User Tools

Site Tools


privacy:data_subject_rights

This is an old revision of the document!


Data Subject Rights

Access, deletion and opt-out requests — the ones a person sends to a company. For HTTP requests and how to classify them as tracking, see Classifying Web Requests.

You want to know whether companies actually honour the rights the law gives people, or you want a copy of what a platform holds about somebody so you can measure it. Either way the instrument is a request: a message sent by a named, identifiable human being to a company, which answers or does not. That is a different machine from a crawler, and almost everything a crawl-shaped intuition tells you about sample size, ethics, automation and error is wrong here.

The scalable half of the topic is a signal rather than a message: Global Privacy Control, the “Do Not Sell or Share My Personal Information” link, the opt-out toggle inside an app. A crawler can send those, so the populations are three or four orders of magnitude bigger and the questions are different. Both halves are on this page because a student who needs one usually ends up needing the other.

Of the 5,859 papers in the publication corpus (CCS, IMC, NDSS, PoPETs, USENIX Security, TheWebConf and IEEE S&P, 2010–2026), 51 are in this page's population — 0.9%. 43 of the 51 are from 2021 or later, and PoPETs carries 25 of them, 4.9% of its own papers against IMC's 0.2%. The derivation is below; the short version is that this is a small, recent and venue-concentrated literature.

The short version.

  • The denominator is “controllers asked”, never “controllers that exist”. The median number of organisations a request-sending paper in this corpus wrote to is 30. The median crawl in the same corpus visits 10,000 sites. You are not going to fix that gap with a better script — the requests are sent by a person, verified against that person's identity, and answered by email.
  • Non-response is your most common observation, and it is data. 195 of the 454 registered California data brokers that [1Kempen, Elina van; Bagayatkar, Isita; Frolikov, Pavel; Georgiou, Chloe; Tsudik, Gene (2026): "Consumer Beware! Exploring Data Brokers' CCPA Compliance", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] wrote to — 43% — never replied at all. Declare a deadline and a follow-up rule before you start, and report non-response as a result rather than dropping it.
  • The response is a document you then have to code, so half of this is an annotation study. 84.3% of the 51 papers coded something by hand, against a corpus base rate of 56.6% — see Annotation.
  • You are the data subject. The ethics review is not the usual crawl review: you are disclosing your own identity documents to hundreds of strangers, and exercising the right can itself create a privacy risk. [2Martino, Mariano Di; Meers, Isaac; Quax, Peter; Andries, Ken; Lamotte, Wim (2022): "Revisiting Identification Issues in GDPR ‘Right Of Access’ Policies: A Technical and Longitudinal Analysis", in: Proceedings on Privacy Enhancing Technologies. (DOI)] and [1Kempen, Elina van; Bagayatkar, Isita; Frolikov, Pavel; Georgiou, Chloe; Tsudik, Gene (2026): "Consumer Beware! Exploring Data Brokers' CCPA Compliance", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] both found that out the hard way; see below.
  • On the signal side, know what is alive. GPC is a W3C Working Draft of 11 June 2026 and is mandatory in Colorado and California. The IAB US Privacy String was deprecated on 31 January 2024; Do Not Track's standard is retired, though its legal status is not quite zero. A 2022-vintage measurement of the USP string is a measurement of a retired standard.
If your question is… Then read
how to send access / deletion / opt-out requests and measure the answers this page
how to send and detect a machine-readable opt-out signal (GPC, “Do Not Sell”) this page, the signal section
what the crawler does with a consent banner, as a treatment Consent
what the IAB TC string encodes and how to parse it TCF consent strings
classifying HTTP requests as tracking or not Requests
what a privacy policy says about rights, as text Policies
taking a finding to a regulator after the paper is out Legal enforcement
coding the responses once you have them Annotation, Interrater agreement
whether you may run the study at all Ethics, and the ethics section below

Where this page stops

  • Consent owns the banner. Consent, and the withdrawal of consent through a banner, is a separate measurement with a separate literature; Johnny Can't Revoke Consent Either (PoPETs 2025) is a consent-revocation paper and is deliberately not in this page's population. The overlap is real — Art. 7(3) withdrawal is a data-subject right — and the practical split is: if the interface is the cookie banner, it is Consent; if it is a request form, an email, an account setting or a browser header, it is here.
  • TCF consent strings owns the TC string. This page owns the opt-out strings that sit next to it: the US Privacy String, the GPP string, and the .well-known/gpc.json file. The two families are often measured by the same crawl and are not the same object.
  • Legal enforcement owns what happens after the paper. Taking a violation to a DPA is that page. Sending a request as a data-collection method is this one. The 2024 and 2025 EDPB coordinated actions below sit on the boundary and are cited here because they are measurements.
  • “Right to be forgotten” in machine learning is a different field. Ten candidates in the sweep below were machine-unlearning papers. Unlearning is about removing a training example's influence from a model; this page is about a request reaching a controller.
  • Content takedown is not a data-subject right. DMCA notices, platform removal requests and blocklist de-listing all use the word “removal” and are out.

The request as an instrument

Name the denominator: controllers asked

There is no equivalent of the Tranco list here. Every paper in the population had to construct a set of organisations and write to each one, and the set is always a convenience, purposive or registry-derived sample. The table below is hand-keyed from each paper's own sentence, because the extraction's population[].n is the largest number the paper drew, not the number it wrote to — [3Farooqi, Shehroze; Musa, Maaz; Shafiq, Zubair; Zaffar, Fareed (2020): "CanaryTrap: Detecting Data Misuse by Third-Party Apps on Online Social Networks", in: Proceedings on Privacy Enhancing Technologies. (DOI)]'s biggest population is a 43,332-website list it never contacted, and its request sample is 100 apps.

Year Venue Asked What was asked, and of whom
2020 PoPETs 100 third-party Facebook apps sent a data-deletion request — 87 by email, 13 through a contact form; 45 of the 87 emailed responded [3Farooqi, Shehroze; Musa, Maaz; Shafiq, Zubair; Zaffar, Fareed (2020): "CanaryTrap: Detecting Data Misuse by Third-Party Apps on Online Social Networks", in: Proceedings on Privacy Enhancing Technologies. (DOI)]
2021 PoPETs 182 online services sent an Art. 20 export request [4Syrmoudis, Emmanuel; Mager, Stefan; Kuebler-Wachendorff, Sophie; Pizzinini, Paul; Grossklags, Jens; Kranz, Johann (2021): "Data Portability between Online Services: An Empirical Analysis on the Effectiveness of GDPR Art. 20", in: Proceedings on Privacy Enhancing Technologies. (DOI)]
2022 PoPETs 90 online services, erasure then a follow-up access request six months later [5Rupp, Eduard; Syrmoudis, Emmanuel; Grossklags, Jens (2022): "Leave No Data Behind – Empirical Insights into Data Erasure from Online Services", in: Proceedings on Privacy Enhancing Technologies. (DOI)]
2022 PoPETs 40 organisations re-evaluated in 2021, by registered letter, under five assumed subject identities [2Martino, Mariano Di; Meers, Isaac; Quax, Peter; Andries, Ken; Lamotte, Wim (2022): "Revisiting Identification Issues in GDPR ‘Right Of Access’ Policies: A Technical and Longitudinal Analysis", in: Proceedings on Privacy Enhancing Technologies. (DOI)]
2022 IEEE S&P 678 apps with their own sign-up, of 1,435 analysed: account created by hand, then deleted [6Santhanam, Preethi; Dang, Hoang; Shan, Zhiyong; Neamtiu, Iulian (2022): "Scraping Sticky Leftovers: App User Information Left on Servers After Account Deletion", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)]
2023 PoPETs 109 of 160 selected Android apps — the ones whose policies carried CCPA disclosures — sent a verifiable consumer request [7Samarin, Nikita; Kothari, Shayna; Siyed, Zaina; Bjorkman, Oscar; Yuan, Reena; Wijesekera, Primal; Alomar, Noura; Fischer, Jordan; Hoofnagle, Chris; Egelman, Serge (2023): "Lessons in VCR Repair: Compliance of Android App Developers with the California Consumer Privacy Act (CCPA)", in: Proceedings on Privacy Enhancing Technologies. (DOI)]
2024 PoPETs 20 people-search websites, access and removal attempted by four researchers [8Take, Kejsi; Young, Jordyn; Bhalerao, Rasika; Gallagher, Kevin; Forte, Andrea; McCoy, Damon; Greenstadt, Rachel (2024): "What to Expect When You’re Accessing: An Exploration of User Privacy Rights in People Search Websites", in: Proceedings on Privacy Enhancing Technologies. (DOI)]
2024 USENIX Sec 33 participants requested their own exports; 801 files. The controllers are not enumerated [9Borem, Arthur; Pan, Elleen; Obielodan, Olufunmilola; Roubinowitz, Aurelie; Dovichi, Luca; Mazurek, Michelle L.; Ur, Blase (2024): "Data Subjects' Reactions to Exercising Their Right of Access", in: Proceedings of the USENIX Security Symposium. (Link)]
2025 CCS 6 services, 12 researcher-controlled accounts [10Nonnenkamp, Julia; Gupta, Naman; Gupta, Abhimanyu Dev; Chatterjee, Rahul (2025): "Hidden in Plain Bytes: Investigating Interpersonal Account Compromise with Data Exports", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)]
2025 PoPETs 2 Amazon and Apple, to discover which interest labels to target across 200 fresh accounts [11Khezresmaeilzadeh, Tina; Zhu, Elaine; Grieco, Kiersten; Dubois, Daniel; Psounis, Konstantinos; Choffnes, David (2025): "Echoes of Privacy: Uncovering the Profiling Practices of Voice Assistants", Proceedings on Privacy Enhancing Technologies 2025(2). (DOI)]
2025 IMC 1 Amazon, as a cross-check on an advertising audit [12Le, Tu; Baldesi, Luca; Markopoulou, Athina; Butts, Carter T.; Shafiq, Zubair (2025): "From Voice to Ads: Auditing Commercial Smart Speakers for Targeted Advertising based on Voice Characteristics", in: Proceedings of the ACM Internet Measurement Conference. (DOI)]
2025 USENIX Sec 5 address-book service providers; none supplied the requested data [13Niksirat, Kavous Salehzadeh; Velykoivanenko, Lev; Mätzler, Samuel; Mulders, Stephan; Tamò-Larrieux, Aurelia; Boldi, Marc-Olivier; Humbert, Mathias; Huguenin, Kévin (2025): "Addressing the Address Books' (Interdependent) Privacy Issues", in: Proceedings of the USENIX Security Symposium. (Link)]
2025 USENIX Sec 494 apps whose deletion method was classified, of 863 with deletion-link data [14Yan, Jingwen; Liao, Song; Ma, Jin; Aldeen, Mohammed; Kumar, Salish; Cheng, Long (2025): "No Way to Sign Out? Unpacking Non-Compliance with Google Play's App Account Deletion Requirements", in: Proceedings of the USENIX Security Symposium. (Link)]
2025 PoPETs 4 paid PII-removal services subscribed to by 71 participants, which then send the opt-outs; the 10 services surveyed cover 1,759 brokers between them [15He, Jiahui; Snyder, Peter; Haddadi, Hamed; Bustamante, Fabián E.; Tyson, Gareth (2025): "Measuring the Accuracy and Effectiveness of PII Removal Services", in: Proceedings on Privacy Enhancing Technologies. (DOI)]
2026 IEEE S&P 454 of 543 registered California data brokers (84%), each sent a request by hand [1Kempen, Elina van; Bagayatkar, Isita; Frolikov, Pavel; Georgiou, Chloe; Tsudik, Gene (2026): "Consumer Beware! Exploring Data Brokers' CCPA Compliance", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)]
2026 TheWebConf 6 author-owned platform accounts, Art. 15(3) before and after an ad-free subscription [16Mousavi, Sepehr; Dash, Abhisek; Zannettou, Savvas; Gummadi, Krishna P. (2026): "Does Ad-Free Mean Less Data Collection? An Empirical Study of Platform Data Practices and User Expectations", in: Proceedings of the ACM Web Conference. (DOI)]
2026 IEEE S&P 3 platforms, via sock-puppet accounts and 80 recruited participants [17Karnam, Sai Keerthana; Dash, Abhisek; Das, Antariksh; Mousavi, Sepehr; Bechtold, Stefan; Gummadi, Krishna P.; Mukherjee, Animesh; Weber, Ingmar; Zannettou, Savvas (2026): "Setting the Course, but Forgetting to Steer: Analyzing Compliance with GDPR's Right of Access to Data by Instagram, TikTok, and Youtube", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)]

