Hacker News new | ask | show | jobs
by StreamBright 2724 days ago
Great idea, not sure how they implement this though. They can just email it to you because GDPR does not specify the delivery means.
2 comments

Just because the user is the one asking for the data doesn't mean the rest of the GDPR stops applying. They're still required to have appropriate safeguards, which means they certainly can't email it to you (at least not in plaintext).

Also, more specifically about the Right to Access, Recital 63 says: "Where possible, the controller should be able to provide remote access to a secure system which would provide the data subject with direct access to his or her personal data". (emphasis mine)

That's what I'd do if I were in their shoes.

I planned to document it and share with wider audience in case I find something out of the ordinary. For example, if they kept my location history for longer than is necessary to just route my data through their network, or if they had the contents of my texts, or DNS requests history.

Not sure how to pressure into the Google-style solution, but I think knowing would be a fist step.