论文标题
人类GDPR互动:访问个人数据的实用经验
Human-GDPR Interaction: Practical Experiences of Accessing Personal Data
论文作者
论文摘要
在我们以数据为中心的世界中,大多数服务都依赖于收集和使用个人数据。欧盟的一般数据保护法规(GDPR)旨在增强个人对数据的控制,但其实际影响尚未得到充分理解。我们提出了一项10个参与的研究,每个参与者在其中提交了4-5个数据访问请求。通过伴随这些请求和讨论审查返回数据的访谈,由于不合规和低质量的响应,GDPR似乎没有达到其目标。参与者发现他们希望了解提供商的数据实践或利用自己的数据未得到满足。尽管更透明的提供商确实获得了更大的信任,但这会增加不信任,而没有任何主观的权力改善。我们建议设计更有效,包含数据的和开放的政策以及数据访问系统,以改善客户关系和个人代理,并且更广泛地公开使用GDPR权利可以帮助提供问责制,并激励提供者改善数据实践。
In our data-centric world, most services rely on collecting and using personal data. The EU's General Data Protection Regulation (GDPR) aims to enhance individuals' control over their data, but its practical impact is not well understood. We present a 10-participant study, where each participant filed 4-5 data access requests. Through interviews accompanying these requests and discussions scrutinising returned data, it appears that GDPR falls short of its goals due to non-compliance and low-quality responses. Participants found their hopes to understand providers' data practices or harness their own data unmet. This causes increased distrust without any subjective improvement in power, although more transparent providers do earn greater trust. We propose designing more effective, data-inclusive and open policies and data access systems to improve both customer relations and individual agency, and also that wider public use of GDPR rights could help with delivering accountability and motivating providers to improve data practices.