Median 30. Eleven of the sixteen stated counts are at or below 100. The comparable figure for the rest of the corpus: of the 1,120 papers that ran a crawl, 603 state a site-or-domain population size, and their median is 10,000. This is the single most important thing to internalise before you design the study — not because small samples are bad, but because everything downstream follows from it. You cannot stratify a sample of 30. A 10-percentage-point difference between two groups of 15 is not a finding. If you need a comparison across jurisdictions or sectors, build the sampling frame around that comparison from the start, because you will not be able to subset your way to it afterwards.

Two ways the population papers get more than 30, both worth copying:

  • Use a statutory registry as the frame. [1Kempen, Elina van; Bagayatkar, Isita; Frolikov, Pavel; Georgiou, Chloe; Tsudik, Gene (2026): "Consumer Beware! Exploring Data Brokers' CCPA Compliance", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] wrote to every data broker on California's official registry — 454 of the 543 registered, after exclusions — which is a census rather than a sample and removes the selection argument entirely. Registries exist in California, Vermont, Texas and Oregon, and [15He, Jiahui; Snyder, Peter; Haddadi, Hamed; Bustamante, Fabián E.; Tyson, Gareth (2025): "Measuring the Accuracy and Effectiveness of PII Removal Services", in: Proceedings on Privacy Enhancing Technologies. (DOI)] uses all four.
  • Measure the mechanism instead of the answer. [14Yan, Jingwen; Liao, Song; Ma, Jin; Aldeen, Mohammed; Kumar, Salish; Cheng, Long (2025): "No Way to Sign Out? Unpacking Non-Compliance with Google Play's App Account Deletion Requirements", in: Proceedings of the USENIX Security Symposium. (Link)], [6Santhanam, Preethi; Dang, Hoang; Shan, Zhiyong; Neamtiu, Iulian (2022): "Scraping Sticky Leftovers: App User Information Left on Servers After Account Deletion", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] and [18Shezan, Faysal Hossain; Su, Zihao; Kang, Mingqing; Phair, Nicholas; Thomas, Patrick William; van Dam, Michelangelo; Cao, Yinzhi; Tian, Yuan (2023): "CHKPLUG: Checking GDPR Compliance of WordPress Plugins via Cross-language Code Property Graph", in: Proceedings of the Network and Distributed System Security Symposium. (Link)] scale by checking whether the deletion path exists and works across hundreds or thousands of apps and plugins, and reserve the hand-sent request for a subsample. That is a different question — availability rather than compliance — and you should say which one you answered.

Non-response is the most common outcome

Across the population, the modal answer to a request is silence or a form that goes nowhere. [1Kempen, Elina van; Bagayatkar, Isita; Frolikov, Pavel; Georgiou, Chloe; Tsudik, Gene (2026): "Consumer Beware! Exploring Data Brokers' CCPA Compliance", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] put it at “Above 40% failed to respond at all, in an apparent violation of the CCPA” — and its Table 1 is the best thing in the request literature for orientation: 13 rows of prior studies, each with the number of entities asked, the law, the year and the response rate. The rates run from 55% to 100%, across populations of 20 to 454. That spread is not a trend; it is thirteen different populations, most of them published outside this corpus's seven venues — though three are in this page's population: [8Take, Kejsi; Young, Jordyn; Bhalerao, Rasika; Gallagher, Kevin; Forte, Andrea; McCoy, Damon; Greenstadt, Rachel (2024): "What to Expect When You’re Accessing: An Exploration of User Privacy Rights in People Search Websites", in: Proceedings on Privacy Enhancing Technologies. (DOI)], [2Martino, Mariano Di; Meers, Isaac; Quax, Peter; Andries, Ken; Lamotte, Wim (2022): "Revisiting Identification Issues in GDPR ‘Right Of Access’ Policies: A Technical and Longitudinal Analysis", in: Proceedings on Privacy Enhancing Technologies. (DOI)] and [7Samarin, Nikita; Kothari, Shayna; Siyed, Zaina; Bjorkman, Oscar; Yuan, Reena; Wijesekera, Primal; Alomar, Noura; Fischer, Jordan; Hoofnagle, Chris; Egelman, Serge (2023): "Lessons in VCR Repair: Compliance of Android App Developers with the California Consumer Privacy Act (CCPA)", in: Proceedings on Privacy Enhancing Technologies. (DOI)].

Three things a reviewer will look for, and which the corpus papers do unevenly:

  1. A stated deadline, taken from the law rather than from convenience. GDPR Art. 12(3) gives controllers “one month of receipt of the request”, extendable “by a maximum of two months” with notice inside the first month;1) the CCPA gives 45 days, extendable “once by an additional 45 days when reasonably necessary, provided the consumer is provided notice of the extension within the first 45-day period”.2) [1Kempen, Elina van; Bagayatkar, Isita; Frolikov, Pavel; Georgiou, Chloe; Tsudik, Gene (2026): "Consumer Beware! Exploring Data Brokers' CCPA Compliance", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] reports both the raw response rate (57%) and the on-time rate (51.5% within 45 calendar days), which is the right pair of numbers.
  2. A stated follow-up rule. [5Rupp, Eduard; Syrmoudis, Emmanuel; Grossklags, Jens (2022): "Leave No Data Behind – Empirical Insights into Data Erasure from Online Services", in: Proceedings on Privacy Enhancing Technologies. (DOI)] builds the follow-up into the design: erase first, then six months later send an Art. 15 access request to see what survived. That two-stage shape is the most transferable idea in the request literature and almost nobody else uses it.
  3. Coded reasons for non-response. “No reply” and “replied refusing” and “sent a broken form” are three different findings. [1Kempen, Elina van; Bagayatkar, Isita; Frolikov, Pavel; Georgiou, Chloe; Tsudik, Gene (2026): "Consumer Beware! Exploring Data Brokers' CCPA Compliance", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] reports a broker whose form link was broken and which then stopped responding; [13Niksirat, Kavous Salehzadeh; Velykoivanenko, Lev; Mätzler, Samuel; Mulders, Stephan; Tamò-Larrieux, Aurelia; Boldi, Marc-Olivier; Humbert, Mathias; Huguenin, Kévin (2025): "Addressing the Address Books' (Interdependent) Privacy Issues", in: Proceedings of the USENIX Security Symposium. (Link)] reports that of five providers asked, none supplied the requested data. Report the mechanism, not just the count.

