Human-GDPR Interaction: Practical Experiences of Accessing Personal Data
Alex Bowyer, Jack Holt, Josephine Go Jefferies, Rob Wilson, David S. Kirk, Jan David Smeddinck
摘要
In our data-centric world, most services rely on collecting and using personal data. The EU's General Data Protection Regulation (GDPR) aims to enhance individuals’ control over their data, but its practical impact is not well understood. We present a 10-participant study, where each participant filed 4-5 data access requests. Through interviews accompanying these requests and discussions scrutinising returned data, it appears that GDPR falls short of its goals due to non-compliance and low-quality responses. Participants found their hopes to understand providers’ data practices or harness their own data unmet. This causes increased distrust without any subjective improvement in power, although more transparent providers do earn greater trust. We propose designing more effective, data-inclusive and open policies and data access systems to improve both customer relations and individual agency, and also that wider public use of GDPR rights could help with delivering accountability and motivating providers to improve data practices.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- What is Sensitive About (Sensitive) Data? Characterizing Sensitivity and Intimacy with Google Assistant UsersAlejandra Gómez Ortega, Jacky Bourgeois, Gerd KortuemCHI 2023 · 被引用 33 次
- Regulating Responsibility: Environmental Sustainability, Law, and the Platformisation of Waste ManagementRob Comber, Chiara RossittoCHI 2023 · 被引用 24 次
- SoK: Technical Implementation and Human Impact of Internet Privacy RegulationsEleanor Birrell, Jay Rodolitz, Angel Ding, Jenna Lee 等S&P 2024 · 被引用 11 次
- Surrendering to Powerlesness: Governing Personal Data Flows in Generative AIAlejandra Gómez Ortega, Hosana Morales Ornelas, Ugur GençCHI 2025 · 被引用 9 次
- Understanding Chinese Internet Users' Perceptions of, and Online Platforms' Compliance with, the Personal Information Protection Law (PIPL)Morgana Mo Zhou, Zhiyan Qu, Jinhan Wan, Bo Wen 等CSCW 2024 · 被引用 9 次
相关 Paper
- Generating Practices: Investigations into the Double Embedding of GDPR and Data Access PoliciesJustin Petelka, Elisa Oreglia, Megan Finn, Janaki SrinivasanCSCW 2022 · 被引用 10 次
- Setting the Course, but Forgetting to Steer: Analyzing Compliance with GDPR's Right of Access to Data by Instagram, TikTok, and YoutubeSai Keerthana Karnam, Abhisek Dash, Antariksh Das, Sepehr Mousavi 等S&P 2026 · 被引用 3 次
- "It doesn't tell me anything about how my data is used": User Perceptions of Data Collection PurposesLin Kyi, Abraham Mhaidli, Cristiana Teixeira Santos, Franziska Roesner 等CHI 2024 · 被引用 22 次
- 'Transparency is Meant for Control' and Vice Versa: Learning from Co-designing and Evaluating Algorithmic News RecommendersElias Storms, Oscar Alvarado, Luciana Monteiro KrebsCSCW 2022 · 被引用 29 次
- Out of Sight, Out of Mind? Exploring Data Protection Practices for Personal Data in Usable Security & Privacy StudiesFlorin Martius, Luisa Jansen, Lukas Struck, Arthi Arumugam 等CHI 2025 · 被引用 7 次
