Needle in the Haystack: Analyzing the Right of Access According to GDPR Article 15 Five Years after the Implementation

08/29/2023
by   Daniela Pöhn, et al.
0

The General Data Protection Regulation (GDPR) was implemented in 2018 to strengthen and harmonize the data protection of individuals within the European Union. One key aspect is Article 15, which gives individuals the right to access their personal data in an understandable format. Organizations offering services to Europeans had five years' time to optimize their processes and functions to comply with Article 15. This study aims to explore the process of submitting and receiving the responses of organizations to GDPR Article 15 requests. A quantitative analysis obtains data from various websites to understand the level of conformity, the data received, and the challenges faced by individuals who request their data. The study differentiates organizations operating worldwide and in Germany, browser website- and app-based usage, and different types of websites. Thereby, we conclude that some websites still compile the data manually, resulting in longer waiting times. A few exceptions did not respond with any data or deliver machine-readable data (GDRP Article 20). The findings of the study additionally reveal ten patterns individuals face when requesting and accessing their data.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
07/08/2023

Right to be Forgotten in the Era of Large Language Models: Implications, Challenges, and Solutions

The Right to be Forgotten (RTBF) was first established as the result of ...
research
04/19/2018

A spark is enough in a straw world: a study of websites password management in the wild

With the entry into force of the General Data Protection Regulation (GDP...
research
10/30/2019

Forgotten @ Scale: A Practical Solution for Implementing the Right To Be Forgotten in Large-Scale Systems

The European General Data Protection Regulation asserts data subjects' r...
research
07/06/2021

Sensemaking in Cybersecurity Incident Response: The Interplay of Organizations, Technology and Individuals

Sensemaking is a critical activity in organizations. It is a process thr...
research
12/02/2019

GDPArrrrr: Using Privacy Laws to Steal Identities

The General Data Protection Regulation (GDPR) has become a touchstone mo...
research
09/09/2021

Survey about cyberattack protection motivation in higher education: Academics at Slovenian universities, 2017

This paper reports on a study aiming to explore factors associated with ...
research
05/19/2022

An Empirical Evaluation of the Implementation of the California Consumer Privacy Act (CCPA)

On January 1, 2020, California passed the California Consumer Privacy Ac...

Please sign up or login with your details

Forgot password? Click here to reset