What the corpus does not tell you, and you should find out before designing.

  • No paper in this population reports a re-ask: sending the same request twice to the same controller to measure whether the answer is stable. [2Martino, Mariano Di; Meers, Isaac; Quax, Peter; Andries, Ken; Lamotte, Wim (2022): "Revisiting Identification Issues in GDPR ‘Right Of Access’ Policies: A Technical and Longitudinal Analysis", in: Proceedings on Privacy Enhancing Technologies. (DOI)] re-evaluates 40 organisations two years apart, which is a longitudinal comparison of a changing policy, not a repeatability measurement. Response is treated throughout as a property of the controller rather than of the attempt.
  • Nor does any of them estimate inter-requester variation — several people sending the same request to the same controller and comparing what comes back. Two get close without doing it: [2Martino, Mariano Di; Meers, Isaac; Quax, Peter; Andries, Ken; Lamotte, Wim (2022): "Revisiting Identification Issues in GDPR ‘Right Of Access’ Policies: A Technical and Longitudinal Analysis", in: Proceedings on Privacy Enhancing Technologies. (DOI)] uses five assumed identities, but to probe the verification step rather than to measure variance, and [8Take, Kejsi; Young, Jordyn; Bhalerao, Rasika; Gallagher, Kevin; Forte, Andrea; McCoy, Damon; Greenstadt, Rachel (2024): "What to Expect When You’re Accessing: An Exploration of User Privacy Rights in People Search Websites", in: Proceedings on Privacy Enhancing Technologies. (DOI)] has four researchers attempt access at the same 20 sites, but reports whose data each site held rather than how each request was answered. Both claims here are about the 51 papers' abstracts and methodology sections; an appendix somewhere may prove them wrong.
  • Almost nobody reports the cost. [1Kempen, Elina van; Bagayatkar, Isita; Frolikov, Pavel; Georgiou, Chloe; Tsudik, Gene (2026): "Consumer Beware! Exploring Data Brokers' CCPA Compliance", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] is the exception and the number is worth quoting in your own methods section: “In total, 9 hours and 57 minutes were spent submitting VCRs to all 454 DBRs”, an average of 79 seconds each — for submission alone, before a single answer was read.

The answer is a document, so this is an annotation study

What comes back is a ZIP file, a PDF, a spreadsheet, an email, or a link that expires. Somebody has to read it and assign it a label, and the quality of the paper is mostly the quality of that codebook.

84.3% of the 51 papers (43) carry a hand-annotation step, against a corpus base rate of 56.6%. They are also better than the corpus at saying how well the annotators agreed: 37.2% of the annotating papers here state an agreement metric, against 15.4% across the corpus's 3,318 annotating papers. Better is not good: 27 of the 43 — nearly two in three — still do not.

The concrete difficulty is that the unit of annotation is not obvious. [9Borem, Arthur; Pan, Elleen; Obielodan, Olufunmilola; Roubinowitz, Aurelie; Dovichi, Luca; Mazurek, Michelle L.; Ur, Blase (2024): "Data Subjects' Reactions to Exercising Their Right of Access", in: Proceedings of the USENIX Security Symposium. (Link)] is the paper to read on this: 33 participants shared 801 files, the complexity “varied both across and within platforms”, and when the authors asked 59 specific questions of the exports, only 15 were fully answered. [17Karnam, Sai Keerthana; Dash, Abhisek; Das, Antariksh; Mousavi, Sepehr; Bechtold, Stefan; Gummadi, Krishna P.; Mukherjee, Animesh; Weber, Ingmar; Zannettou, Savvas (2026): "Setting the Course, but Forgetting to Steer: Analyzing Compliance with GDPR's Right of Access to Data by Instagram, TikTok, and Youtube", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] goes further and treats the export as something whose correctness can be measured, by browsing three platforms with sock-puppet accounts, requesting the export, and comparing it against a ground-truth log — reporting completeness and Jaccard similarity per platform, and concluding that “the failure to disclose processing purposes, retention periods, and other third-party data recipients serves as a further indicator of non-compliance” across all three. That design — instrument the behaviour, then ask for it back — is the strongest methodological idea in the 2026 slice, and it is the only way to separate “the platform did not collect it” from “the platform did not disclose it”.

You are the data subject

This is the part a crawl-shaped ethics review does not cover, and the reason the corpus papers' ethics sections read differently from the rest of the corpus: 62.7% of the 51 state an ethics review outcome, against a corpus base rate of 33.8% among empirical papers. Twenty-two say the study was approved; four say it was explicitly discussed without review; four say review was not required; two say exempt; nineteen say nothing at all.

What actually needs deciding:

  • Whose identity. [1Kempen, Elina van; Bagayatkar, Isita; Frolikov, Pavel; Georgiou, Chloe; Tsudik, Gene (2026): "Consumer Beware! Exploring Data Brokers' CCPA Compliance", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)]'s lead author used their own identity and the IRB declared the work non-human-subject research; [2Martino, Mariano Di; Meers, Isaac; Quax, Peter; Andries, Ken; Lamotte, Wim (2022): "Revisiting Identification Issues in GDPR ‘Right Of Access’ Policies: A Technical and Longitudinal Analysis", in: Proceedings on Privacy Enhancing Technologies. (DOI)] used five Hasselt University employees who consented. If you recruit participants to send requests, they are human subjects and the exports they return are some of the most sensitive data a study can hold.
  • The request creates a new disclosure. Verification asks for data the controller may not have had. [1Kempen, Elina van; Bagayatkar, Isita; Frolikov, Pavel; Georgiou, Chloe; Tsudik, Gene (2026): "Consumer Beware! Exploring Data Brokers' CCPA Compliance", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] found that brokers “requested personal information as part of their identity verification process, including details they had not previously collected”, including selfies, signed affidavits and partial Social Security numbers, and states the consequence plainly: “exercising one's privacy rights under CCPA introduces new privacy risks”. Budget for the possibility that your experiment leaks your co-authors.
  • The request can leak other people. [2Martino, Mariano Di; Meers, Isaac; Quax, Peter; Andries, Ken; Lamotte, Wim (2022): "Revisiting Identification Issues in GDPR ‘Right Of Access’ Policies: A Technical and Longitudinal Analysis", in: Proceedings on Privacy Enhancing Technologies. (DOI)] found 17 of 40 organisations vulnerable to a weak-authentication attack on the access right, and every vulnerable organisation leaked at least some sensitive personal data. [1Kempen, Elina van; Bagayatkar, Isita; Frolikov, Pavel; Georgiou, Chloe; Tsudik, Gene (2026): "Consumer Beware! Exploring Data Brokers' CCPA Compliance", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] reports one broker disclosing sensitive information about a housemate. Decide in advance what you do when a controller sends you a stranger's data — and note that this is also a disclosure you will have to make to somebody.
  • Third parties end up in your dataset. [13Niksirat, Kavous Salehzadeh; Velykoivanenko, Lev; Mätzler, Samuel; Mulders, Stephan; Tamò-Larrieux, Aurelia; Boldi, Marc-Olivier; Humbert, Mathias; Huguenin, Kévin (2025): "Addressing the Address Books' (Interdependent) Privacy Issues", in: Proceedings of the USENIX Security Symposium. (Link)] is an address-book study: the contacts in a donated address book never agreed to anything.
  • Requests come back at you. When you notify or recruit at scale, some recipients exercise their rights against you. [19Abramova, Svetlana; Böhme, Rainer (2023): "Anatomy of a High-Profile Data Breach: Dissecting the Aftermath of a Crypto-Wallet Case", in: Proceedings of the USENIX Security Symposium. (Link)] — not in this population, but the cleanest instance in the corpus — reports receiving 6 requests exercising the right to erase and 11 objections to processing from the people it had contacted. Have the process ready before you send the first email; see Ethics and Notifying websites.

Machine-readable opt-out is the scalable half

A browser can assert an opt-out on every site it visits, which turns a 30-controller study into a 10,000-site crawl. Four signals have tried this. Two are alive: GPC, which a person sets, and the IAB's GPP, which carries the result between publisher and vendors. The other two are history you still have to recognise in older papers.

