A copy of this work was available on the public web and has been preserved in the Wayback Machine. The capture dates from 2022; you can also visit the original URL.
The file type is application/pdf
.
Revisiting Identification Issues in GDPR 'Right Of Access' Policies: A Technical and Longitudinal Analysis
2022
Proceedings on Privacy Enhancing Technologies
Several data protection regulations permit individuals to request all personal information that an organization holds about them by utilizing Subject Access Requests (SARs). Prior work has observed the identification process of such requests, demonstrating weak policies that are vulnerable to potential data breaches. In this paper, we analyze and compare prior work in terms of methodologies, requested identification credentials and threat models in the context of privacy and cybersecurity.
doi:10.2478/popets-2022-0037
fatcat:ml5yzplblbbl5b3qo7oejrn6gi