Amazon gives a German Alexa user, who requested his personal data under GDPR, access to 1,700 audio files of another user; Amazon says it was due to human error
FRANKFURT (Reuters) - A user of Amazon's (AMZN.O) Alexa voice assistant in Germany got access to more than a thousand recordings …
Context & Ripple Effects
This is the second Alexa privacy failure Amazon has had to explain in 2018: in May it blamed an Echo that recorded a private conversation and sent it to a contact on the device mishearing background speech as a wake-word confirmation. The new incident is different in kind — not a device misfiring inside one household, but Amazon's own data-subject-access process handing one customer another customer's recordings.
First-order effects
- A German user exercising GDPR access rights received 1,700 audio files from an unidentified stranger's account, exposing that person's home recordings to a third party through no action of their own.
- Amazon's 'human error' explanation puts its manual fulfillment of GDPR requests — the process meant to demonstrate compliance — directly at issue with European regulators.
Second-order effects
- The failure is not Amazon-specific: seven months later a Belgian broadcaster obtained over a thousand Google Assistant clips from a contractor, showing every major voice-assistant vendor's review pipeline leaks recordings and inviting regulators to treat these as a category, not isolated cases.
- Amazon's disclosure that it keeps Alexa transcripts and recordings indefinitely unless manually deleted sharpens the exposure — breaches like this surface archives that never had a deletion deadline.
Third-order effects
- GDPR subject-access requests are turning into an audit mechanism users and journalists run against assistant vendors, forcing structural changes to how voice data is stored, segmented, and retained rather than one-off apologies.
- If indefinite retention plus human review remains the default, the likely endpoint is regulator-mandated retention limits and automated deletion for voice corpora — a compliance cost baked into every assistant sold in Europe.
The trend: Voice-assistant privacy is shifting from device-level misfires to systemic data-handling failures, with GDPR access rights converting ordinary users into auditors of what assistants record and keep.