Amazon reveals private Alexa voice data files
heise.de
heise.de
The story here isn't that Echo stores recordings (they tell you they do, you can even listen to them) and it wasn't done "via GDPR" since that's a law, not a method of communication or platform.
(Submitted title was "Amazon Echo stores your voice recordings – sent other user’s records via GDPR".)
PSA: you can go into the Alexa app and look at your Echo history and even listen to recordings of each interaction.
https://myactivity.google.com/myactivity?restrict=vaa
I'm not sure if it's codified in law, but big tech companies are moving towards 'if we store non-anonymized user data, it must be possible for the user to log in and see it themselves'. I think they do that so they can argue that storing and playing back the audio is a feature of the product, rather than something ancillary they happen to do which might not be in the users interest.
They meant to give consumers insight into their own data. Instead they created a process for getting previously locked up private data out of the company, which is prone to human error and / or intentional abuse. Nice.
So the regulation is not at fault here, "they created a process for getting previously locked up private data out of the company, which is prone to human error and / or intentional abuse" is the real problem.
I currently have both and need to make a decision on which route I am going to go.
Each action has a card that explains what triggered it, what device, and what result was given, and you can listen to it. You can also turn recording storage off entirely, or delete by device or date ranges.
Honestly the only bad part is it's buried several layers down in the options and account activity, where most people don't go looking. If you do care though the privacy options and controls are pretty good.
It's actually a really cool feature; this entire fiasco could likely have been avoided if Amazon were to embrace the feature (data export and review) rather than treat it as something only nerds are interested in.
If you have data export by default (like Google's Data Takeout), then you don't need to build internal custom systems and manual processes that are only tested on GDPR requests. You've already built them for the default case. Handling GDPR requests is now user self-serve with a link to documentation explaining how to get their data.
To make the choice which route to go, you need to figure out which one has more integrations that are useful to you. Try integrating your other stuff with both and see which works better. Also try asking both the same questions and see which gives a better answer.
Relying on her to say "Alexa, play sexy music for Johnny" seems unreliable. But if you really want to use the Echo to spy on your wife, you can just review the voice history yourself.