Researcher says one in four UK- and US-based companies contacted to test a GDPR “right of access” request made in someone else's name revealed personal data
Context & Ripple Effects
The right of access has been stress-tested before: earlier this year a reporter exercising it received 138GB of raw personal data from Apple, Amazon, Facebook, and Google — much of it barely parseable. What that test didn't probe was the other side of the obligation: whether companies check who is actually asking.
This BBC experiment answers that, and the answer is uncomfortable — a quarter of UK- and US-based firms handed over personal data to requests made in someone else's name. It lands as regulators are already active on enforcement, from Privacy International's complaints against Oracle, Acxiom, and other data brokers to the UK authority's Cambridge Analytica probe.
First-order effects
- Companies that disclosed data to an imposter have effectively leaked third parties' personal information through their own compliance process, exposing them to supervisory-authority action under the same GDPR rules they were following.
- Individuals whose names were used in the tests had their data released without any request of their own — the access right became an exfiltration channel against them.
Second-order effects
- Identity verification moves to the center of compliance spending: reporting on CCPA-era practice already shows firms with insecure disclosure processes and some outsourcing user verification, so demand for verification vendors grows as the failure rate becomes measurable.
- Regulators now have a concrete, repeatable test methodology — fake-name requests — that complaint groups like Privacy International can deploy at scale against laggards.
Third-order effects
- If the pattern holds, data-portability rights force a structural merge of privacy compliance and authentication: every access regime (GDPR today, CCPA-style laws next) needs a trusted identity layer, or the right itself becomes the industry's largest self-inflicted breach vector.
- Firms that can't afford robust verification face the same asymmetry already documented with GDPR's compliance costs — the burden falls hardest on smaller players while Big Tech absorbs it.
The trend: Privacy regulation is entering its verification phase, where the binding constraint shifts from responding to access requests to proving who made them.