Testing GDPR's “Right of Access”, a reporter received 138GB of raw personal data from Apple, Amazon, Facebook, and Google, much of which was very hard to parse
Jon Porter / The Verge :
Context & Ripple Effects
Jon Porter's experiment lands a year after Engadget surveyed how 30+ tech companies responded to personal-data requests and found their interpretations of what they hold remained opaque — this test answers the follow-up question of what actually arrives when the law forces an answer. It also sits inside a longer enforcement arc: European regulators have been pressing US platforms over data handling since German authorities opened their EU-to-US transfer investigations in 2015.
The result — 138GB from four of the biggest data holders, largely unparsable — reframes the right of access from a legal formality into a usability problem: compliance delivered is not comprehension delivered.
First-order effects
- Apple, Amazon, Facebook, and Google must now field access requests at raw-dump scale, and each request exposes how little curation their exports get — the burden of making sense of the data shifts entirely to the user.
- For requesters like Porter, the practical value of the right depends on parsing skill, meaning transparency is nominal unless the output is structured.
Second-order effects
- The gap between delivering data and securing its delivery invites abuse: later testing found [[a:944652|one in four UK- and US-based companies handed personal data to requests made in someone else's name]], showing the same compliance channel doubles as a leak vector.
- As GDPR and CCPA volume grows, platforms increasingly outsource user identity verification to meet deadlines, moving the trust boundary to vendors most users never chose.
Third-order effects
- If raw, unparsable dumps remain the norm, regulators face pressure to define machine-readable export standards, turning the right of access from a document handover into a data-portability requirement.
- The pattern points toward a split in privacy compliance itself: firms that treat access requests as a security surface will need verification infrastructure, while the rest accumulate breach risk through the very mechanism meant to empower users.
The trend: GDPR-era data rights are evolving from a legal obligation to produce data into an engineering problem of usable, secure delivery — where format standards and identity verification decide whether access empowers users or exposes them.