Data Subjects' Reactions to Exercising Their Right of Access
Arthur Borem, Elleen Pan, Olufunmilola Obielodan, Aurelie Roubinowitz, Luca Dovichi, Michelle L. Mazurek, Blase Ur
摘要
Recent privacy laws have strengthened data subjects' right to access personal data collected by companies. Prior work has found that data exports companies provide consumers in response to Data Subject Access Requests (DSARs) can be overwhelming and hard to understand. To identify directions for improving the user experience of data exports, we conducted an online study in which 33 participants explored their own data from Amazon, Facebook, Google, Spotify, or Uber. Participants articulated questions they hoped to answer using the exports. They also annotated parts of the data they found confusing, creepy, interesting, or surprising. While participants hoped to learn either about their own usage of the platform or how the company collects and uses their personal data, these questions were often left unanswered. Participants' annotations documented their excitement at finding data records that triggered nostalgia, but also shock about the privacy implications of other data they saw. Having examined their data, many participants hoped to request the company erase some, but not all, of the data. We discuss opportunities for future transparency-enhancing tools and enhanced laws.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- An Experimental Study Of Netflix Use and the Effects of Autoplay on Watching BehaviorsBrennan Schaffner, Yaretzi Ulloa, Riya Sahni, Jiatong Li 等CSCW 2025 · 被引用 13 次
- Consumer Beware! Exploring Data Brokers' CCPA ComplianceElina van Kempen, Isita Bagayatkar, Pavel Frolikov, Chloe Georgiou 等S&P 2026 · 被引用 6 次
- The Nuances of Creepiness: A Systematic Literature Review of Creepy TechnologyTora Jarsve, Barbara Sienkiewicz, Meagan B. Loerakker, Pawel W. Wozniak 等CHI 2026 · 被引用 4 次
- Setting the Course, but Forgetting to Steer: Analyzing Compliance with GDPR's Right of Access to Data by Instagram, TikTok, and YoutubeSai Keerthana Karnam, Abhisek Dash, Antariksh Das, Sepehr Mousavi 等S&P 2026 · 被引用 3 次
- Addressing the Address Books' (Interdependent) Privacy IssuesKavous Salehzadeh Niksirat, Lev Velykoivanenko, Samuel Mätzler, Stephan Mulders 等USENIX Security 2025
它引用的顶会 Paper10
- Understanding and Benchmarking the Impact of GDPR on Database SystemsSupreeth Shastri, Vinay Banakar, Melissa Wasserman, Arun Kumar 等VLDB 2020 · 被引用 82 次
- Share First, Ask Later (or Never?) Studying Violations of GDPR's Explicit Consent in Android AppsTrung Tin Nguyen, Michael Backes, Ninja Marnau, Ben StockUSENIX Security 2021 · 被引用 70 次
- Are Privacy Dashboards Good for End Users? Evaluating User Perceptions and Reactions to Google's My ActivityFlorian M. Farke, David G. Balash, Maximilian Golla, Markus Dürmuth 等USENIX Security 2021 · 被引用 48 次
- Five Years of the Right to be ForgottenTheo Bertram, Elie Bursztein, Stephanie Caro, Hubert Chao 等CCS 2019 · 被引用 41 次
- Investigating Deceptive Design in GDPR's Legitimate InterestLin Kyi, Sushil Ammanaghatta Shivakumar, Cristiana Teixeira Santos, Franziska Roesner 等CHI 2023 · 被引用 32 次
相关 Paper
- Generating Practices: Investigations into the Double Embedding of GDPR and Data Access PoliciesJustin Petelka, Elisa Oreglia, Megan Finn, Janaki SrinivasanCSCW 2022 · 被引用 10 次
- "It's a scavenger hunt": Usability of Websites' Opt-Out and Data Deletion ChoicesHana Habib, Sarah Pearman, Jiamin Wang, Yixin Zou 等CHI 2020 · 被引用 113 次
- A Visualization Interface to Improve the Transparency of Collected Personal Data on the InternetMarija Schufrin, Steven Lamarr Reynolds, Arjan Kuijper, Jörn KohlhammerIEEE VIS 2020 · 被引用 26 次
- Understanding Account Deletion and Relevant Dark Patterns on Social MediaBrennan Schaffner, Neha A. Lingareddy, Marshini ChettyCSCW 2022 · 被引用 66 次
- Human-GDPR Interaction: Practical Experiences of Accessing Personal DataAlex Bowyer, Jack Holt, Josephine Go Jefferies, Rob Wilson 等CHI 2022 · 被引用 51 次
