to significant non-compliance practices, raising concerns about its effectiveness in helping organizations adhere to legal requirements. Victor Morel, Cristiana Teixeira Santos, Pontus Carlsson, Joel Ahlinder, Romaric Duvignau |
Proc. Priv. Enhancing Technol. | 2 |
| 2025 | You Can't Trust Your Tag Neither: Privacy Leaks and Potential Legal Violations within the Google Tag ManagerabstractTag Management Systems (TMS) were developed in order to support website Publishers in installing multiple third-party JavaScript scripts (Tags) on their websites. Google has proposed its own TMS called "Google Tag Manager" (GTM) that is currently present on 52% of the top 1 million most popular websites. However, GTM has not yet been thoroughly evaluated by the academic research community. In this work, we study, for the first time, the Tags provided within the GTM system. Our methodology consists in installing Tags in isolation to analyze the types of data that Tags collect and contrast them to the legal and technical documentation, in collaboration with a legal expert. Across three studies - in-depth analysis of 6 Tags, automated analysis of 718 Tags, and analysis of Google "Consent Mode" - we discover multiple hidden data leaks, incomplete and diverging declarations, undisclosed third- parties and cookies, personal data sharing without consent and we further identify potential legal violations within EU Data Protection law. Gilles Mertens, Nataliia Bielova, Vincent Roca, Cristiana Teixeira Santos |
EuroS&P | 4 |
| 2025 | Johnny Can't Revoke Consent Either: Measuring Compliance of Consent Revocation on the WebabstractThe EU General Data Protection Regulation (GDPR) requires websites to facilitate the right to revoke consent from Web users. Prior works have examined consent management by auditing that user choices are correctly stored, and comparing cookies set upon acceptance versus rejection to assess compliance. While these studies measured compliance of consent with respect to the various consent requirements, no prior work has studied consent revocation on the Web. Therefore, it is unclear how difficult it is to revoke consent on the websites’ interfaces, and whether the revoked consent is properly stored and communicated behind the user interface. Our work aims to fill this gap by measuring compliance of consent revocation on the Web on Tranco’s top-200 websites. We found that 19.87% of websites make it difficult for users to revoke consent throughout different interfaces, 20.5% of websites require more effort than acceptance, and 2.48% do not provide consent revocation at all, thus violating EU legal requirements for valid consent. 57.5% websites do not delete the cookies after consent revocation enabling continuous illegal processing of users’ data. Further, we analyzed 281 websites implementing the IAB Europe Transparency & Consent Framework, and found 22 websites that store a positive consent despite user’s revocation. Surprisingly, we found that on 101 websites, third parties that have received consent upon user’s acceptance, are not informed of revocation, leading to the illegal processing of users’ data by such third parties according to EU laws. Our findings emphasize the need for improved legal compliance of consent revocation, and proper, consistent, and uniform implementation of revocation communication to third-parties. Gayatri Priyadarsini Kancherla, Nataliia Bielova, Cristiana Teixeira Santos, Abhishek Bichhawat |
Proc. Priv. Enhancing Technol. | 3 |
| 2024 | An Ontology of Dark Patterns Knowledge: Foundations, Definitions, and a Pathway for Shared Knowledge-BuildingabstractDeceptive and coercive design practices are increasingly used by companies to extract profit, harvest data, and limit consumer choice. Dark patterns represent the most common contemporary amalgamation of these problematic practices, connecting designers, technologists, scholars, regulators, and legal professionals in transdisciplinary dialogue. However, a lack of universally accepted definitions across the academic, legislative, practitioner, and regulatory space has likely limited the impact that scholarship on dark patterns might have in supporting sanctions and evolved design practices. In this paper, we seek to support the development of a shared language of dark patterns, harmonizing ten existing regulatory and academic taxonomies of dark patterns and proposing a three-level ontology with standardized definitions for 64 synthesized dark pattern types across low-, meso-, and high-level patterns. We illustrate how this ontology can support translational research and regulatory action, including transdisciplinary pathways to extend our initial types through new empirical work across application and technology domains. Colin M. Gray, Cristiana Teixeira Santos, Nataliia Bielova, Thomas Eßmeyer |
CHI | 2 |
| 2024 | "It doesn't tell me anything about how my data is used": User Perceptions of Data Collection PurposesabstractData collection purposes and their descriptions are presented on almost all privacy notices under the GDPR, yet there is a lack of research focusing on how effective they are at informing users about data practices. We fill this gap by investigating users’ perceptions of data collection purposes and their descriptions, a crucial aspect of informed consent. We conducted 23 semi-structured interviews with European users to investigate user perceptions of six common purposes (Strictly Necessary, Statistics and Analytics, Performance and Functionality, Marketing and Advertising, Personalized Advertising, and Personalized Content) and identified elements of an effective purpose name and description. Lin Kyi, Abraham H. Mhaidli, Cristiana Teixeira Santos, Franziska Roesner, Asia J. Biega |
