As companies comply with privacy laws like GDPR and CCPA, many have insecure practices for giving users their data and some outsource user identity verification
but it could let snoops & hackers see it too. Researchers have proved they can use access rights to get other people's files & @jeanqasaur had her Spotify data downloaded by a miscreant: https://www.nytimes.com/... Gus Hurwitz / @gushurwitz : Yep. And anyone who didn't see this coming shouldn't be in the business of writing laws. https://twitter.com/... Thomas Brewster / @iblametom : I hope someone downloads my Spotify data and gives me some kudos for my listening habits https://twitter.com/... Debra J. Farber / @privacyguru : Yep, GDPR's data subject access requests (DSAR) also created this new attack vector. New data rights become company obligations with new risks and technical challenges. https://twitter.com/... Lynne d Johnson / @lynneluvah : With privacy regs like #CCPA and #GDPR, accessing your data means giving up more personal info. But it's a necessary safeguard, as researchers have proven that hackers (or possibly even—god forbid—friends) could request your data. https://www.nytimes.com/... via @shareaholic @nytimesbusiness : To get access to your secret data file, you may have to give up more personal data https://www.nytimes.com/... Joseph Cox / @josephfcox : People moaning about having to verify their identity in order to download their wealth of data from a company is epitome of threat modelling. What, you want any rando to be able to do it? https://twitter.com/... David Carroll / @profcarroll : When I tried to encourage other US voters to request their Cambridge Analytica data using UK law similar to the #CCPA most people balked at the requirement to provide identity verification information. #DataRights https://www.nytimes.com/... via @kashhill Kashmir Hill / @kashhill : Many people seeking their secret score files have emailed me upset about the info the cos want in exchange for their files. Like forcing them to “look happy” in a selfie. There's a reason! The companies don't want creepers to get your file. https://www.nytimes.com/... https://twitter.com/...
Context & Ripple Effects
After the post-Cambridge Analytica collapse in trust over personal data, regulators handed users a legal right to their own files — GDPR's data subject access requests and CCPA equivalents — and companies built pipelines to comply. This reporting shows the pipes leak: researchers demonstrated attackers can abuse those same access rights to pull down other people's user files, and Jean Qasaur's Spotify data was downloaded by a stranger through exactly this route.
The irony is structural rather than incidental: the law mandates fast, low-friction data handover, while verifying who is actually asking was left as an afterthought — with many firms outsourcing identity checks entirely.
First-order effects
- Companies fulfilling GDPR and CCPA requests — Spotify among them, per the Qasaur incident — now face documented cases where an impostor's request yields another person's private files, forcing immediate rework of request-handling and identity verification.
- The outsourced identity-verification vendors these firms rely on become a named point of failure: whoever verifies the requester effectively controls access to everyone's data.
Second-order effects
- Compliance teams will have to trade away some of the mandated speed and low friction — adding verification steps that slow legitimate DSAR fulfillment and raise per-request costs across every covered company.
- Vendors selling identity-proofing for data-subject requests gain a compliance-driven market, while firms that can't verify cheaply may consolidate customer data behind fewer, better-defended custodians — the direction argued in [[a:929312|proposals for a central custodian such as Apple holding personal data under GDPR-style rules]].
Third-order effects
- If abuse of access rights keeps surfacing, privacy statutes will likely be amended to mandate requester verification — shifting the regulatory design question from 'how fast must data be returned' to 'who may ask,' a tension running through the broader wave of 50+ countries moving to control digital data.
- The episode reframes data rights as a security boundary: every new statutory right to obtain data expands the attack surface, meaning future privacy legislation will be written with adversaries, not just consumers, as the model requester.
The trend: Privacy laws that grant individuals rights over their data are colliding with security reality, forcing a redesign of identity verification wherever regulated data handover meets an unverified requester.