The General Data Protection Regulation (GDPR) was implemented in 2018 to strengthen and harmonize the data protection of individuals within the European Union. One key aspect is Article 15, which gives individuals the right to access their personal data in an understandable format. Organizations offering services to Europeans had five years' time to optimize their processes and functions to comply with Article 15. This study aims to explore the process of submitting and receiving the responses of organizations to GDPR Article 15 requests. A quantitative analysis obtains data from various websites to understand the level of conformity, the data received, and the challenges faced by individuals who request their data. The study differentiates organizations operating worldwide and in Germany, browser website- and app-based usage, and different types of websites. Thereby, we conclude that some websites still compile the data manually, resulting in longer waiting times. A few exceptions did not respond with any data or deliver machine-readable data (GDRP Article 20). The findings of the study additionally reveal ten patterns individuals face when requesting and accessing their data.
翻译:译文摘要:《通用数据保护条例》(GDPR)于2018年实施,旨在加强和协调欧盟境内个人的数据保护。其核心条款第15条赋予个人以可理解格式访问其个人数据的权利。面向欧洲用户的服务机构有五年时间优化其流程与功能以符合第15条要求。本研究旨在探索向机构提交GDPR第15条请求及接收回复的流程。通过定量分析从各网站获取数据,以了解合规水平、所获取的数据内容及个人在请求数据时面临的挑战。研究区分了全球运营与德国本土运营的机构、基于浏览器网站与应用程序的使用模式,以及不同类型的网站。由此我们得出结论:部分网站仍采用人工方式汇编数据,导致等待时间延长;少数例外情况未提供任何数据或未交付机器可读数据(GDPR第20条)。研究结果还揭示了个人在请求与访问数据时面临的十种典型模式。