VICEROY: GDPR-/CCPA-compliant Enforcement of Verifiable Accountless Consumer Requests
Scott Jordan, Yoshimichi Nakatsuka, Ercan Ozturk, Andrew Paverd, Gene Tsudik
Abstract
Recent data protection regulations (such as GDPR and CCPA) grant consumers various rights, including the right to access, modify or delete any personal information collected about them (and retained) by a service provider. To exercise these rights, one must submit a verifiable consumer request proving that the collected data indeed pertains to them. This action is straightforward for consumers with active accounts with a service provider at the time of data collection, since they can use standard (e.g., password-based) means of authentication to validate their requests. However, a major conundrum arises from the need to support consumers without accounts to exercise their rights. To this end, some service providers began requiring such accountless consumers to reveal and prove their identities (e.g., using government-issued documents, utility bills, or credit card numbers) as part of issuing a verifiable consumer request. While understandable as a short-term cure, this approach is cumbersome and expensive for service providers as well as privacy-invasive for consumers. Consequently, there is a strong need to provide better means of authenticating requests from accountless consumers. To achieve this, we propose VICEROY, a privacy-preserving and scalable framework for producing proofs of data ownership, which form a basis for verifiable consumer requests. Building upon existing web techniques and features, VICEROY allows accountless consumers to interact with service providers, and later prove that they are the same person in a privacy-preserving manner, while requiring minimal changes for both parties. We design and implement VICEROY with emphasis on security/privacy, deployability and usability. We also thoroughly assess its practicality via extensive experiments.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext dff8399e-5064-4d10-b778-0d2539032ac5Cited by top-tier papers1
Ask how each one uses itBuilds on3
- Measuring HTTPS Adoption on the WebAdrienne Porter Felt, Richard Barnes, April King, Chris Palmer et al.USENIX Security 2017 · 177 citations
- Presence Attestation: The Missing Link in Dynamic Trust BootstrappingZhangkai Zhang, Xuhua Ding, Gene Tsudik, Jinhua Cui et al.CCS 2017 · 16 citations
- CACTI: Captcha Avoidance via Client-side TEE IntegrationYoshimichi Nakatsuka, Ercan Ozturk, Andrew Paverd, Gene TsudikUSENIX Security 2021 · 11 citations
Related papers
- Consumer Beware! Exploring Data Brokers' CCPA ComplianceElina van Kempen, Isita Bagayatkar, Pavel Frolikov, Chloe Georgiou et al.S&P 2026 · 6 citations
- DECO: Liberating Web Data Using Decentralized Oracles for TLSFan Zhang, Deepak Maram, Harjasleen Malvai, Steven Goldfeder et al.CCS 2020 · 110 citations
- SSI, from Specifications to Protocol? Formally Verify Security!Christoph H.-J. Braun, Ross Horne, Tobias Käfer, Sjouke MauwWWW 2024 · 4 citations
- Fast IDentity Online with Anonymous Credentials (FIDO-AC)Wei-Zhu Yeoh, Michal Kepkowski, Gunnar Heide, Dali Kaafar et al.USENIX Security 2023
- Anchors of Trust: A Usability Study on User Awareness, Consent, and Control in Cross-Device AuthenticationXin Zhang, Xiaohan Zhang, Huijun Zhou, Bo ZhaoNDSS 2026