CHI | 3 |
| 2024 | The Devil is in the Details: Detection, Measurement and Lawfulness of Server-Side Tracking on the WebabstractAs online privacy is cementing itself as one of the core pillars of the Internet, major changes are happening across many industries. On the technological side, users are pushing for more privacy-preserving technologies and rely on browsers and extensions that limit online tracking as much as possible. On the legal front, regulations like GDPR and the ePrivacy Directive in Europe have forced companies to change their practices and be more transparent about how they handle user data. For the ad industry, the end of third-party cookies planned for 2025 is having severe ramifications as the main source of data on which this industry is built on will be gone. In this tumultuous context, companies have come up with innovative ways to overcome current and future restrictions. A novel technique which has not received much attention called Server-side tracking (SST) moves its tracking logic away from the user's device onto an external server. In this work, our aim is to detect SST on the web and understand its lawfulness with respect to current legislation. We developed a methodology that relies on crawls spaced 2 years apart performed before and after the introduction of SST to identify trackers that moved behind SST domains and that are now hidden from view. Our results show that 389, out of 7,367 visited websites, track users behind a cloaked domain and that 28 websites perform Server-side tracking in a first-party capacity. We demonstrate that such a tracking technique can overcome the Same-Origin Policy and introduce security vulnerabilities. Together with a legal scholar, we also show that SST entails non-compliant practices and infringes the GDPR and the ePrivacy Directive. Imane Fouad, Cristiana Teixeira Santos, Pierre Laperdrix |
Proc. Priv. Enhancing Technol. | 2 |
| 2023 | Investigating Deceptive Design in GDPR's Legitimate InterestabstractLegitimate interest is one of the six grounds for processing data under the European Union’s General Data Protection Regulation (GDPR). The flexibility and ambiguity of the term "legitimate interests" can be problematic; coupled with the lack of enforcement from legal authorities and different interpretations from the various data protection authorities, legitimate interests can be taken advantage of as a loophole to collect more user data. Lin Kyi, Sushil Ammanaghatta Shivakumar, Cristiana Teixeira Santos, Franziska Roesner, Frederike Zufall, Asia J. Biega |
CHI | 3 |
| 2022 | My Cookie is a phoenix: detection, measurement, and lawfulness of cookie respawning with browser fingerprintingabstractStateful and stateless web tracking gathered much attention in the last decade, however they were always measured separately. To the best of our knowledge, our study is the first to detect and measure cookie respawning with browser and machine fingerprinting. We develop a detection methodology that allows us to detect cookies dependency on browser and machine features. Our results show that 1, 150 out of the top 30, 000 Alexa websites deploy this tracking mechanism. We find out that this technique can be used to track users across websites even when third-party cookies are deprecated. Together with a legal scholar, we conclude that cookie respawning with browser fingerprinting lacks legal interpretation under the GDPR and the ePrivacy directive, but its use in practice may breach them, thus subjecting it to fines up to 20 million e. Imane Fouad, Cristiana Teixeira Santos, Arnaud Legout, Nataliia Bielova |
Proc. Priv. Enhancing Technol. | 2 |
| 2021 | Dark Patterns and the Legal Requirements of Consent Banners: An Interaction Criticism PerspectiveabstractUser engagement with data privacy and security through consent banners has become a ubiquitous part of interacting with internet services. While previous work has addressed consent banners from either interaction design, legal, and ethics-focused perspectives, little research addresses the connections among multiple disciplinary approaches, including tensions and opportunities that transcend disciplinary boundaries. In this paper, we draw together perspectives and commentary from HCI, design, privacy and data protection, and legal research communities, using the language and strategies of “dark patterns” to perform an interaction criticism reading of three different types of consent banners. Our analysis builds upon designer, interface, user, and social context lenses to raise tensions and synergies that arise together in complex, contingent, and conflicting ways in the act of designing consent banners. We conclude with opportunities for transdisciplinary dialogue across legal, ethical, computer science, and interactive systems scholarship to translate matters of ethical concern into public policy. Colin M. Gray, Cristiana Teixeira Santos, Nataliia Bielova, Michael Toth, Damian Clifford |
CHI | 2 |
