GDPR: When the Right to Access Personal Data Becomes a Threat

GDPR: When the Right to Access Personal Data Becomes a Threat
复制标题

GDPR:当访问个人数据的权利成为威胁时

DOI:
--
复制
发表时间:
2020
期刊:
2020 IEEE International Conference on Web Services (ICWS)
影响因子:
--
通讯作者:
Julinda Stefa
Julinda Stefa
中科院分区:
--
文献类型:
--
作者:
Luca Bufalieri;Massimo La Morgia;Alessandro Mei;Julinda Stefa

文献摘要

参考文献

被引文献

相似文献

GDPR生效一年后,所有网站和数据控制员都更新了存储用户数据的程序。GDPR不仅包括服务提供商应该如何保存数据以及应该保存哪些数据,而且还保证了一种简单的方法,即知道收集了哪些数据并自由地将其导出。在本文中,我们对GDPR第15条规定的数据获取权进行了全面的研究。我们检查了300多名数据控制员,要求他们每个人都能访问个人数据。我们发现,几乎每个数据控制器都有一个略微不同的程序来满足请求,以及几种将数据返回给用户的方法,从像CSV这样的结构化文件到监视器的屏幕截图。我们衡量完成访问数据请求所需的时间和所提供信息的完整性。在此阶段的数据收集之后,我们将分析数据控制器所遵循的身份验证过程,以确定请求者的身份。我们发现,50.4%的处理请求的数据控制器在识别用户的过程中或在发送数据的阶段存在缺陷,使用户面临新的威胁,即使这些数据控制器按照GDPR存储数据。我们令人惊讶和不受欢迎的结果表明,在目前的部署中,GDRP实际上降低了Web服务用户的隐私。
One year following the entry into force of the GDPR, all websites and data controllers have updated their procedures to store users' data. The GDPR does not only cover how and what data should be saved by the service providers, but it also guarantees an easy way to know what data are collected and the freedom to export them. In this paper, we carry out a comprehensive study on the right to access data provided by Article 15 of the GDPR. We examined more than 300 data controllers, requesting access to personal data to each of them. We found that almost each data controller has a slightly different procedure to fulfill the request and several ways to provide data back to the user, from a structured file like CSV to a screenshot of the monitor. We measure the time needed to complete the access data request and the completeness of the information provided. After this phase of data gathering, we analyze the authentication process followed by the data controllers to establish the identity of the requester. We find that 50.4% of the data controllers that handled the request have flaws in their procedures of identifying users or in their phase of sending the data, exposing users to new threats, even if these data controllers store data in compliance with the GDPR. Our surprising and undesired results show that, in its present deployment, the GDRP has actually decreased the privacy of users of web services.
DOI: 10.1145/3176258.3176332
发表时间: 2018-03
期刊: Proceedings of the Eighth ACM Conference on Data and Application Security and Privacy
影响因子: --
作者:
C. Wang;Steve T. K. Jan;Hang Hu;Douglas Bossart;G. Wang
通讯作者: C. Wang;Steve T. K. Jan;Hang Hu;Douglas Bossart;G. Wang