Signal Status on 2026-09-16 What it is, for a measurement
Do Not Track (DNT: 1) Standard retired; legal status not zero. The W3C Tracking Protection Working Group “closed on 17 January 2019” and both its specifications are marked retired.3) But in October 2023 the Berlin Regional Court held that LinkedIn's public statement that it ignores DNT was misleading, because under the GDPR “the right to object to the processing of personal data can also be expressed using an automated procedure”.4) One statute does name it, and naming the right one matters: CalOPPA requires a site's privacy policy to “Disclose how the operator responds to Web browser “do not track” signals”,5) which makes the disclosure measurable — it is text in a policy — without making the honouring of the signal an obligation anywhere. Nothing gives DNT the effect California and Colorado give GPC. Record it as a covariate, cite it when explaining why GPC exists, and if you measure “DNT compliance”, say whether you mean the disclosure or the behaviour.
IAB US Privacy String (usprivacy, the 1YYN values) Deprecated 31 January 2024. The IAB's own repository states: “The US Privacy signal has been deprecated as of January 31, 2024. We strongly advise all users of the US Privacy String to transition to the Global Privacy Protocol”.6) An adtech-internal string carrying opt-out status between publisher and vendors, readable from a cookie or the __uspapi JavaScript API. Every corpus paper that measures it [20Zimmeck, Sebastian; Wang, Oliver; Alicki, Kuba; Wang, Jocelyn; Eng, Sophie (2023): "Usability and Enforceability of Global Privacy Control", Proceedings on Privacy Enhancing Technologies 2023(2). (DOI)] [21Aziz, Muhammad Abu Bakar; Wilson, Christo (2024): "Johnny Still Can't Opt-out: Assessing the IAB CCPA Compliance Framework", in: Proceedings on Privacy Enhancing Technologies. (DOI)] [22Hausladen, Katherine; Wang, Oliver; Eng, Sophie; Wang, Jocelyn; Wijaya, Francisca; May, Matthew; Zimmeck, Sebastian (2025): "Websites' Global Privacy Control Compliance at Scale and over Time", in: Proceedings of the USENIX Security Symposium. (Link)] crawled before or around the sunset.
Global Privacy Platform → Global Privacy Protocol (GPP) Live and the successor. Renamed from “Platform” to “Protocol”. The specification page's own Last updated stamp is 12 August 2026, and the August 2026 MSPA-alignment update was in public comment until 11 September 2026 — five days before this page was written, with no finalised outcome posted yet.7) A container carrying per-jurisdiction sections (US national, plus per-state strings). If you are writing a parser in 2026, target GPP sections, not usprivacy. Note the rename when you cite pre-2026 papers, which all say “Platform”.
Global Privacy Control (Sec-GPC: 1 and navigator.globalPrivacyControl) W3C Working Draft, 11 June 2026, published by the W3C Privacy Working Group.8) Legally mandatory in California and Colorado, and California now legislates the browser side too (see below). The user-agent-to-site signal, and the only one of the four a person sets directly. This is where the measurement literature now is.

What GPC is, and what your crawler does about it

GPC is one bit in two places: an HTTP request header Sec-GPC: 1 and a DOM property navigator.globalPrivacyControl. That is the whole specification's wire format; everything else is legal interpretation.

Which jurisdictions make it binding is itself a moving denominator. Colorado's Attorney General maintains the statutory list and states that “Currently, GPC is the only UOOM considered valid by The Department”, binding on covered businesses “Beginning July 1, 2024”.9) California's CCPA regulations require businesses to honour opt-out preference signals, and the California Attorney General has brought enforcement actions over GPC. Several further states — Connecticut, Delaware, Montana, Oregon and Texas among them — have universal-opt-out provisions of their own, and more have taken effect in 2026. This page does not publish a state count: the lists that circulate are vendor trackers, the effective dates differ from the enforcement dates, and no single authoritative register exists. If your paper needs the count, derive it from each state's own AG page and date it, as the two above are dated here.

The browser support matters for your crawl, and it is narrow. Per MDN's browser-compatibility data, navigator.globalPrivacyControl is supported in Firefox 120 on desktop and Firefox 122 on Android — opt-in in both, via the “Tell websites not to sell or share my data” setting or the privacy.globalprivacycontrol.enabled preference — and is not supported in Chrome or Safari.10) MDN's table does not cover every browser: Brave and DuckDuckGo both implement GPC and are listed among the project's implementing organisations,11) but neither appears in the compatibility data. If your crawl uses one, verify the signal on the wire — request a page from a server you control and look for Sec-GPC: 1 — rather than trusting any support table, this one included.

This is about to change by statute, and it will change what a crawl can do. California AB 566 was approved by the Governor on 8 October 2025 as Chapter 465 and adds §1798.136 to the Civil Code: “beginning January 1, 2027”, it prohibits a business “from developing or maintaining a browser, as defined, that does not include functionality configurable by a consumer that enables the browser to send an opt-out preference signal, as defined, to businesses with which the consumer interacts through the browser”.12) Chrome has a chromestatus entry for GPC whose stated motivation is precisely that bill — “This year California signed a bill under the CCPA/CPRA that obligates the browsers to provide ability to communicate do-not-sell-or-share preference before 2027” — but it is at stage Proposed, was last touched on 2026-01-02, has no milestone attached and was not filed by a Google address.13) Nothing has shipped. If you are planning a longitudinal crawl that spans 1 January 2027, pin and record the browser build, because the baseline for “does this browser send GPC” is a statutory deadline away from moving.

Three consequences for the crawler:

  • Chrome, and the plain Chromium your automation library bundles, cannot send GPC natively — Brave is Chromium and does, which is the point: it is a browser-vendor choice, not a Chromium limitation. If your instrument is Puppeteer or Playwright over stock Chromium — which is most of the field — you must inject Sec-GPC: 1 yourself on every request, and separately define navigator.globalPrivacyControl in the page context, because a site may check either. Checking only the header under-detects sites that read the DOM property, and vice versa.
  • GPC is a treatment, so it needs a control arm. Every good measurement here is paired: the same crawl with and without the signal. [23Rasaii, Ali; Dao, Ha; Feldmann, Anja; Javid, Mohammadmahdi; Gasser, Oliver; Gosain, Devashish (2025): "Intractable Cookie Crumbs: Unveiling the Nexus of Stateful Banner Interaction and Tracking Cookies", in: Proceedings on Privacy Enhancing Technologies, pp. 429-445. (DOI)] is the cleanest small example: enabling GPC cuts a site's intractable cookies — the paper's term for tracking cookies sent to third-party domains before that site has obtained consent, carried over from a banner accepted elsewhere — by about 30% on average, with a further 32% on a later visit that also rejects the banner. The number only means anything because the no-GPC arm exists.
  • Compliance is invisible in the network trace alone. A site that honours GPC mostly does so by not doing something, and the observable proxies are the privacy strings. [22Hausladen, Katherine; Wang, Oliver; Eng, Sophie; Wang, Jocelyn; Wijaya, Francisca; May, Matthew; Zimmeck, Sebastian (2025): "Websites' Global Privacy Control Compliance at Scale and over Time", in: Proceedings of the USENIX Security Symposium. (Link)] reads four of them — the US Privacy String, the GPP string, the OneTrust OptanonConsent cookie and /.well-known/gpc.json — which is the current state of the art for detection and is also an admission that there is no direct signal.

What the signal-side papers measured, with each paper's own denominator

Read these as separate studies of separate populations. They are not a time series.

