/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researcher says one in four UK- and US-based companies contacted to test a GDPR “right of access” request made in someone else's name revealed personal data

Leo Kelion / BBC :

BBC Leo Kelion

Context & Ripple Effects

The right of access has been stress-tested before: earlier this year a reporter exercising it received 138GB of raw personal data from Apple, Amazon, Facebook, and Google — much of it barely parseable. What that test didn't probe was the other side of the obligation: whether companies check who is actually asking.

This BBC experiment answers that, and the answer is uncomfortable — a quarter of UK- and US-based firms handed over personal data to requests made in someone else's name. It lands as regulators are already active on enforcement, from Privacy International's complaints against Oracle, Acxiom, and other data brokers to the UK authority's Cambridge Analytica probe.

First-order effects

  • Companies that disclosed data to an imposter have effectively leaked third parties' personal information through their own compliance process, exposing them to supervisory-authority action under the same GDPR rules they were following.
  • Individuals whose names were used in the tests had their data released without any request of their own — the access right became an exfiltration channel against them.

Second-order effects

  • Identity verification moves to the center of compliance spending: reporting on CCPA-era practice already shows firms with insecure disclosure processes and some outsourcing user verification, so demand for verification vendors grows as the failure rate becomes measurable.
  • Regulators now have a concrete, repeatable test methodology — fake-name requests — that complaint groups like Privacy International can deploy at scale against laggards.

Third-order effects

  • If the pattern holds, data-portability rights force a structural merge of privacy compliance and authentication: every access regime (GDPR today, CCPA-style laws next) needs a trusted identity layer, or the right itself becomes the industry's largest self-inflicted breach vector.
  • Firms that can't afford robust verification face the same asymmetry already documented with GDPR's compliance costs — the burden falls hardest on smaller players while Big Tech absorbs it.

The trend: Privacy regulation is entering its verification phase, where the binding constraint shifts from responding to access requests to proving who made them.

Discussion

  • @privacymatters Privacy Matters on x
    A University of Oxford researchers abuses subject access rights to challenge controller security measures 🤔 “Mr Pavur says he believes he did not break the law himself while conducting the trial”🤔 https://www.bbc.com/...
  • @brianhonan @brianhonan on x
    I just read this story from @BlackHatEvents “Black Hat: GDPR privacy law exploited to reveal personal data” This is a totally misinterpretation of #GDPR & shows orgs are in breach with poor implementation & not a flaw in the regulation itself! https://www.bbc.com/...
  • @lorenzofb @lorenzofb on x
    New: a researcher used Europe's data privacy law to steal his fiancé's identity (with her consent). Using GDPR's “right of access” requests," the researcher was able to get her SSN, passwords, home addresses and more. https://www.vice.com/...?
  • @cbridge_chief Daragh O Brien on x
    Black Hat: GDPR privacy law exploited to reveal personal data - BBC News > This is a bullshit take. Authentication and validation of requester not up to scratch. ascribing fault to the legislation is akin to blaming Road Traffic Act for a tailback. https://www.bbc.com/...
  • @privacyforum @privacyforum on x
    A study exploring security holes resulting from GDPR requirements for fulfilling data requests found that 1 in 4 companies contacted for the study released results to someone other than the actual data subject. https://www.bbc.com/...
  • @iansherr Ian Sherr on x
    This is my surprised face. https://twitter.com/...
  • @martinsfp Martin Sfp Bryant on x
    🤦‍♂️ https://twitter.com/...
  • @gcluley Graham Cluley on x
    About one in four companies revealed personal information to a woman's partner, who had made a bogus demand for the data by citing GDPR privacy legislation https://www.bbc.co.uk/...