This paper examines how governmental decision-making was undertaken in the aftermath of four key cybersecurity crises affecting Estonian e-governance, with the objective of bolstering future cybersecurity.

‘Cookie-less’ identification for/against privacy?

Ido Sivan-Sevilla, University of Maryland
Patrick Parham, University of Maryland
Lee McGuigan, University of North Carolina at Chapel Hill
PUBLISHED ON: 6 Aug 2025 DOI: 10.14763/2025.3.2025

The online advertising industry is shifting content monetisation mechanisms to rely on first-party user identification architectures. The paper evaluates these architectures based on a novel typology to assess their privacy implications.

The impact of zero-knowledge proofs on data minimisation compliance of digital identity wallets

Emanuela Podda, Università degli Studi di Milano
Pol Hölzmer, University of Luxembourg
Alexandre Amard, University of Luxembourg
Johannes Sedlmeir, University of Münster
Gilbert Fridgen, University of Luxembourg
PUBLISHED ON: 30 Jul 2025 DOI: 10.14763/2025.3.2019

Zero-knowledge proofs allow the implementation of the data minimisation principle imposed by the GDPR in digital identity wallets and the related personal data transactions, therefore representing a reasonable option to be enforced by lawmakers.

“You and TikTok are, and will remain at all times, independent contractors”

Taylor Annabell, Utrecht University
Sophie Bishop, University of Leeds
Catalina Goanta, Utrecht University
PUBLISHED ON: 23 Jul 2025 DOI: 10.14763/2025.3.2014

This article explores TikTok's platform governance of monetisation by systematically examining the classification of influencers and monetisation practices in TikTok’s platform documentation.

Transparency and content moderation are becoming increasingly interconnected within legislation. It is time for tech companies to recognise this in the context of borderline terrorist and violent extremist content moderation.

Regulating pressing systemic risks – but not too soon?

Defne Halil, Maastricht University
Konrad Kollnig, Maastricht University
Aurelia Tamò-Larrieux, University of Lausanne
PUBLISHED ON: 25 Jun 2025 DOI: 10.14763/2025.2.2010

The EU’s 2022 Digital Services Act mandates data access for researchers to study platform risks, but delays and diverging opinions of authorities hold back the DSA’s practical implementation.

Infrastructural power: State strategies for internet control

Juan Ortiz Freuler, University of Southern California
PUBLISHED ON: 20 May 2025 DOI: 10.14763/2025.2.2009

This article explores how governments, shifting from an anti-interventionist stance and views of regulatory impossibility, are embracing an infrastructural turn through strategies that include hijacking, and localising the "points of control" of the internet.

From threat to opportunity: Gaming the algorithmic system as a service

Marijn Sax, University of Amsterdam
Hao Wang, Wageningen University & Research
PUBLISHED ON: 6 May 2025 DOI: 10.14763/2025.2.2007

Gaming the system is often portrayed as a threat to platforms and services, but this alleged threat can also be turned into a commercial service which raises ethical questions on exploitative digital environments, equality, and the erosion of democratic values.