  • Roughly one site in ten offers a manual opt-out link. [24Charatan, Jan; Birrell, Eleanor (2024): "Two Steps Forward and One Step Back: The Right to Opt-out of Sale under CPRA", in: Proceedings on Privacy Enhancing Technologies. (DOI)] found 2,429 of the top 25,000 Tranco websites (9.9%) with an opt-out-of-sale link in November 2022. [25Van Nortwick, Maggie; Wilson, Christo (2022): "Setting the Bar Low: Are Websites Complying With the Minimum Requirements of the CCPA?", in: Proceedings on Privacy Enhancing Technologies. (DOI)], looking specifically for the CCPA's mandated “Do Not Sell My Personal Information” wording across a much larger corpus, found 9,838 of 497,870 reachable English-language homepages — 2% — and found, in a second crawl whose 12,222 DNSMPI sites are a different set from the 9,838, that 2,101 (17%) show the link only to some visitors — 1,293 (62%) deciding client-side and 808 (38%) server-side. Geofenced links are a trap for a single-vantage crawl; see Crawling location.
  • Where a site has the machinery, it honours the signal about half the time. [22Hausladen, Katherine; Wang, Oliver; Eng, Sophie; Wang, Jocelyn; Wijaya, Francisca; May, Matthew; Zimmeck, Sebastian (2025): "Websites' Global Privacy Control Compliance at Scale and over Time", in: Proceedings of the USENIX Security Symposium. (Link)], crawling 11,708 sites longitudinally, found that “about a third of sites that have evidence of selling or sharing personal information per the CCPA implement at least one of the four privacy strings”, and among those, 44% (1,411/3,226) in December 2023, 43% in February 2024 and 45% (1,620/3,566) in April 2024 opted the user out through every string they implemented. Note what the denominator is: not “all sites”, not even “all CCPA-covered sites”, but sites that both sell or share and implement a string.
  • The earlier number was much worse, on a narrower denominator. [20Zimmeck, Sebastian; Wang, Oliver; Alicki, Kuba; Wang, Jocelyn; Eng, Sophie (2023): "Usability and Enforceability of Global Privacy Control", Proceedings on Privacy Enhancing Technologies 2023(2). (DOI)] found 54 of 464 (12%) sites carrying a US Privacy String honoured GPC as of August 2022. Between that and the 44% above lie a CPRA enforcement deadline, two Attorney-General actions and a different site set — do not read the pair as a trend.
  • The adtech plumbing does not carry the opt-out reliably. [21Aziz, Muhammad Abu Bakar; Wilson, Christo (2024): "Johnny Still Can't Opt-out: Assessing the IAB CCPA Compliance Framework", in: Proceedings on Privacy Enhancing Technologies. (DOI)] found the USP API on 821 of the top 10,000 publishers (8.2%); of the 825 with the API, only 380 (46.1%) converted a GPC signal into an opt-out USP String; and when the string did say opt-out, there was no statistically significant reduction in tracking pixels for most crawl comparisons. Propagation is measurable: 17.9% of the 1,214,540 advertising-and-analytics inclusion chains rooted at a USP publisher carried the string at least once.
  • Trackers' own opt-out tools are inconsistent with their own policies. [26Bui, Duc; Tang, Brian; Shin, Kang G. (2022): "Do Opt-Outs Really Opt Me Out?", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)] built OptOutCheck over merged tracker lists and the top 5,000 US sites and found 11 trackers whose behaviour after opting out contradicted their stated no-collection or no-tracking policies, with 100% precision and 68.75% recall on its own test set. The oldest instance of this design in the corpus is [27Acar, Gunes; Eubank, Christian; Englehardt, Steven; Juarez, Marc; Narayanan, Arvind; Díaz, Claudia (2014): "The Web Never Forgets: Persistent Tracking Mechanisms in the Wild", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)], which opted out of every company on the NAI and EDAA lists and then measured whether the persistent-tracking mechanisms it studied went away.
  • Opting out does not stop the bidding. [28Liu, Zengrui; Iqbal, Umar; Saxena, Nitesh (2024): "Opted Out, Yet Tracked: Are Regulations Enough to Protect Your Privacy?", in: Proceedings on Privacy Enhancing Technologies. (DOI)] opted personas out under both GDPR and CCPA across 352 sites running a CMP and client-side header bidding, and found that most personas still received higher bids than the control after opting out, with cookie syncing continuing across CMPs and jurisdictions. This is the strongest “the signal is not the effect” result in the corpus and the reason to measure downstream behaviour rather than the string.
  • On mobile there is barely a mechanism at all. [29Zimmeck, Sebastian; Aggarwal, Nishant; Liu, Zachary; Altman, Sage; Kollnig, Konrad (2026): "Exercising the CCPA Opt-out Right on Android: Legally Mandated but Practically Challenging", in: Proceedings on Privacy Enhancing Technologies. (DOI)] (PoPETs 2026) is the newest and bluntest: “only 48 out of 100 apps implement a respective setting” for the CCPA opt-out right, and sending GPC to an app dataset of 1,811 apps was “largely ineffective” — with GPC set and AdID access disabled, 338 apps still had the ad network Vungle's ccpa status set to opted_in while only 26 had opted_out. The paper estimates with 95% confidence that 62–81% of its apps are subject to the right.
  • An “opt out” can make the outcome worse. [30Mai, Cat; Coelho, Bruno; Kieserman, Julia; Matsumoto, Lexie; Spinelli, Kyle; Yang, Eric; Andreou, Athanasios; Greenstadt, Rachel; Lauinger, Tobias; McCoy, Damon (2025): "More and Scammier Ads: The Perils of YouTube's Ad Privacy Settings", in: Proceedings on Privacy Enhancing Technologies. (DOI)] disabled YouTube's ad personalisation and measured what was served instead: 1.30× more pre-roll ads, and the share of predatory advertisements rose from 2.5% to 8.7%. Whatever you are measuring, measure the thing the user cares about, not only whether the toggle moved.
  • The self-service dashboard is the other opt-out surface. [31Bashir, Muhammad Ahmad; Farooq, Umar; Shahid, Maryam; Zaffar, Muhammad Fareed; Wilson, Christo (2019): "Quantity vs. Quality: Evaluating User Interest Profiles Using Ad Preference Managers", in: Proceedings of the Network and Distributed System Security Symposium. (Link)] and [32Caravaca, Francisco; González-Cabañas, José; Cuevas, Ángel; Cuevas, Rubén (2024): "Overprofiling Analysis on Major Internet Players", in: Proceedings on Privacy Enhancing Technologies. (DOI)] both pull interest profiles out of ad preference managers, and [33Gkiouzepi, Eleni; Andreou, Athanasios; Goga, Oana; Loiseau, Patrick (2023): "Collaborative Ad Transparency: Promises and Limitations", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] monitors them through an extension. It is also a data source — see the next section.

The export as a dataset

Ten of the 51 papers do not measure the right at all — they use it to get data, and if what you want is a platform's own record of somebody, this is the cheapest route in the literature. [34Wei, Miranda; Stamos, Madison; Veys, Sophie; Reitinger, Nathan; Goodman, Justin; Herman, Margot; Filipczuk, Dorota; Weinshel, Ben; Mazurek, Michelle L.; Ur, Blase (2020): "What Twitter Knows: Characterizing Ad Targeting Practices, User Perceptions, and Ad Explanations Through Users' Own Twitter Data", in: Proceedings of the USENIX Security Symposium. (Link)] takes 447 Prolific participants' own Twitter data and gets 240,651 targeted ads out of it; [35Karnam, Sai Keerthana; Dash, Abhisek; Gummadi, Krishna P.; Mukherjee, Animesh; Weber, Ingmar; Zannettou, Savvas (2026): "Bowling with ChatGPT: On the Evolving User Interactions with Conversational AI Systems", in: Proceedings of the ACM Web Conference. (DOI)] recruits 300 people who exercise Art. 15 against OpenAI and donate 138,231 ChatGPT conversations; [36Zaman, Anis; Acharyya, Rupam; Kautz, Henry A.; Silenzio, Vincent (2019): "Detecting Low Self-Esteem in Youths from Web Search Data", in: Proceedings of the ACM Web Conference. (DOI)] and [37Akgul, Omer; Roberts, Richard; Shroyer, Emma; Levin, Dave; Mazurek, Michelle L. (2025): "As Advertised? Understanding the Impact of Influencer VPN Ads", in: Proceedings of the USENIX Security Symposium. (Link)] use Google Takeout search and watch histories; [38Onaolapo, Jeremiah; Leontiadis, Nektarios; Magka, Despoina; Stringhini, Gianluca (2021): "SocialHEISTing: Understanding Stolen Facebook Accounts", in: Proceedings of the USENIX Security Symposium. (Link)] pulls Facebook's Download Your Information export from 1,008 honeypot accounts it controls itself; [39Vombatkere, Karan; Mousavi, Sepehr; Zannettou, Savvas; Roesner, Franziska; Gummadi, Krishna P. (2024): "TikTok and the Art of Personalization: Investigating Exploration and Exploitation on Social Media Feeds", in: Proceedings of the ACM Web Conference. (DOI)] reuses somebody else's donation corpus of 347 TikTok users, which is the cheapest route of all.

Four things this route costs you, none of them obvious from a crawl background:

  1. A product export is not an Art. 15 response, and the difference is legal, not technical. A dashboard download is a feature the platform may change or withdraw; a right-of-access request is an obligation with a deadline. Say which one you used — several of the ten used the product surface and describe it as the right.
  2. The people are participants, and the data is the most sensitive a study can hold. Every donation paper here recruits, consents and pays; budget for an IRB process shaped like a user study, not like a crawl.
  3. Format drift is your longitudinal confound. The export's schema is the platform's to change, and [17Karnam, Sai Keerthana; Dash, Abhisek; Das, Antariksh; Mousavi, Sepehr; Bechtold, Stefan; Gummadi, Krishna P.; Mukherjee, Animesh; Weber, Ingmar; Zannettou, Savvas (2026): "Setting the Course, but Forgetting to Steer: Analyzing Compliance with GDPR's Right of Access to Data by Instagram, TikTok, and Youtube", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] measures exactly that — intra-user inconsistency between two snapshots of the same account, losing 6% of entries for Instagram and 12% for YouTube.
  4. Donation corpora are reusable, and reusing one is a legitimate design. [39Vombatkere, Karan; Mousavi, Sepehr; Zannettou, Savvas; Roesner, Franziska; Gummadi, Krishna P. (2024): "TikTok and the Art of Personalization: Investigating Exploration and Exploitation on Social Media Feeds", in: Proceedings of the ACM Web Conference. (DOI)] did, and it is the only paper in the population that got a 347-person trace set without recruiting anybody.

