论文标题

GDPR:访问个人数据的权利成为威胁

GDPR: When the Right to Access Personal Data Becomes a Threat

论文作者

Bufalieri, Luca, La Morgia, Massimo, Mei, Alessandro, Stefa, Julinda

论文摘要

自GDPR生效的一年后,所有网站和数据控制器都已更新了其存储用户数据的过程。 GDPR不仅涵盖了服务提供商应保存的数据以及哪些数据,而且还保证了一种简单的方法来了解收集哪些数据并自由导出它们。 在本文中,我们对GDPR第15条提供的访问数据的权利进行了全面研究。我们检查了300多个数据控制器,为每个数据控制器执行了访问个人数据的请求。我们发现,几乎每个数据控制器都有一个略有不同的过程来满足请求,并有几种将数据提供给用户的方法,从诸如CSV之类的结构化文件到监视器的屏幕截图。我们衡量完成访问数据请求和提供信息的完整性所需的时间。在此数据收集阶段之后,我们分析了身份验证过程,然后是数据控制器建立请求者的身份。我们发现处理请求的数据控制器中有50.4 \%,即使他们符合GDPR的数据存储数据,在识别用户或发送数据的阶段,将用户暴露于新威胁的过程中存在缺陷。由于目前的部署中,GDPR实际上降低了Web服务用户的隐私,因此GDPR的结果是不希望的,令人惊讶的结果。

After one year since the entry into force of the GDPR, all web sites and data controllers have updated their procedures to store users' data. The GDPR does not only cover how and what data should be saved by the service providers, but it also guarantees an easy way to know what data are collected and the freedom to export them. In this paper, we carry out a comprehensive study on the right to access data provided by Article 15 of the GDPR. We examined more than 300 data controllers, performing for each of them a request to access personal data. We found that almost each data controller has a slightly different procedure to fulfill the request and several ways to provide data back to the user, from a structured file like CSV to a screenshot of the monitor. We measure the time needed to complete the access data request and the completeness of the information provided. After this phase of data gathering, we analyze the authentication process followed by the data controllers to establish the identity of the requester. We find that 50.4\% of the data controllers that handled the request, even if they store the data in compliance with the GDPR, have flaws in the procedure of identifying the users or in the phase of sending the data, exposing the users to new threats. With the undesired and surprising result that the GDPR, in its present deployment, has actually decreased the privacy of the users of web services.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源