Submitted:
12 September 2026
Posted:
14 September 2026
You are already at the latest version
Abstract
Web tracking and browser fingerprinting are typically invisible to users and are difficult to characterize reliably from a single website observation. This study evaluates privacy- and security-relevant indicators across a curated frame of 947 Ecuador-associated domains and introduces a completion-aware automation and data-engineering pipeline that uses Blacklight as an external measurement instrument. The developed application normalizes and deduplicates domains, controls a headless Chromium browser through Playwright, initiates scans through the Blacklight web interface, waits until the platform signals scan completion or a maximum timeout is reached, and, only after completion, captures and preserves the original JSON download. For each artifact, the application records acquisition metadata and errors, computes a SHA-256 integrity hash, extracts instrument-reported variables, validates summary-versus-detail consistency, and joins a manually established sector/subsector taxonomy while preserving raw, derived, and classification layers separately. Three measurements were conducted on 25 June 2026, 25 July 2026, and 25 August 2026. Successful JSON export rates were 58.0%, 55.8%, and 59.0%; the strict quality-controlled longitudinal panel contained 381 domains across 19 sectors. Within that panel, tracker prevalence was 15.0%-15.5%, fingerprinting 37.5%-38.1%, cookies 34.1%-34.4%, third-party domains 74.3%-74.8%, Content Security Policy (CSP) presence 22.3%-22.6%, and instrument-defined critical-category fingerprinting 7.3%-8.1%. None of the six binary conditions changed significantly after Holm correction (all adjusted p >= 0.812), with three-round exact agreement of 96.6%-99.5% and Fleiss’ kappa of 0.927-0.986. Count reliability was also high (ICC(A,1) = 0.897-0.993). Persistent domain-item pairs accounted for 89.2% of tracker-domain, 89.1% of tracker-company, 91.3% of fingerprinting-technique, and 95.5% of third-party-domain detections. Under Ecuador’s Organic Law on Personal Data Protection (LOPDP), these results are interpreted as persistent compliance-verification signals rather than proof of unlawful processing. The combined framework strengthens reproducibility, audit prioritization, and evidentiary traceability while preserving the distinction between technical detection and legal conclusion.
Keywords:
web privacy
; web tracking
; browser fingerprinting
; Blacklight
; Playwright
; repeated measurement
; third-party tracking
; Ecuador
; LOPDP
; privacy engineering
; cybersecurity
Copyright: This open access article is published under a Creative Commons CC BY 4.0 license, which permit the free download, distribution, and reuse, provided that the author and preprint are cited in any reuse.