| 2020 | Events Matter: Extraction of Events from Court DecisionsabstractThe analysis of court decisions and associated events is part of the daily life of many legal practitioners. Unfortunately, since court decision texts can often be long and complex, bringing all events relating to a case in order, to understand their connections and durations is a time-consuming task. Automated court decision timeline generation could provide a visual overview of what happened throughout a case by representing the main legal events, together with relevant temporal information. Tools and technologies to extract events from court decisions however are still underdeveloped. To this end, in the current paper we compare the effectiveness of three different extraction mechanisms, namely deep learning, conditional random fields, and rule-based method, to facilitate automated extraction of events and their components (i.e., the event type, who was involved, and when it happened). In addition, we provide a corpus of manually annotated decisions of the European Court of Human Rights, which shall serve as a gold standard not only for our own evaluation, but also for the research community for comparison and further experiments. Erwin Filtz, María Navas-Loro, Cristiana Teixeira Santos, Axel Polleres, Sabrina Kirrane |
JURIX | 3 |
| 2020 | Do Cookie Banners Respect my Choice? : Measuring Legal Compliance of Banners from IAB Europe's Transparency and Consent FrameworkabstractAs a result of the GDPR and the ePrivacy Directive, European users encounter cookie banners on almost every website. Many of such banners are implemented by Consent Management Providers (CMPs), who respect IAB Europe's Transparency and Consent Framework (TCF). Via cookie banners, CMPs collect and disseminate user consent to third parties. In this work, we systematically study IAB Europe's TCF and analyze consent stored behind the user interface of TCF cookie banners. We analyze the GDPR and the ePrivacy Directive to identify potential legal violations in implementations of cookie banners based on the storage of consent and detect such suspected violations by crawling 1 426 websites that contains TCF banners, found among 28 257 crawled European websites. With two automatic and semi-automatic crawl campaigns, we detect suspected violations, and we find that: 141 websites register positive consent even if the user has not made their choice; 236 websites nudge the users towards accepting consent by pre-selecting options; and 27 websites store a positive consent even if the user has explicitly opted out. Performing extensive tests on 560 websites, we find at least one suspected violation in 54% of them. Finally, we provide a browser extension to facilitate manual detection of suspected violations for regular users and Data Protection Authorities. Célestin Matte, Nataliia Bielova, Cristiana Teixeira Santos |
SP | 3 |
| 2018 | Property and the cloud
Cesare Bartolini, Cristiana Teixeira Santos, Carsten Ullrich |
Comput. Law Secur. Rev. | 2 |
| 2016 | Legal aspects of linked data - The European framework
Víctor Rodríguez-Doncel, Cristiana Teixeira Santos, Pompeu Casanovas, Asunción Gómez-Pérez |
Comput. Law Secur. Rev. | 2 |
| 2015 | Mapping Recitals to Normative Provisions in EU Legislation to Assist Legal InterpretationabstractThis paper looks at the use of recitals in the interpretation of EU legislation, and mechanisms for connecting them to normative provisions. The purposive approach to the interpretation of EU legislation taken by the European Court of Justice makes frequent references to recitals as helping to establish the purpose of normative provisions. Our research uses a cosine similarity based approach to link articles with relevant provisions to help legal professionals and lay end-users interpret the law. Such support can be used in legal knowledge-based systems. Llio Humphreys, Cristiana Teixeira Santos, Luigi Di Caro, Guido Boella, Leon van der Torre, Livio Robaldo |
JURIX | 2 |
| 2015 | A Linked Term Bank of Copyright-Related TermsabstractA multi-lingual term bank of copyright-related terms has been published connecting WIPO definitions, IATE terms and definitions from Creative Commons licenses. These terms have been hierarchically arranged, spanning multiple languages and targeting different jurisdictions. The term bank has been published as a TBX dump file and is publicly accessible as linked data. Models for the RDF data structure are based on Lemon and W3C Recommendations. The term bank has been used to annotate common licenses in the RDFLicense dataset. Víctor Rodríguez-Doncel, Cristiana Teixeira Santos, Pompeu Casanovas, Asunción Gómez-Pérez |
JURIX | 2 |
| 2014 | A model of Air Transport Passenger Incidents and RightsabstractThis paper describes a representation of the legal framework in the air transport passenger's rights domain and the foremost incidents that trigger the top of consumer complaints ranking in the EU. It comprises the development of a small network of three ontologies, formalisation of scenarios, specification of properties and identification of relations. The approach is illustrated by means of a case study based in the context of a real life cancelled flight incident. This is part of an intended support-system that aims to provide both consumers and companies with relevant legal information to enhance the decision-making process. Víctor Rodríguez-Doncel, Cristiana Teixeira Santos, Pompeu Casanovas |
JURIX | 2 |