Needle in the Haystack: Analyzing the Right of Access According to GDPR Article 15 Five Years after the Implementation
Daniela P\"ohn, Niklas M\"orsdorf, Wolfgang Hommel

TL;DR
This study evaluates how well organizations comply with GDPR Article 15 by analyzing real-world data requests, revealing compliance levels, challenges, and patterns in data access experiences five years after regulation implementation.
Contribution
It provides a comprehensive quantitative analysis of GDPR Article 15 compliance, highlighting practical challenges and identifying patterns in data access requests across different organizations.
Findings
Some websites still compile data manually, causing delays.
A few organizations do not respond or provide non-machine-readable data.
Ten common patterns affect individuals' data access experiences.
Abstract
The General Data Protection Regulation (GDPR) was implemented in 2018 to strengthen and harmonize the data protection of individuals within the European Union. One key aspect is Article 15, which gives individuals the right to access their personal data in an understandable format. Organizations offering services to Europeans had five years' time to optimize their processes and functions to comply with Article 15. This study aims to explore the process of submitting and receiving the responses of organizations to GDPR Article 15 requests. A quantitative analysis obtains data from various websites to understand the level of conformity, the data received, and the challenges faced by individuals who request their data. The study differentiates organizations operating worldwide and in Germany, browser website- and app-based usage, and different types of websites. Thereby, we conclude that…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
