Streamlining personal data access requests: From obstructive procedures to automated web workflows

Nicola Leschke, Florian Kirsten, Frank Pallas, Elias Grünewald
{"title":"Streamlining personal data access requests: From obstructive procedures to automated web workflows","authors":"Nicola Leschke, Florian Kirsten, Frank Pallas, Elias Grünewald","doi":"10.48550/arXiv.2305.03471","DOIUrl":null,"url":null,"abstract":"Transparency and data portability are two core principles of modern privacy legislations such as the GDPR. From the regulatory perspective, providing individuals (data subjects) with access to their data is a main building block for implementing these. Different from other privacy principles and respective regulatory provisions, however, this right to data access has so far only seen marginal technical reflection. Processes related to performing data subject access requests (DSARs) are thus still to be executed manually, hindering the concept of data access from unfolding its full potential. To tackle this problem, we present an automated approach to the execution of DSARs, employing modern techniques of web automation. In particular, we propose a generic DSAR workflow model, a corresponding formal language for representing the particular workflows of different service providers (controllers), a publicly accessible and extendable workflow repository, and a browser-based execution engine, altogether providing ``one-click'' DSARs. To validate our approach and technical concepts, we examine, formalize and make publicly available the DSAR workflows of 15 widely used service providers and implement the execution engine in a publicly available browser extension. Altogether, we thereby pave the way for automated data subject access requests and lay the groundwork for a broad variety of subsequent technical means helping web users to better understand their privacy-related exposure to different service providers.","PeriodicalId":91383,"journal":{"name":"Proceedings of the ... International Conference on Web Information Systems Engineering. International Conference on Web Information Systems Engineering","volume":"92 1","pages":"111-125"},"PeriodicalIF":0.0000,"publicationDate":"2023-05-05","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the ... International Conference on Web Information Systems Engineering. International Conference on Web Information Systems Engineering","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.48550/arXiv.2305.03471","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

Abstract

Transparency and data portability are two core principles of modern privacy legislations such as the GDPR. From the regulatory perspective, providing individuals (data subjects) with access to their data is a main building block for implementing these. Different from other privacy principles and respective regulatory provisions, however, this right to data access has so far only seen marginal technical reflection. Processes related to performing data subject access requests (DSARs) are thus still to be executed manually, hindering the concept of data access from unfolding its full potential. To tackle this problem, we present an automated approach to the execution of DSARs, employing modern techniques of web automation. In particular, we propose a generic DSAR workflow model, a corresponding formal language for representing the particular workflows of different service providers (controllers), a publicly accessible and extendable workflow repository, and a browser-based execution engine, altogether providing ``one-click'' DSARs. To validate our approach and technical concepts, we examine, formalize and make publicly available the DSAR workflows of 15 widely used service providers and implement the execution engine in a publicly available browser extension. Altogether, we thereby pave the way for automated data subject access requests and lay the groundwork for a broad variety of subsequent technical means helping web users to better understand their privacy-related exposure to different service providers.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
简化个人数据访问请求:从阻碍程序到自动化web工作流程
透明度和数据可移植性是GDPR等现代隐私立法的两个核心原则。从监管的角度来看,为个人(数据主体)提供访问其数据的权限是实现这些功能的主要组成部分。然而,与其他隐私原则和相应的监管规定不同,这项数据访问权迄今为止在技术上的反映还很有限。因此,与执行数据主体访问请求(dsar)相关的流程仍然需要手动执行,这阻碍了数据访问概念充分发挥其潜力。为了解决这个问题,我们提出了一种自动化的方法来执行dsar,采用现代网络自动化技术。特别地,我们提出了一个通用的DSAR工作流模型,一个相应的表示不同服务提供者(控制器)的特定工作流的形式化语言,一个可公开访问和可扩展的工作流存储库,以及一个基于浏览器的执行引擎,共同提供“一键式”DSAR。为了验证我们的方法和技术概念,我们检查、形式化并公开了15个广泛使用的服务提供商的DSAR工作流,并在一个公开可用的浏览器扩展中实现了执行引擎。总之,我们因此为自动数据主体访问请求铺平了道路,并为各种各样的后续技术手段奠定了基础,帮助网络用户更好地了解他们在不同服务提供商面前与隐私相关的风险。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Streamlining personal data access requests: From obstructive procedures to automated web workflows The Rise of Disappearing Frameworks in Web Development Quantum Web Services: Development and Deployment Topio: An Open-Source Web Platform for Trading Geospatial Data In2P-Med: Toward the Individual Privacy Preferences Identity in the Medical Web Apps
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1