What the request-side papers measured

  • Deletion mostly happens, and the gap is in the tail. [5Rupp, Eduard; Syrmoudis, Emmanuel; Grossklags, Jens (2022): "Leave No Data Behind – Empirical Insights into Data Erasure from Online Services", in: Proceedings on Privacy Enhancing Technologies. (DOI)] asked 90 services to erase: the majority complied, but 27% (24 of 90) did not, and the method mattered — 69% compliance for requests made through a service's own deletion button against 82% for a formal Art. 17 email. That is an experimental contrast worth reproducing.
  • Portability is the weakest right. [4Syrmoudis, Emmanuel; Mager, Stefan; Kuebler-Wachendorff, Sophie; Pizzinini, Paul; Grossklags, Jens; Kranz, Johann (2021): "Data Portability between Online Services: An Empirical Analysis on the Effectiveness of GDPR Art. 20", in: Proceedings on Privacy Enhancing Technologies. (DOI)]: 135 of 182 services (74.2%) executed an export within the legal timeframe, but only 52 of 182 met every criterion the authors tested — 130 (71.4%) failed at least one — and only 44 of 190 offered any import at all. Mean fulfilment 9.5 days, median 4.
  • Account deletion is a rights mechanism that platforms now police. [14Yan, Jingwen; Liao, Song; Ma, Jin; Aldeen, Mohammed; Kumar, Salish; Cheng, Long (2025): "No Way to Sign Out? Unpacking Non-Compliance with Google Play's App Account Deletion Requirements", in: Proceedings of the USENIX Security Symposium. (Link)] found 291 of 863 Google Play apps with no account-deletion link at all and only 42 of 494 (8.5%) offering both the in-app and web methods Google Play requires; twelve apps failed to delete after saying they had. [6Santhanam, Preethi; Dang, Hoang; Shan, Zhiyong; Neamtiu, Iulian (2022): "Scraping Sticky Leftovers: App User Information Left on Servers After Account Deletion", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] reached the same place from the security side: 437 of 678 apps with their own sign-up had no deletion function, and only 5% specify a retention period. [40Liu, Yijing; Jia, Yan; Tan, Qingyin; Liu, Zheli; Xing, Luyi (2022): "How Are Your Zombie Accounts? Understanding Users' Practices and Expectations on Mobile App Account Deletion", in: Proceedings of the USENIX Security Symposium. (Link)] adds the human cost — 6.14 clicks on average to delete an account, 4.01 of them just to find the option.
  • Paid removal services are a market with a measurable failure rate. [15He, Jiahui; Snyder, Peter; Haddadi, Hamed; Bustamante, Fabián E.; Tyson, Gareth (2025): "Measuring the Accuracy and Effectiveness of PII Removal Services", in: Proceedings on Privacy Enhancing Technologies. (DOI)]: ten services surveyed, four of them actually subscribed to by 71 participants, 1,759 brokers covered between the ten with an average pairwise Jaccard similarity of 0.21 — they barely overlap — 41.1% of retrieved records marked correct by the person they were about, and 48.2% of records removed on average.
  • People-search sites answer access requests worse than they answer removal requests. [8Take, Kejsi; Young, Jordyn; Bhalerao, Rasika; Gallagher, Kevin; Forte, Andrea; McCoy, Damon; Greenstadt, Rachel (2024): "What to Expect When You’re Accessing: An Exploration of User Privacy Rights in People Search Websites", in: Proceedings on Privacy Enhancing Technologies. (DOI)] attempted both at 20 sites: only one group of connected sites gave the researcher the same report it sells to paying customers, nine sites tried to block EU IP addresses, and removal did propagate — information disappeared from at least five further sites — with no reappearance after two months.
  • The delisting literature is a different shape, because the requests are other people's. [41Bertram, Theo; Bursztein, Elie; Caro, Stephanie; Chao, Hubert; Feman, Rutledge Chin; Fleischer, Peter; Gustafsson, Albin; Hemerly, Jess; Hibbert, Chris; Invernizzi, Luca; Donnelly, Lanah Kammourieh; Ketover, Jason; Laefer, Jay; Nicholas, Paul; Niu, Yuan; Obhi, Harjinder; Price, David; Strait, Andrew; Thomas, Kurt; Verney, Al (2019): "Five Years of the Right to be Forgotten", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)] analyses 3,231,694 URLs requested by 502,648 requesters from Google's own records: 44.5% were delisted, the top thousand requesters generated 16.3% of requests, and median processing time fell from 85 days to 6 after January 2017. [42Xue, Minhui; Magno, Gabriel; Cunha, Evandro; Almeida, Virgilio; Ross, Keith W. (2016): "The Right to be Forgotten in the Media: A Data-Driven Study", in: Proceedings on Privacy Enhancing Technologies. (DOI)] works from the outside, recovering 80 requesters behind 103 of 283 delisted links and finding 87.5% of them male. Neither generalises to access or deletion requests, and both are the best available evidence on who actually exercises a right.
  • LLM agents are the 2026 development. [43Sun, Chen; Vekaria, Yash; Nithyanand, Rishab (2026): "On the Suitability of LLM-Driven Agents for Dark Pattern Audits", Proceedings on Privacy Enhancing Technologies 2026(4):927-946. (DOI)] deploys an agent end to end across 456 registered data brokers' CCPA request portals, completing 87% and 79% of workflows in two phases, and estimates dark-pattern deployment at 15.2%–48.6% across eight categories. The object of measurement is the agent, not the portals — the paper is about whether agents can classify reliably — but it is the only automated audit of rights-request portals in the corpus, and it is where the field is going.

The regulator runs a bigger study than you can

If your question is “how well do controllers implement the right of access”, the largest measurement in existence is not a paper. The European Data Protection Board's 2024 Coordinated Enforcement Framework action on the right of access, adopted 16 January 2025, ran across 30 supervisory authorities and reports that “A total of 1,185 controllers responded to the questionnaire”.14) The 2025 action, on the right to erasure, was adopted on 10 February 2026 across 32 supervisory authorities, with “a total of 764 controllers” responding.15) That is 40 and 25 times the median paper in this population.

It is a different instrument, and that is the opening. The EDPB actions are questionnaires sent to controllers, backed by supervisory powers: the controller describes its own process. A researcher sends a request and observes what comes back. The two measure different things and have opposite biases — self-report versus behaviour — and none of the 51 papers in this page's population puts them side by side. The EDPB's own reports say the gap is real: authorities were “surprised about the large number of controllers responding having received a very low number of access requests in 2023 – which could suggest that not all access requests are actually recognised as such”. A study that sends requests to the same population the EDPB questioned would be a genuinely new result and is well within a PhD's reach.

The American analogue is arriving on a fixed schedule. California's Delete Request and Opt-out Platform (DROP) lets residents send one deletion request to every registered data broker at once: “As of January 1, 2026, California residents may use DROP”, and “Data brokers are required to begin processing these requests on August 1, 2026”.16) That is the frame [1Kempen, Elina van; Bagayatkar, Isita; Frolikov, Pavel; Georgiou, Chloe; Tsudik, Gene (2026): "Consumer Beware! Exploring Data Brokers' CCPA Compliance", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] assembled by hand a year earlier — a census of every registered broker — now with a statutory deadline and an enforcement clock attached to it. The 1 August 2026 date has now passed; no compliance figure has been published by the agency that this page could find, and nothing in the corpus measures it. It is the most obviously available study on this topic right now.

The EDPB series does not continue into data-subject rights in 2026. The 2026 coordinated action, launched on 19 March 2026 with 25 DPAs, is on transparency and information obligations under Arts. 12, 13 and 14 — the duty to tell people what you are doing, not the right to ask.17) So the 2024 and 2025 figures above are, for now, the whole regulator-scale series on the rights themselves.

Which methods are current

Dating matters more here than on most pages, because the legal substrate moved twice inside the corpus window and the papers did not all move with it.

Method Period in the corpus Verdict on 2026-09-16
Hand-sent access / deletion / portability requests, responses coded by hand 2020 → 2026, all 17 R papers Current, and still the only way to answer the compliance question. Note the start year: no paper in this corpus sent a rights request before 2020, two years after the GDPR applied. The technique has not changed since; what changed is that registries now supply a census frame.
Two-stage design: exercise a right, then come back months later and exercise a second one to check [5Rupp, Eduard; Syrmoudis, Emmanuel; Grossklags, Jens (2022): "Leave No Data Behind – Empirical Insights into Data Erasure from Online Services", in: Proceedings on Privacy Enhancing Technologies. (DOI)] 2022; [8Take, Kejsi; Young, Jordyn; Bhalerao, Rasika; Gallagher, Kevin; Forte, Andrea; McCoy, Damon; Greenstadt, Rachel (2024): "What to Expect When You’re Accessing: An Exploration of User Privacy Rights in People Search Websites", in: Proceedings on Privacy Enhancing Technologies. (DOI)] 2024 Current and under-used. Two papers out of 51.
Instrument first, then request: build a ground-truth log with sock puppets, then ask for the export and diff [17Karnam, Sai Keerthana; Dash, Abhisek; Das, Antariksh; Mousavi, Sepehr; Bechtold, Stefan; Gummadi, Krishna P.; Mukherjee, Animesh; Weber, Ingmar; Zannettou, Savvas (2026): "Setting the Course, but Forgetting to Steer: Analyzing Compliance with GDPR's Right of Access to Data by Instagram, TikTok, and Youtube", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] 2026 The current frontier, and the only design that separates non-collection from non-disclosure.
Crawling for a “Do Not Sell” link [25Van Nortwick, Maggie; Wilson, Christo (2022): "Setting the Bar Low: Are Websites Complying With the Minimum Requirements of the CCPA?", in: Proceedings on Privacy Enhancing Technologies. (DOI)] 2022 → [24Charatan, Jan; Birrell, Eleanor (2024): "Two Steps Forward and One Step Back: The Right to Opt-out of Sale under CPRA", in: Proceedings on Privacy Enhancing Technologies. (DOI)] 2024 Current but no longer sufficient on its own. Since the CPRA and Colorado made the signal mandatory, a site can be compliant with no link at all — [24Charatan, Jan; Birrell, Eleanor (2024): "Two Steps Forward and One Step Back: The Right to Opt-out of Sale under CPRA", in: Proceedings on Privacy Enhancing Technologies. (DOI)] found 340 sites where GPC was the only opt-out mechanism. Counting links alone now undercounts compliance.
Measuring the US Privacy String [20Zimmeck, Sebastian; Wang, Oliver; Alicki, Kuba; Wang, Jocelyn; Eng, Sophie (2023): "Usability and Enforceability of Global Privacy Control", Proceedings on Privacy Enhancing Technologies 2023(2). (DOI)] 2023, [21Aziz, Muhammad Abu Bakar; Wilson, Christo (2024): "Johnny Still Can't Opt-out: Assessing the IAB CCPA Compliance Framework", in: Proceedings on Privacy Enhancing Technologies. (DOI)] 2024, [22Hausladen, Katherine; Wang, Oliver; Eng, Sophie; Wang, Jocelyn; Wijaya, Francisca; May, Matthew; Zimmeck, Sebastian (2025): "Websites' Global Privacy Control Compliance at Scale and over Time", in: Proceedings of the USENIX Security Symposium. (Link)] 2025 Superseded. The string was deprecated on 31 January 2024. Read these papers for the method, retarget the parser at GPP.
Measuring DNT compliance none in this population Historical. The dnt probe was context-tier and never drove a candidate, so no DNT-compliance paper was audited into the 51 — that is a statement about this page's population, not about the corpus. The standard is retired; the one live legal hook is the 2023 Berlin judgment in the signal table above, and it is about a statement rather than a compliance rate.
Sending GPC and measuring what changes downstream [20Zimmeck, Sebastian; Wang, Oliver; Alicki, Kuba; Wang, Jocelyn; Eng, Sophie (2023): "Usability and Enforceability of Global Privacy Control", Proceedings on Privacy Enhancing Technologies 2023(2). (DOI)] 2023 → [29Zimmeck, Sebastian; Aggarwal, Nishant; Liu, Zachary; Altman, Sage; Kollnig, Konrad (2026): "Exercising the CCPA Opt-out Right on Android: Legally Mandated but Practically Challenging", in: Proceedings on Privacy Enhancing Technologies. (DOI)] 2026 Current, and the most active line in the corpus. Seven of the twelve S papers are 2024 or later.
LLM agents driving request portals [43Sun, Chen; Vekaria, Yash; Nithyanand, Rishab (2026): "On the Suitability of LLM-Driven Agents for Dark Pattern Audits", Proceedings on Privacy Enhancing Technologies 2026(4):927-946. (DOI)] 2026 Emerging, one paper. Treat as a research question, not a tool: the paper's own finding is about where the agent fails.

