Hot take: the researcher did nothing wrong. Some random person could make the same legitimate requests. If you dislike what this person did then really you just dislike that portion of the law.
You cannot simultaneously believe anyone can request their data via these laws and then get mad that people do it, research or not.
You can believe that users should be able to request this information legitimately, but arbitrary third parties should not.
The idea is that the burden and stress of response is outweighed by benefit to the legitimate user. In this case there is no legitimate user.
This is similar to the concept of standing in the courts. Someone who is harmed can bring a suit for compensation or redress, but an uninvolved third party cannot.
The answers to the questions don’t depend on whether or not the user is legitimate or not. Not to mention cases where the user isn’t even sure of their account information or lost email, etc.
I agree the answer does not depend on the legitimacy, but that doesn't matter. The answer to where were you last Tuesday night does not depend on who asks it, but only some have the right to ask that question and demand an answer.
I guess there in is the disagreement. Is the request more like one case or the other. It seems that most people feel the intent of the law is (or should be) to allow users to request information no, not any unrelated third-party
Indeed, but the experiment wasn’t about requesting information, it was about requesting their policy around handling user data.
Seems reasonable to me - for example you’re a prospective user and want to know how they handle requests, just in case you want to do it in the future after being a user.
Which is itself a request for information. I think a request for policy information is reasonable if they they didn't make up false identities and claim to be users.
It only takes a quick scan of the comments in this thread to see that there were people who received this email while hosting a static github.io website with their personal blog. That's a public website. Do you honestly think that anyone running a personal blog has no business doing so unless they are knowledgeable about the details of European and California website privacy rules? What a brilliant way to stifle public speech.
Your answer will probably be: "personal blog don't fall under these regulations, so it's a non-issue" but that's exactly the point: these researchers scared a bunch of people into spending time to research a law that doesn't even apply to them, yet the chance that some random from Europe would send a GDPR request to their blog is essentially zero, because even privacy crusaders are smarter than these Princeton research to know that it makes no sense to do this.
Even if the general principle were ethical (not that I agree), the Princeton researches should have used a curated list of websites that could reasonably be expected to receive GDPR requests.
I love the casualness about somebody wasting hundreds of dollars consulting a lawyer for something that isn’t relevant to them.
As for the personal blog: it is relevant, because the email was send to owners of personal blogs.
You claimed that the recipients of this email, such as personal blog owners, had no business running a website if they didn’t know the details a law that doesn’t apply to them. That’s stifling plain and simple.
People to whom the law doesn't apply are not necessarily very familiar with the details of this, and thus are going to be cautious if presented with what appears to be a legal threat. For a pro, this is easy to reply to, for random hobbyists it's not.
“The law says you have a month to reply.”? A little aggressive, but OK.
“According to such-and-such code, section 45, part b, subsection 3, you have 87 hours from the time I sent this — that is, from 12:43:56 PM Eastern time on this date — to give your on-the-record response.”? They’ve got a lawyer, and this is going to be a pain in the ass.
These particular emails were somewhere between the second and third options.
Asserting your rights (which you even say is "a little aggressive, but OK") as per specific regulation is far from being a legal threat where I live. That's just asserting your rights. A legal threat would be far worse.
> They’ve got a lawyer
...but this would suggest to me that this is cultural, since this thought would never occur to me.
How is this not a threat in the EU or anywhere? Yes it's made worse by the litigious nature of the US, but that's beside the point IMO. The sender is clearly implicating that there will be consequences for not responding. Even if this is the law and the sender is within their rights, it's still a threat.
The entire thing is even worse because most of these websites were not under any obligation to reply but didn't know as much as they weren't experts in the law
In your view, what purpose does informing someone of a law related to their compliance serve?
Saying on the basis of which regulation you're asking for something just isn't considered a threat where I live, period. People who want to make threats actually make threats.
> In your view, what purpose does informing someone of a law related to their compliance serve?
Well, obviously, in this case, it was about the time period expected. If you have reasonable assumption that your request is not common (for example businesses may plausibly receive far fewer GDPR requests then they receive product warranty requests), then communicating the expectation seems like a prudent thing to do since the other party is less likely to be familiar with it.
