/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Testing GDPR's “Right of Access”, a reporter received 138GB of raw personal data from Apple, Amazon, Facebook, and Google, much of which was very hard to parse

Jon Porter / The Verge :

The Verge Jon Porter

Context & Ripple Effects

Jon Porter's experiment lands a year after Engadget surveyed how 30+ tech companies responded to personal-data requests and found their interpretations of what they hold remained opaque — this test answers the follow-up question of what actually arrives when the law forces an answer. It also sits inside a longer enforcement arc: European regulators have been pressing US platforms over data handling since German authorities opened their EU-to-US transfer investigations in 2015.

The result — 138GB from four of the biggest data holders, largely unparsable — reframes the right of access from a legal formality into a usability problem: compliance delivered is not comprehension delivered.

First-order effects

  • Apple, Amazon, Facebook, and Google must now field access requests at raw-dump scale, and each request exposes how little curation their exports get — the burden of making sense of the data shifts entirely to the user.
  • For requesters like Porter, the practical value of the right depends on parsing skill, meaning transparency is nominal unless the output is structured.

Second-order effects

  • The gap between delivering data and securing its delivery invites abuse: later testing found [[a:944652|one in four UK- and US-based companies handed personal data to requests made in someone else's name]], showing the same compliance channel doubles as a leak vector.
  • As GDPR and CCPA volume grows, platforms increasingly outsource user identity verification to meet deadlines, moving the trust boundary to vendors most users never chose.

Third-order effects

  • If raw, unparsable dumps remain the norm, regulators face pressure to define machine-readable export standards, turning the right of access from a document handover into a data-portability requirement.
  • The pattern points toward a split in privacy compliance itself: firms that treat access requests as a security surface will need verification infrastructure, while the rest accumulate breach risk through the very mechanism meant to empower users.

The trend: GDPR-era data rights are evolving from a legal obligation to produce data into an engineering problem of usable, secure delivery — where format standards and identity verification decide whether access empowers users or exposes them.