What do they have on us?
Accessing and Assessing the Data Subject Access Request process �- Ameya Naik, UC Berkeley School of Information
Under guidance of Prof. Michael Buckland
Table of Contents
Data Subject Access Requests
An individual (data subject) may submit a Data Subject Access Request (DSAR) to a company to find out what information has been collected and stored about them or to ask that certain actions be taken with their data. A DSAR can be used to request that data be deleted, incorrect information be corrected, or that future data collection be opted out of.
Art. 15 GDPR : Right of access by the data subject
The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data and the following information:
California Consumer Privacy Act.
California Consumer Protection Act defines the rights has collects a consumer’s personal information disclose to that consumer the categories and specific pieces of personal information the business has collected.
Organizations must follow these steps to respond to a DSAR include:
The “Data” in Data Subject Access Request
GDPR’ Personal information:
Personal data means any information relating to an identifiable or identified natural person. Eg. identifier such as a name, an identification number, location data, an online identifier or one of several special characteristics, which expresses the physical, physiological, genetic, mental, commercial, cultural or social identity of these natural persons.
CCPA’s Personal Data:
The CCPA take broader approach towards what constitutes as personal information - it does contain browsing history, records of visitor’s interaction with the website/ application. Also includes, inferences drawn from the profile of the data subjects - eg consumer personas, etc.
Implementation
We all have multiple applications on our mobile phones with which we interact more than even with other humans. These application could be categorized under different labels depending on the their purpose. As per my the top frequently used applications on my IOS I have :
Evaluating the DSARs on different criterias
Application Tag | Application | Code | Data Access Request(Requested or not) | |
Streaming Service | Netflix | SS1 | Netflix | Yes |
Streaming Service | Hulu | SS2 | The Walt Disney Company | Yes |
Fitness Application | Apple fitness | F2 | Apple | Yes |
Messaging Application | Slack | MA2 | Salesforce | No - Standard Mechanism |
Messaging Application | MA1 | Yes | ||
Social Media | ST1 | Facebook - Details | Yes | |
Social Media | ST2 | Yes | ||
Social Media | ST3 | Yes | ||
Streaming Service | Youtube | SS1 | Yes | |
Social Media | ST4 | Yes | ||
Streaming Service | Prime Videos | ST5 | Amazon | Yes |
Music Stream Service | Amazon Music | MST1 | Amazon | Yes |
Fitness Application | Google Fit | F1 | No - separate Mechanism- through google | |
Music Stream Service | Spotify | MST2 | Spotify | Yes |
Research on the Parent organization
Since lot of application shared the data across hence, I had do research about the parent organisation and developer of the application.
Eg. Peacock Tv, is under NBCUniversal hence for the data request it had to be done through NBCUniversal ( which was still difficult to find )
CCPA is applicable to business:
The CCPA applies to for-profit businesses that do business in California and meet any of the following:
Spotify DSAR process
Quora DSAR process:
Future Scope
Thank you!
Questions/Comments/Suggestions are Welcomed!