Cristiana Santos

ORCID: 0000-0003-0712-2038
Publications
Citations
Views
---
Saved
---
About
Contact & Profiles
Research Areas
  • Privacy, Security, and Data Protection
  • Privacy-Preserving Technologies in Data
  • Digitalization, Law, and Regulation
  • Dispute Resolution and Class Actions
  • Artificial Intelligence in Law
  • Semantic Web and Ontologies
  • Multi-Agent Systems and Negotiation
  • Sexuality, Behavior, and Technology
  • Internet Traffic Analysis and Secure E-voting
  • Cybercrime and Law Enforcement Studies
  • European Criminal Justice and Data Protection
  • Digital Rights Management and Security
  • Hate Speech and Cyberbullying Detection
  • Law, logistics, and international trade
  • Ethics and Social Impacts of AI
  • Digital and Cyber Forensics
  • Access Control and Trust
  • Library Science and Information Systems
  • User Authentication and Security Systems
  • Law, AI, and Intellectual Property
  • Blockchain Technology Applications and Security
  • Respiratory Support and Mechanisms
  • Digital Marketing and Social Media
  • Cryptography and Data Security
  • Chronic Obstructive Pulmonary Disease (COPD) Research

Utrecht University
2013-2025

Faculty (United Kingdom)
2022

University College London
2022

Aarhus University
2022

Vienna University of Economics and Business
2020

University of Minho
2018-2020

Institut national de recherche en informatique et en automatique
2014-2020

Observatoire de la Côte d’Azur
2014-2020

Université Côte d'Azur
2014-2020

Centre de Recherche en Informatique
2014-2019

As a result of the GDPR and ePrivacy Directive, European users encounter cookie banners on almost every website. Many such are implemented by Consent Management Providers (CMPs), who respect IAB Europe's Transparency Framework (TCF). Via banners, CMPs collect disseminate user consent to third parties. In this work, we systematically study TCF analyze stored behind interface banners. We Directive identify potential legal violations in implementations based storage detect suspected crawling 1...

10.1109/sp40000.2020.00076 article EN 2022 IEEE Symposium on Security and Privacy (SP) 2020-05-01

Deceptive and coercive design practices are increasingly used by companies to extract profit, harvest data, limit consumer choice. Dark patterns represent the most common contemporary amalgamation of these problematic practices, connecting designers, technologists, scholars, regulators, legal professionals in transdisciplinary dialogue. However, a lack universally accepted definitions across academic, legislative, practitioner, regulatory space has likely limited impact that scholarship on...

10.1145/3613904.3642436 article EN 2024-05-11

The concept of 'relevance' is crucial to legal information retrieval, but because its intuitive understanding it goes undefined too easily and unexplored often. We discuss a conceptual framework on relevance within based typology dimensions used general retrieval science, tailored the specific features information. This can be for development improvement systems.

10.1007/s10506-017-9195-8 article EN cc-by Artificial Intelligence and Law 2017-03-01

Deceptive design practices are increasingly used by companies to extract profit, harvest data, and limit consumer choice. Dark patterns represent the most common contemporary amalgamation of these problematic practices, connecting designers, technologists, scholars, regulators, legal professionals in transdisciplinary dialogue. However, a lack universally accepted definitions across academic, legislative regulatory space has likely limited impact that scholarship on dark might have...

10.1145/3544549.3585676 article EN 2023-04-19

Legitimate interest is one of the six grounds for processing data under European Union's General Data Protection Regulation (GDPR). The flexibility and ambiguity term "legitimate interests" can be problematic; coupled with lack enforcement from legal authorities different interpretations various protection authorities, legitimate interests taken advantage as a loophole to collect more user data.

10.1145/3544548.3580637 article EN cc-by 2023-04-19

Data collection purposes and their descriptions are presented on almost all privacy notices under the GDPR, yet there is a lack of research focusing how effective they at informing users about data practices. We fill this gap by investigating users' perceptions descriptions, crucial aspect informed consent. conducted 23 semi-structured interviews with European to investigate user six common (Strictly Necessary, Statistics Analytics, Performance Functionality, Marketing Advertising,...

10.1145/3613904.3642260 article EN cc-by 2024-05-11

Recent work in patients with acute respiratory failure (ARF) due to exacerbation of chronic airflow obstruction (CAO) suggests that application low degrees positive end-expiratory pressure (PEEP) can improve rather than impair mechanics, because PEEP replaces intrinsic (PEEPi). However, the impact on pulmonary gas exchange has not been fully investigated. We designed this study examine effects and those PEEPi ventilation/perfusion (VA/Q) mismatching mechanically ventilated CAO. Eight were...