Two honest caveats on that table. First, it rests on 43 papers from 2021–2026 and only 8 from 2010–2020, so “current practice” here is nearly all of the practice there is. Second, 2025 and 2026 are provisional venue-years in this corpus — CCS 2026 and IMC 2026 have not been held, and IEEE S&P 2026 and TheWebConf 2026 are under-represented by construction — so the 12 papers from 2025 and 6 from 2026 are a floor, not a count. Do not read the per-year row for 2026 as a decline.

How this page's population was derived

There is no extraction-schema enum for data-subject rights, so the population is a full-text sweep followed by a hand audit of every candidate.

Inclusion rule. A paper is in the population if it reports an empirical result produced by, or about, a data-subject-rights request or a machine-readable opt-out signal, in one of five ways: (R) the authors or their participants sent access, deletion, portability or opt-out requests to real controllers and coded the responses; (S) the paper measured the deployment or honouring of an opt-out signal or setting across a population; (M) the paper measured the availability, correctness or usability of a rights-exercise mechanism across a population; (D) the paper's research dataset was obtained through a right of access or an equivalent self-service export; (O) the paper is an observational study of requests other people sent. Naming a right in background is out. Analysing what a privacy policy says about rights is out — that is Policies. Machine unlearning, content takedown, consent banners, and studies of attitudes with no request sent and no mechanism observed are out.

Fifteen full-text probes over the 5,855 of 5,859 papers with full text on disk produce 471 candidates (8.0%). Hand-auditing all 471 gives 5110.8% precision. The probes, the tight-and-loose pairs, the verdict for every candidate and the reason for each rejection are on data_subject_rights.

Two things about the derivation are worth carrying onto this page, because they are findings rather than plumbing.

  • The title probe that queued this page has 100% precision and 17.6% recall. The roadmap scoped this page from a title-and-summary probe that matched 9 papers. Every one of the 9 is in the population — but the population is 51, so the probe misses 42, including every paper in the corpus that obtained its research data through the right of access, both people-search removal studies, and the largest opt-out-signal paper before 2024. On this topic the rights work is usually one section of a paper whose title says nothing about rights.
  • Nine tenths of the candidates are noise, and it is structured noise. Of the 420 rejections, 129 are homonyms and 53 are a single recurring class: an internet-scanning paper's ethics section offering an “opt-out request” for its own probes. If you write a probe on this topic, that phrase will drown you.

What to report

  • The frame, and how you built it. “The 543 brokers on California's registry as of date” is a population. “50 popular websites” is not, unless you say how popularity was measured and when.
  • The number of controllers asked, separately from every other n in the paper. Participant counts, site counts and export-file counts are different denominators and this literature mixes them constantly.
  • Who sent the requests, under whose identity, and what verification each controller demanded. This is the ethics disclosure and the reproducibility note at the same time.
  • The deadline you used and where it comes from — GDPR Art. 12(3)'s one month plus two, the CCPA's 45 plus 45 — and the response rate both raw and on-time.
  • The follow-up rule, stated in advance: how many chases, at what interval, and what counts as a final non-response.
  • Non-responses as a reported category, broken down. Silence, refusal, broken form and unanswered verification are four different outcomes.
  • The codebook and the agreement statistic for whatever you did to the responses. Two in three papers here skip the second — see Interrater agreement.
  • For a signal measurement: the control arm, the exact bytes you sent, and where you sent them. Sec-GPC: 1 on every request, navigator.globalPrivacyControl, or both; and what browser build, since Chrome does not implement it.
  • The vantage point, because opt-out links and age-of-consent rules are geofenced and the applicable law follows the IP address; see Crawling location.
  • The date, in the sentence, not only in the artefact. This substrate has a deprecation every eighteen months.

The population, in full

All 51 papers, with the category of instrument each uses: R sent requests, S measured an opt-out signal or setting, M measured a rights mechanism across a population, D obtained its research data through an access or export surface, O observed requests other people sent.