I'll have to take you at your word as I don't have experience where you live. Here, friendly requests tend to be much less formal. As a further example, suppose my dog was in my back yard barking, and this annoys my neighbor. They approach me about it:
> "Hey, neighbor, your dog is bothering us. Could you take it inside?"
Typical response: "Oh, sorry! Sure. Come here, pooch!"
> "Hello neighbor. According to county code section 23, 'Nuisances', paragraph 3, 'Pets', your dog can't bark for more than one minute without violating the ordinance and being subject to a fine of not more than $85."
Typical response: "Get off my property, and if your kid ever throws a baseball at my house again, I'm going to launch it through your front window."
Normal-person requests are usually formulated like "hi, can you do this thing for me?" even if the person being asked is obligated to do it. Citing law is considered an aggressive escalation.
A communication between two entities who are not friends is not "friendly". This is clearly a formal request of a type that is even regulated by a law. You're almost certainly not asking your neighbor about something like this. You're almost certainly asking someone you've never met in your life. Not sure what about it needs to be "friendly" any more that asking a government bureau using some formalized process (like filling out a form) needs to be "friendly".
I've gotten requests from people asking me to delete their account, sent from the email address they used to register it, along the lines of:
"Hi, I've forgotten my password, but I don't really use my account anyway. Could you delete it for me?"
And of course I comply, because I want to be helpful. They asked nicely; I replied nicely. It's a pleasant and productive interaction from all involved. This is the social norm here.
But the example you outlined is not regulated by any law as a formal procedure. That's an ad-hoc request. Of course it could also be phrased as an GDPR erasure request, but I bet you'd definitely expect that to be more formal and more specific. After all, that would be a (formally) legal request, and not just something you may decide to do or not to do depending on how you slept last night.
My door bell is designed to be pressed. But I do have a problem with someone who run down the street pressing every doorbell, because they want to gauge home owner's response time.
Spamming and wrong intentions can make an otherwise legitimate action unethical.
If anything, it seems like this was an effective means to introduce a lot of people to possible liabilities they have under GDPR/CCPA (or why they are not applicable to them).
Fine, but I had no desire to be introduced to the intricacies of the CCPA that afternoon. I was off minding my own business and didn’t ask for an “Are You Compliant For Dummies” course to be dropped in my lap.
Yes, but whether or not it’s explicitly stated doesn’t really change the law.
Ultimately I don’t really get the big deal. It takes 5 minutes to reply to this, and if you don’t unless you’re some huge organization no one is going to waste resources bringing you to court.
It’s not that they’re implying that it is illegal - it’s that it is.
I'm honestly baffled about the response, especially from the pro-privacy crowd on HN. This is simply the reality of GDPR. If you host and operate a website that serves EU visitors you must comply with GDPR. Of course this is a burden on small operators and it may come off alarming the first time you receive a GDPR request, however, this is GDPR working as intended. It is intended to force operators to explicitly decide which user data they are going to collect (incl. on how to inform users, correct, delete, export, etc. this data).
I do agree that there might be ethical concerns on how this study was conducted, however, the email messages do not suggest pending legal action. They're pretty standard GDPR requests.
The emails were sent to websites that do not process personal information and are thus not subject to GDPR, so the recipients were in some cases confused about what their responsibilities would be. And though the emails did not suggest that legal action was pending, they do suggest a willingness to resort to legal action in a relatively short time frame. This caused anxiety for apparently many small-time, non-profit bloggers.
Is it unethical? I dunno. But it's nuanced, at least.
As soon as the client's IP address touches your server you are processing personal information. E.g. I have seen many webserver which save these in their access logs.
Again, this is the reality of GDPR. It is not okay to operate a website serving EU visitors without considering GDPR implications. This is how GDPR is intended. Don't operate a website serving EU visitors if you don't have a plan on how to respond to these emails. I'm not trying to be harsh or dissuade these small websites from operating. It is just the reality of GDPR.
You cannot simultaneously believe anyone can request their data via these laws and then get mad that people do it, research or not.
It’s literally designed this way.