10.1164/ajrccm.149.5.8173744 article EN American Journal of Respiratory and Critical Care Medicine 1994-05-01

A cookie banner pops up when a user visits website for the first time, requesting consent to use of cookies and other trackers variety purposes. Unlike prior work that has focused on evaluating interface (UI) design banners, this paper presents an in-depth analysis what banners say users get their consent. We took interdisciplinary approach determiningwhat should say. Following legal requirements ePrivacy Directive (ePD) General Data Protection Regulation (GDPR), we manually annotated around...

10.1145/3463676.3485611 preprint EN 2021-11-05

Internet users are constantly subjected to incessant demands for attention in a noisy digital world. Countless inputs compete the chance be clicked, seen, and interacted with, they can deploy tactics that take advantage of behavioral psychology 'nudge' into doing what want. Some nudges benign; others deceive, steer, or manipulate users, as U.S. FTC Commissioner says, "into behavior is profitable an online service, but often harmful [us] contrary [our] intent". These dark patterns, which...

10.1145/3511265.3550448 article EN 2022-11-01

10.1016/j.clsr.2025.106113 article EN cc-by Computer Law & Security Review 2025-02-28

Objetivo: Analisar a influência da nutrição materna durante gestação no desenvolvimento neurológico fetal, com ênfase impacto do consumo de alimentos ultraprocessados (AUPs) Revisão bibliográfica: A alimentação equilibrada, composta por macronutrientes e micronutrientes essenciais, é fundamental para formação sistema nervoso feto, provocando déficits cognitivos doenças metabólicas na vida adulta.gestantes dietas inadequadas, seja subnutrição ou excesso calorias, podem gerar consequências...

10.25248/reac.e20103.2025 article PT Revista Eletrônica Acervo Científico 2025-03-19

Growth hacking, particularly within the spectre of surveillance capitalism, has led to widespread use deceptive, manipulative, and coercive design techniques in last decade. These challenges exist at intersection many different technology professions that are rapidly evolving "shapeshifting" their practices confront emerging regulation. A wide range scholars have increasingly addressed these through label "dark patterns," describing content deceptive practices, ubiquity patterns contemporary...

10.1145/3544549.3583173 article EN 2023-04-19

Data Protection and Consenting Communication Mechanisms (DPCCMs) enable users to express their privacy decisions manage online consent. Thus, they can become a crucial means of protecting individuals' agency, thereby replacing the current problematic practices such as "consent dialogues". Based on an in-depth analysis different DPCCMs, we propose interdisciplinary set factors that be used for comparison mechanisms. Moreover, use results from qualitative expert study identify some main...

10.1109/eurospw55150.2022.00029 article EN 2022-06-01

The enforcement of the General Data Protection Regulation and ePrivacy Directive relies upon auditing legal compliance websites. controllers, as part their accountability transparency obligations, need to declare purposes cookies that they use in This leads relevant questions such as: How should be described according purpose specification principle? And how ensure a scalable auditing, enabled by automated means, for cookie purposes?In this paper, we investigate 20,218 third-party cookies....

10.1109/eurospw51379.2020.00051 preprint EN 2020-09-01

User engagement with data privacy and security through consent banners has become a ubiquitous part of interacting internet services. While previous work addressed from either interaction design, legal, ethics-focused perspectives, little research addresses the connections among multiple disciplinary approaches, including tensions opportunities that transcend boundaries. In this paper, we draw together perspectives commentary HCI, protection, legal communities, using language strategies...

10.1145/3411764.3445779 preprint EN 2021-05-06

In this work, we analyze the legal requirements on how cookie banners are supposed to be implemented fully compliant with e-Privacy Directive and General Data Protection Regulation. Our contribution resides in definition of seventeen operational fine-grained banner design that legally compliant, moreover, define whether when verification compliance each requirement is technically feasible. The emerges from a joint interdisciplinary analysis composed lawyers computer scientists domain web...

10.48550/arxiv.1912.07144 preprint EN cc-by-nc-sa arXiv (Cornell University) 2019-01-01

In this paper, we describe how cookie banners, as a consent mechanism in web applications, should be designed and implemented to compliant with the ePrivacy Directive GDPR, defining 22 legal requirements. While some are provided by sources, others result from domain expertise of computer scientists. We perform technical assessment whether (with science tools), manual human operator) or user studies verification is needed. show that it not possible assess compliance for majority requirements...

10.26116/techreg.2020.009 preprint EN other-oa HAL (Le Centre pour la Communication Scientifique Directe) 2020-12-01
Coming Soon ...