You cannot simultaneously believe anyone can request their data via these laws and then get mad that people do it, research or not.
It’s literally designed this way.
You cannot simultaneously believe anyone can request their data via these laws and then get mad that people do it, research or not.
It’s literally designed this way.
The idea is that the burden and stress of response is outweighed by benefit to the legitimate user. In this case there is no legitimate user.
This is similar to the concept of standing in the courts. Someone who is harmed can bring a suit for compensation or redress, but an uninvolved third party cannot.
Keep in mind the experiment wasn’t even making requests.
A more relevant example would be your right to go into a restaurant and see their food safety certificate.
Seems reasonable to me - for example you’re a prospective user and want to know how they handle requests, just in case you want to do it in the future after being a user.
The action you should take doesn’t depend on whether or not the email you’ve received is for research purposes.
If someone doesn’t understand this then they have no business running a public website.
Your answer will probably be: "personal blog don't fall under these regulations, so it's a non-issue" but that's exactly the point: these researchers scared a bunch of people into spending time to research a law that doesn't even apply to them, yet the chance that some random from Europe would send a GDPR request to their blog is essentially zero, because even privacy crusaders are smarter than these Princeton research to know that it makes no sense to do this.
Even if the general principle were ethical (not that I agree), the Princeton researches should have used a curated list of websites that could reasonably be expected to receive GDPR requests.
Stifling free speech is ridiculous hyperbole - no one was silenced by this. At worst people needlessly wasted time consulting a lawyer.
As for the personal blog: it is relevant, because the email was send to owners of personal blogs.
You claimed that the recipients of this email, such as personal blog owners, had no business running a website if they didn’t know the details a law that doesn’t apply to them. That’s stifling plain and simple.
Also in the usa most lawyers offer a free initial consultation.
“Please respond quickly.”? Fine.
“The law says you have a month to reply.”? A little aggressive, but OK.
“According to such-and-such code, section 45, part b, subsection 3, you have 87 hours from the time I sent this — that is, from 12:43:56 PM Eastern time on this date — to give your on-the-record response.”? They’ve got a lawyer, and this is going to be a pain in the ass.
These particular emails were somewhere between the second and third options.
> They’ve got a lawyer
...but this would suggest to me that this is cultural, since this thought would never occur to me.
> "Hey, neighbor, your dog is bothering us. Could you take it inside?"
Typical response: "Oh, sorry! Sure. Come here, pooch!"
> "Hello neighbor. According to county code section 23, 'Nuisances', paragraph 3, 'Pets', your dog can't bark for more than one minute without violating the ordinance and being subject to a fine of not more than $85."
Typical response: "Get off my property, and if your kid ever throws a baseball at my house again, I'm going to launch it through your front window."
Normal-person requests are usually formulated like "hi, can you do this thing for me?" even if the person being asked is obligated to do it. Citing law is considered an aggressive escalation.
I've gotten requests from people asking me to delete their account, sent from the email address they used to register it, along the lines of:
"Hi, I've forgotten my password, but I don't really use my account anyway. Could you delete it for me?"
And of course I comply, because I want to be helpful. They asked nicely; I replied nicely. It's a pleasant and productive interaction from all involved. This is the social norm here.
The entire thing is even worse because most of these websites were not under any obligation to reply but didn't know as much as they weren't experts in the law
In your view, what purpose does informing someone of a law related to their compliance serve?
> In your view, what purpose does informing someone of a law related to their compliance serve?
Well, obviously, in this case, it was about the time period expected. If you have reasonable assumption that your request is not common (for example businesses may plausibly receive far fewer GDPR requests then they receive product warranty requests), then communicating the expectation seems like a prudent thing to do since the other party is less likely to be familiar with it.
A legal expectation, no?
Spamming and wrong intentions can make an otherwise legitimate action unethical.
I think a ethical good study would be if they requested users to request their data from sites they use.
"I look forward to your reply without undue delay and at most within one month of this email, as required by Article 12 of GDPR."
Ultimately I don’t really get the big deal. It takes 5 minutes to reply to this, and if you don’t unless you’re some huge organization no one is going to waste resources bringing you to court.
It’s not that they’re implying that it is illegal - it’s that it is.
I do agree that there might be ethical concerns on how this study was conducted, however, the email messages do not suggest pending legal action. They're pretty standard GDPR requests.
Is it unethical? I dunno. But it's nuanced, at least.
Again, this is the reality of GDPR. It is not okay to operate a website serving EU visitors without considering GDPR implications. This is how GDPR is intended. Don't operate a website serving EU visitors if you don't have a plan on how to respond to these emails. I'm not trying to be harsh or dissuade these small websites from operating. It is just the reality of GDPR.