首页> 外文会议>IEEE International Conference on Web Services >GDPR: When the Right to Access Personal Data Becomes a Threat
【24h】

GDPR: When the Right to Access Personal Data Becomes a Threat

机译:GDPR:当访问个人数据的权利成为威胁时

获取原文

摘要

One year following the entry into force of the GDPR, all websites and data controllers have updated their procedures to store users' data. The GDPR does not only cover how and what data should be saved by the service providers, but it also guarantees an easy way to know what data are collected and the freedom to export them. In this paper, we carry out a comprehensive study on the right to access data provided by Article 15 of the GDPR. We examined more than 300 data controllers, requesting access to personal data to each of them. We found that almost each data controller has a slightly different procedure to fulfill the request and several ways to provide data back to the user, from a structured file like CSV to a screenshot of the monitor. We measure the time needed to complete the access data request and the completeness of the information provided. After this phase of data gathering, we analyze the authentication process followed by the data controllers to establish the identity of the requester. We find that 50.4% of the data controllers that handled the request have flaws in their procedures of identifying users or in their phase of sending the data, exposing users to new threats, even if these data controllers store data in compliance with the GDPR. Our surprising and undesired results show that, in its present deployment, the GDRP has actually decreased the privacy of users of web services.
机译:在GDPR生效后一年,所有网站和数据控制器都更新了他们的程序来存储用户的数据。 GDPR不仅涵盖服务提供商应该如何以及哪些数据,但它还保证了一种简单的方法来了解收集的数据以及导出它们的自由。在本文中,我们对访问GDPR第15条提供的数据提供了全面的研究。我们检查了300多个数据控制器,请求访问每个数据的数据。我们发现几乎每个数据控制器都有一个略有不同的过程,以满足请求和几种方式来向用户提供数据,如CSV到监视器的屏幕截图。我们测量完成访问数据请求的时间和所提供信息的完整性所需的时间。在此阶段的数据收集之后,我们分析了验证过程,后跟数据控制器来建立请求者的身份。我们发现,即使这些数据控制器将数据符合GDPR存储数据,我们发现请求的50.4%的数据控制器识别出识别用户或发送数据的阶段,使用户识别为新威胁。我们令人惊讶和不希望的结果表明,在目前的部署中,GDRP实际上降低了Web服务用户的隐私。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号