Human-GDPR Interaction: Practical Experiences of Accessing Personal Data
Honorable MentionAuthors
Title of the Paper
Human-GDPR Interaction: Practical Experiences of Accessing Personal Data
Paper Information
- Subject Area: Data Privacy and Personal Data Interaction
- Keywords: Privacy, GDPR, Information Access, Personal Data, Open Data, Data Portability, Human-Data Interaction (HDI), User Empowerment, Data Collection, Digital Rights, Trust, Information Literacy, Participatory Action Research
Research Background and Issues
-
What problems or challenges did the authors identify?
- Although the GDPR (General Data Protection Regulation) aims to enhance individuals' control over their personal data, its practical effectiveness is lacking. Many service providers offer low-quality responses and often fail to comply with legal requirements.
- Users find it difficult to understand the returned data and relate it to their own lives, hindering the full utilization of personal data.
- There is a power imbalance between data-holding companies and users, making it challenging for individuals to exercise their rights effectively, which further exacerbates user distrust.
-
Why is this issue important?
- In a data-centric society, personal data has become a critical resource for businesses, yet individual users often struggle to access, understand, or manage their own data. This lack of transparency not only affects user experience but also risks privacy violations and unfair practices.
- Enhancing control over data is a core topic in cutting-edge technology discussions, directly tied to individual rights, trust, and the development of the data economy.
-
Research Motivation and Related Work
- This study provides an in-depth exploration of the user experience and institutional effectiveness of GDPR, aiming to fill gaps in existing research on user-driven data interaction and institutional evaluation.
- Previous studies have highlighted the impact and limitations of GDPR on organizations (e.g., data portability, privacy by design), but there is a lack of comprehensive exploration from the user's perspective.
Solutions
-
What methods or solutions did the authors propose?
- The authors designed and conducted a mixed-methods study, combining multi-phase user interviews with practical analyses of GDPR data access requests.
- They proposed recommendations to improve transparency, enhance the data interaction experience, and design more effective data access systems.
- They positioned personal data control and exploration as a new technological direction in human-computer interaction, aiming to bridge the power gap between users and data holders through policy improvements and corporate optimizations.
-
What is innovative about this solution?
- They introduced a user goal categorization model (e.g., data reflection, self-empowerment), providing empirical guidance for policy and design.
- They recommended strengthening legal oversight of GDPR response quality and user education to improve data access experiences and promote data transparency.
- They proposed creating a collaborative platform centered on data support, offering a framework for improving user-enterprise relationships.
-
What are the implementation steps? What key technologies were used?
- Participants were recruited through convenience sampling and guided through GDPR data request processes.
- Step-by-step interviews captured participants' perceptions and data interaction experiences before, during, and after the requests.
- Coding and data analysis techniques were used to extract key themes from the interview transcripts, supplemented by quantitative data visualizations.
Research Outcomes
-
What specific outcomes were achieved?
- The study identified numerous limitations in the practical application of GDPR, such as low response rates, incomplete data returns, and data formats that are difficult to understand.
- Users' goals and needs (e.g., reflecting on personal data, increasing trust in service providers) were largely unmet.
- Transparent and supportive GDPR data requests can significantly enhance user trust and brand loyalty, but such cases remain rare.
-
How does it compare to existing solutions?
- This study focuses directly on user experience, uncovering the shortcomings of policies and technical designs in practice, and providing targeted recommendations for improvement.
- It proposed a new model for user-data holder interaction, emphasizing new opportunities for trust and data support.
-
What were the experimental or evaluation results?
- After data requests, user trust in service providers decreased in 52% of cases, while perceptions of power inequality with data holders increased in 74% of cases.
- The quality of returned data was generally low: only 22% of cases were considered complete, with much critical information (especially inferred data and metadata) missing.
- Data requests had limited impact on enhancing users' sense of empowerment and decision-making capabilities, with key needs such as data deletion and data interpretation largely unmet.
-
Limitations and Future Directions
- Limitations: The study had a small sample size, limited to a younger, tech-savvy demographic, which may not fully represent the general public's experiences. Participants received training from the research team, which might not reflect the natural behavior of ordinary users.
- Future Directions:
- Expand the sample size to include diverse groups with varying levels of technical proficiency and age ranges.
- Explore how GDPR interface design can foster user trust and identify best practices.
- Develop more systematic designs for data integration and intuitive analysis tools.
Research Questions / Practical Problems
Question signals indexed for this paper.
Research Questions
3- What specific problems do users encounter when accessing their personal data?Category: Personal Data Reflection and Goal-Setting SupportSimilar questionsarrow_forward
- What deficiencies exist in GDPR data access provisions in practice?Category: Personal Data Reflection and Goal-Setting SupportSimilar questionsarrow_forward
- How can policy and design improve user interaction experiences with data holders?Category: Personal Data Reflection and Goal-Setting SupportSimilar questionsarrow_forward
Practical Problems
1- Users struggle to access, understand, and manage their personal data and cannot effectively exercise data rights.Category: Personal Data Reflection and Goal-Setting SupportSimilar questionsarrow_forward
- 100%
SIGCHI Social Impact Award Talk – Making Privacy and Security More Usable
CHI '18· Privacy by Design & User Control +1
- 100%
You 'Might' Be Affected: An Empirical Analysis of Readability and Usability Issues in Data Breach Notifications
CHI '19· Privacy by Design & User Control +1
- 100%
Obfuscation Remedies Harms Arising from Content Flagging of Photos
CHI '22· Privacy by Design & User Control +1
- 100%
Understanding Privacy Switching Behaviour on Twitter
CHI '22· Privacy by Design & User Control +1
- 100%
How Language Formality in Security and Privacy Interfaces Impacts Intended Compliance
CHI '23· Privacy by Design & User Control +1
- 100%
The Impact of Risk Appeal Approaches on Users’ Sharing Confidential Information
CHI '24· Privacy by Design & User Control +1
- 75%
Contextualizing Privacy Decisions for Better Prediction (and Protection)
CHI '18· Privacy by Design & User Control +1
- 75%
“This App Would Like to Use Your Current Location to Better Serve You”: Importance of User Assent and System Transparency in Personalized Mobile Services
CHI '18· Privacy by Design & User Control +1
- 75%
A Field Study of Computer-Security Perceptions Using Anti-Virus Customer-Support Chats
CHI '19· Privacy by Design & User Control +1
- 75%
Machine Heuristic: When We Trust Computers More than Humans with Our Personal Information
CHI '19· Privacy by Design & User Control +1
Based on Jaccard similarity of research subtopics & professions (≥60%)