My Data Request: Request your data from over 100 companies
mydatarequest.com
mydatarequest.com
Your argument is at least formally wrong, the GDPR does not contain any such concept as personally identifiable information. It covers personal data.
An IP address can be personal data under some circumstances.
IANAL, but I would be more than surprised if the interpretation of personally identifiable information and personal data ends up to be identical in legal practice. I'd assume that even lawyers are not sure yet, because there isn't any practice yet.
I see that there's a way to suggest it to "request for me" as well, so that covers all bases!
When I created a new (my only) facebook account a few years back, it was clear they already knew that about 90% of my friends knew me.
They probably interpreted “what information do you have” as “give me a copy of my account”. If they still do this, someone in a GPDR country (but without a FB account) should go through this exercise, then report the violation.
I saw this practice in the wild, however I don't quite agree with supplying of any more information. Emails and phone numbers are most often used for identification on the web. What can they even do with an ID? Surely most sites don't store ID numbers.
Also how would they defend against fake IDs? If the purpose is to prevent malicious access then they better expect that attackers will try and use fakes.
At this point I see this practice mostly as deterrance with a little cya mixed in, possibly with a pinch of data fishing in some rare cases.
However in the future I'm all for providing IDs as a requirement to use webservices if that makes people more conscious about what data they share.
How could they transmit that info? They at least have stored your mail address.
If not why would you send them on a wild goose chase?
[1] "So Your Startup Received the Nightmare GDPR Letter " which contains
[2] "Is there amy regulation about how the data has to be formatted? Say I send a json string like "this is LITERALLY the data we use", but the avergae Joe is left irritated and annoyed, am I in trouble?"
---
From the ICO: (the UK regulator)
How should we provide the data to individuals?
If an individual makes a request electronically, you should provide the information in a commonly used electronic format, unless the individual requests otherwise.
The GDPR includes a best practice recommendation that, where possible, organisations should be able to provide remote access to a secure self-service system which would provide the individual with direct access to his or her information (Recital 63). This will not be appropriate for all organisations, but there are some sectors where this may work well.
However, providing remote access should not adversely affect the rights and freedoms of others – including trade secrets or intellectual property.
Ref: https://ico.org.uk/for-organisations/guide-to-the-general-da...
---