Human-GDPR Interaction: Practical Experiences of Accessing Personal Data
Alex Bowyer, Jack Holt, Josephine Go Jefferies, Rob Wilson, David S. Kirk, Jan David Smeddinck
Abstract
In our data-centric world, most services rely on collecting and using personal data. The EU's General Data Protection Regulation (GDPR) aims to enhance individuals’ control over their data, but its practical impact is not well understood. We present a 10-participant study, where each participant filed 4-5 data access requests. Through interviews accompanying these requests and discussions scrutinising returned data, it appears that GDPR falls short of its goals due to non-compliance and low-quality responses. Participants found their hopes to understand providers’ data practices or harness their own data unmet. This causes increased distrust without any subjective improvement in power, although more transparent providers do earn greater trust. We propose designing more effective, data-inclusive and open policies and data access systems to improve both customer relations and individual agency, and also that wider public use of GDPR rights could help with delivering accountability and motivating providers to improve data practices.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 33aaae4c-4f85-49d1-a631-3966b0d006f6Cited by top-tier papers7
- What is Sensitive About (Sensitive) Data? Characterizing Sensitivity and Intimacy with Google Assistant UsersAlejandra Gómez Ortega, Jacky Bourgeois, Gerd KortuemCHI 2023 · 33 citations
- Regulating Responsibility: Environmental Sustainability, Law, and the Platformisation of Waste ManagementRob Comber, Chiara RossittoCHI 2023 · 24 citations
- SoK: Technical Implementation and Human Impact of Internet Privacy RegulationsEleanor Birrell, Jay Rodolitz, Angel Ding, Jenna Lee et al.S&P 2024 · 11 citations
- Surrendering to Powerlesness: Governing Personal Data Flows in Generative AIAlejandra Gómez Ortega, Hosana Morales Ornelas, Ugur GençCHI 2025 · 9 citations
- Understanding Chinese Internet Users' Perceptions of, and Online Platforms' Compliance with, the Personal Information Protection Law (PIPL)Morgana Mo Zhou, Zhiyan Qu, Jinhan Wan, Bo Wen et al.CSCW 2024 · 9 citations
Related papers
- Generating Practices: Investigations into the Double Embedding of GDPR and Data Access PoliciesJustin Petelka, Elisa Oreglia, Megan Finn, Janaki SrinivasanCSCW 2022 · 10 citations
- Setting the Course, but Forgetting to Steer: Analyzing Compliance with GDPR's Right of Access to Data by Instagram, TikTok, and YoutubeSai Keerthana Karnam, Abhisek Dash, Antariksh Das, Sepehr Mousavi et al.S&P 2026 · 3 citations
- "It doesn't tell me anything about how my data is used": User Perceptions of Data Collection PurposesLin Kyi, Abraham Mhaidli, Cristiana Teixeira Santos, Franziska Roesner et al.CHI 2024 · 22 citations
- 'Transparency is Meant for Control' and Vice Versa: Learning from Co-designing and Evaluating Algorithmic News RecommendersElias Storms, Oscar Alvarado, Luciana Monteiro KrebsCSCW 2022 · 29 citations
- Out of Sight, Out of Mind? Exploring Data Protection Practices for Personal Data in Usable Security & Privacy StudiesFlorin Martius, Luisa Jansen, Lukas Struck, Arthi Arumugam et al.CHI 2025 · 7 citations
