CHI Conference on Human Factors in Computing Systems 2022
DOI: 10.1145/3491102.3501947
|View full text |Cite
|
Sign up to set email alerts
|

Human-GDPR Interaction: Practical Experiences of Accessing Personal Data

Abstract: In our data-centric world, most services rely on collecting and using personal data. The EU's General Data Protection Regulation (GDPR) aims to enhance individuals' control over their data, but its practical impact is not well understood. We present a 10-participant study, where each participant filed 4-5 data access requests. Through interviews accompanying these requests and discussions scrutinising returned data, it appears that GDPR falls short of its goals due to non-compliance and low-quality responses. … Show more

Help me understand this report
View preprint versions

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
4
0

Year Published

2023
2023
2024
2024

Publication Types

Select...
4
2
2

Relationship

1
7

Authors

Journals

citations
Cited by 27 publications
(9 citation statements)
references
References 42 publications
0
4
0
Order By: Relevance
“…Researchers also studied the usability of subject access request and deletion mechanisms from a number of different angles, including the ease of initiating the requests as well as the extent to which the content of the responses can be understood by average users [8,24,60,64,66]. After investigating users' awareness of their rights under the GDPR in [36], researchers found that users do not have sufficient understanding of their "right to data portability."…”
Section: Efficacy Of Subject Access Requestsmentioning
confidence: 99%
See 1 more Smart Citation
“…Researchers also studied the usability of subject access request and deletion mechanisms from a number of different angles, including the ease of initiating the requests as well as the extent to which the content of the responses can be understood by average users [8,24,60,64,66]. After investigating users' awareness of their rights under the GDPR in [36], researchers found that users do not have sufficient understanding of their "right to data portability."…”
Section: Efficacy Of Subject Access Requestsmentioning
confidence: 99%
“…By the same token, users do not gain much by being informed about the collection of these categories. We also identified the categories of personal information that the developers disclosed or sold, 8 as well as the categories of recipients of users' personal information. Although the CCPA requires companies to enumerate the recipients for each category of personal information, in practice we found that only a small number of policies did so.…”
Section: Privacy Policiesmentioning
confidence: 99%
“…Can we rely on alternative ways to access behavioral data (e.g., crowdsourcing [17], data donation [8])? How do these approaches ft and challenge existing data protection regulations and privacy considerations (e.g., the European General Data Protection Regulation [5])? To what extent do these approaches reinforce or mitigate existing inequalities [7]?…”
Section: Sig Goalmentioning
confidence: 99%
“…For example, looking at her activity tracker, the same participant could say "my daily steps were below my goal for two days when I was sick". In this context, design and HCI researchers support people's engagement with their behavioral data; helping them (1) navigate existing data protection regulations [5,8], (2) categorize and visualize the data and, in doing so, understand it and its implications [13,17], and (3) interpret and situate the data [8,13,18,19].…”
Section: Introductionmentioning
confidence: 99%
“…We should learn from these experiences to improve procedures and instructions for users. Furthermore, the format and data quality of takeouts is often far from ideal, lacking crucial data sources or variables of interest (Bowyer et al, 2022). The research community must push for higher standards and the monitoring of the completeness of data take-outs, not only for its sake by also for the sake of users executing their rights to data access (Ausloos & Veale, 2020).…”
Section: Methodological Implications and Challengesmentioning
confidence: 99%