Year Venue Paper
2014 CCS S [27Acar, Gunes; Eubank, Christian; Englehardt, Steven; Juarez, Marc; Narayanan, Arvind; Díaz, Claudia (2014): "The Web Never Forgets: Persistent Tracking Mechanisms in the Wild", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)] The Web Never Forgets: Persistent Tracking Mechanisms in the Wild
2015 PoPETs S [44Datta, Amit; Tschantz, Michael Carl; Datta, Anupam (2015): "Automated Experiments on Ad Privacy Settings", in: Proceedings on Privacy Enhancing Technologies. (DOI)] Automated Experiments on Ad Privacy Settings
2016 PoPETs O [42Xue, Minhui; Magno, Gabriel; Cunha, Evandro; Almeida, Virgilio; Ross, Keith W. (2016): "The Right to be Forgotten in the Media: A Data-Driven Study", in: Proceedings on Privacy Enhancing Technologies. (DOI)] The Right to be Forgotten in the Media: A Data-Driven Study
2019 CCS O [41Bertram, Theo; Bursztein, Elie; Caro, Stephanie; Chao, Hubert; Feman, Rutledge Chin; Fleischer, Peter; Gustafsson, Albin; Hemerly, Jess; Hibbert, Chris; Invernizzi, Luca; Donnelly, Lanah Kammourieh; Ketover, Jason; Laefer, Jay; Nicholas, Paul; Niu, Yuan; Obhi, Harjinder; Price, David; Strait, Andrew; Thomas, Kurt; Verney, Al (2019): "Five Years of the Right to be Forgotten", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)] Five Years of the Right to be Forgotten
2019 NDSS D [31Bashir, Muhammad Ahmad; Farooq, Umar; Shahid, Maryam; Zaffar, Muhammad Fareed; Wilson, Christo (2019): "Quantity vs. Quality: Evaluating User Interest Profiles Using Ad Preference Managers", in: Proceedings of the Network and Distributed System Security Symposium. (Link)] Quantity vs. Quality: Evaluating User Interest Profiles Using Ad Preference Managers
2019 TheWebConf D [36Zaman, Anis; Acharyya, Rupam; Kautz, Henry A.; Silenzio, Vincent (2019): "Detecting Low Self-Esteem in Youths from Web Search Data", in: Proceedings of the ACM Web Conference. (DOI)] Detecting Low Self-Esteem in Youths from Web Search Data
2020 PoPETs R [3Farooqi, Shehroze; Musa, Maaz; Shafiq, Zubair; Zaffar, Fareed (2020): "CanaryTrap: Detecting Data Misuse by Third-Party Apps on Online Social Networks", in: Proceedings on Privacy Enhancing Technologies. (DOI)] CanaryTrap: Detecting Data Misuse by Third-Party Apps on Online Social Networks
2020 USENIX Sec D [34Wei, Miranda; Stamos, Madison; Veys, Sophie; Reitinger, Nathan; Goodman, Justin; Herman, Margot; Filipczuk, Dorota; Weinshel, Ben; Mazurek, Michelle L.; Ur, Blase (2020): "What Twitter Knows: Characterizing Ad Targeting Practices, User Perceptions, and Ad Explanations Through Users' Own Twitter Data", in: Proceedings of the USENIX Security Symposium. (Link)] What Twitter Knows: Characterizing Ad Targeting Practices, User Perceptions, and Ad Explanations Through Users' Own Twitter Data
2021 PoPETs R [4Syrmoudis, Emmanuel; Mager, Stefan; Kuebler-Wachendorff, Sophie; Pizzinini, Paul; Grossklags, Jens; Kranz, Johann (2021): "Data Portability between Online Services: An Empirical Analysis on the Effectiveness of GDPR Art. 20", in: Proceedings on Privacy Enhancing Technologies. (DOI)] Data Portability between Online Services: An Empirical Analysis on the Effectiveness of GDPR Art. 20
2021 PoPETs S [45Hils, Maximilian; Woods, Daniel W.; Böhme, Rainer (2021): "Privacy Preference Signals: Past, Present and Future", in: Proceedings on Privacy Enhancing Technologies. (DOI)] Privacy Preference Signals: Past, Present and Future
2021 USENIX Sec D [38Onaolapo, Jeremiah; Leontiadis, Nektarios; Magka, Despoina; Stringhini, Gianluca (2021): "SocialHEISTing: Understanding Stolen Facebook Accounts", in: Proceedings of the USENIX Security Symposium. (Link)] SocialHEISTing: Understanding Stolen Facebook Accounts
2022 CCS S [26Bui, Duc; Tang, Brian; Shin, Kang G. (2022): "Do Opt-Outs Really Opt Me Out?", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)] Do Opt-Outs Really Opt Me Out?
2022 IEEE S&P R [6Santhanam, Preethi; Dang, Hoang; Shan, Zhiyong; Neamtiu, Iulian (2022): "Scraping Sticky Leftovers: App User Information Left on Servers After Account Deletion", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] Scraping Sticky Leftovers: App User Information Left on Servers After Account Deletion
2022 PoPETs M [46Take, Kejsi; Gallagher, Kevin; Forte, Andrea; McCoy, Damon; Greenstadt, Rachel (2022): "“It Feels Like Whack-a-mole”: User Experiences of Data Removal from People Search Websites", in: Proceedings on Privacy Enhancing Technologies. (DOI)] “It Feels Like Whack-a-mole”: User Experiences of Data Removal from People Search Websites
2022 PoPETs R [5Rupp, Eduard; Syrmoudis, Emmanuel; Grossklags, Jens (2022): "Leave No Data Behind – Empirical Insights into Data Erasure from Online Services", in: Proceedings on Privacy Enhancing Technologies. (DOI)] Leave No Data Behind – Empirical Insights into Data Erasure from Online Services
2022 PoPETs R [2Martino, Mariano Di; Meers, Isaac; Quax, Peter; Andries, Ken; Lamotte, Wim (2022): "Revisiting Identification Issues in GDPR ‘Right Of Access’ Policies: A Technical and Longitudinal Analysis", in: Proceedings on Privacy Enhancing Technologies. (DOI)] Revisiting Identification Issues in GDPR ‘Right Of Access’ Policies: A Technical and Longitudinal Analysis
2022 PoPETs M [25Van Nortwick, Maggie; Wilson, Christo (2022): "Setting the Bar Low: Are Websites Complying With the Minimum Requirements of the CCPA?", in: Proceedings on Privacy Enhancing Technologies. (DOI)] Setting the Bar Low: Are Websites Complying With the Minimum Requirements of the CCPA?
2022 USENIX Sec M [40Liu, Yijing; Jia, Yan; Tan, Qingyin; Liu, Zheli; Xing, Luyi (2022): "How Are Your Zombie Accounts? Understanding Users' Practices and Expectations on Mobile App Account Deletion", in: Proceedings of the USENIX Security Symposium. (Link)] How Are Your Zombie Accounts? Understanding Users' Practices and Expectations on Mobile App Account Deletion
2022 USENIX Sec D [47Sharma, Vandit; Mondal, Mainack (2022): "Understanding and Improving Usability of Data Dashboards for Simplified Privacy Control of Voice Assistant Data", in: Proceedings of the USENIX Security Symposium. (Link)] Understanding and Improving Usability of Data Dashboards for Simplified Privacy Control of Voice Assistant Data
2023 IEEE S&P D [33Gkiouzepi, Eleni; Andreou, Athanasios; Goga, Oana; Loiseau, Patrick (2023): "Collaborative Ad Transparency: Promises and Limitations", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] Collaborative Ad Transparency: Promises and Limitations
2023 NDSS M [18Shezan, Faysal Hossain; Su, Zihao; Kang, Mingqing; Phair, Nicholas; Thomas, Patrick William; van Dam, Michelangelo; Cao, Yinzhi; Tian, Yuan (2023): "CHKPLUG: Checking GDPR Compliance of WordPress Plugins via Cross-language Code Property Graph", in: Proceedings of the Network and Distributed System Security Symposium. (Link)] CHKPLUG: Checking GDPR Compliance of WordPress Plugins via Cross-language Code Property Graph
2023 PoPETs M [48Utz, Christine; Michels, Matthias; Degeling, Martin; Marnau, Ninja; Stock, Ben (2023): "Comparing Large-Scale Privacy and Security Notifications", in: Proceedings on Privacy Enhancing Technologies. (DOI)] Comparing Large-Scale Privacy and Security Notifications
2023 PoPETs R [7Samarin, Nikita; Kothari, Shayna; Siyed, Zaina; Bjorkman, Oscar; Yuan, Reena; Wijesekera, Primal; Alomar, Noura; Fischer, Jordan; Hoofnagle, Chris; Egelman, Serge (2023): "Lessons in VCR Repair: Compliance of Android App Developers with the California Consumer Privacy Act (CCPA)", in: Proceedings on Privacy Enhancing Technologies. (DOI)] Lessons in VCR Repair: Compliance of Android App Developers with the California Consumer Privacy Act (CCPA)
2023 PoPETs S [20Zimmeck, Sebastian; Wang, Oliver; Alicki, Kuba; Wang, Jocelyn; Eng, Sophie (2023): "Usability and Enforceability of Global Privacy Control", Proceedings on Privacy Enhancing Technologies 2023(2). (DOI)] Usability and Enforceability of Global Privacy Control
2024 IEEE S&P M [49Du, Xiaolin; Yang, Zhemin; Lin, Jiapeng; Cao, Yinzhi; Yang, Min (2024): "Withdrawing is believing? Detecting Inconsistencies between Withdrawal Choices and Third-party Data Collections in Mobile Apps", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] Withdrawing is believing? Detecting Inconsistencies between Withdrawal Choices and Third-party Data Collections in Mobile Apps
2024 PoPETs M [50Zimmeck, Sebastian; Kuller, Eliza; Ma, Chunyue; Tassone, Bella; Champeau, Joe (2024): "Generalizable Active Privacy Choice: Designing a Graphical User Interface for Global Privacy Control", in: Proceedings on Privacy Enhancing Technologies. (DOI)] Generalizable Active Privacy Choice: Designing a Graphical User Interface for Global Privacy Control
2024 PoPETs S [21Aziz, Muhammad Abu Bakar; Wilson, Christo (2024): "Johnny Still Can't Opt-out: Assessing the IAB CCPA Compliance Framework", in: Proceedings on Privacy Enhancing Technologies. (DOI)] Johnny Still Can't Opt-out: Assessing the IAB CCPA Compliance Framework
2024 PoPETs S [28Liu, Zengrui; Iqbal, Umar; Saxena, Nitesh (2024): "Opted Out, Yet Tracked: Are Regulations Enough to Protect Your Privacy?", in: Proceedings on Privacy Enhancing Technologies. (DOI)] Opted Out, Yet Tracked: Are Regulations Enough to Protect Your Privacy?
2024 PoPETs D [32Caravaca, Francisco; González-Cabañas, José; Cuevas, Ángel; Cuevas, Rubén (2024): "Overprofiling Analysis on Major Internet Players", in: Proceedings on Privacy Enhancing Technologies. (DOI)] Overprofiling Analysis on Major Internet Players
2024 PoPETs S [24Charatan, Jan; Birrell, Eleanor (2024): "Two Steps Forward and One Step Back: The Right to Opt-out of Sale under CPRA", in: Proceedings on Privacy Enhancing Technologies. (DOI)] Two Steps Forward and One Step Back: The Right to Opt-out of Sale under CPRA
2024 PoPETs R [8Take, Kejsi; Young, Jordyn; Bhalerao, Rasika; Gallagher, Kevin; Forte, Andrea; McCoy, Damon; Greenstadt, Rachel (2024): "What to Expect When You’re Accessing: An Exploration of User Privacy Rights in People Search Websites", in: Proceedings on Privacy Enhancing Technologies. (DOI)] What to Expect When You’re Accessing: An Exploration of User Privacy Rights in People Search Websites
2024 USENIX Sec R [9Borem, Arthur; Pan, Elleen; Obielodan, Olufunmilola; Roubinowitz, Aurelie; Dovichi, Luca; Mazurek, Michelle L.; Ur, Blase (2024): "Data Subjects' Reactions to Exercising Their Right of Access", in: Proceedings of the USENIX Security Symposium. (Link)] Data Subjects' Reactions to Exercising Their Right of Access
2024 TheWebConf D [39Vombatkere, Karan; Mousavi, Sepehr; Zannettou, Savvas; Roesner, Franziska; Gummadi, Krishna P. (2024): "TikTok and the Art of Personalization: Investigating Exploration and Exploitation on Social Media Feeds", in: Proceedings of the ACM Web Conference. (DOI)] TikTok and the Art of Personalization: Investigating Exploration and Exploitation on Social Media Feeds
2025 CCS R [10Nonnenkamp, Julia; Gupta, Naman; Gupta, Abhimanyu Dev; Chatterjee, Rahul (2025): "Hidden in Plain Bytes: Investigating Interpersonal Account Compromise with Data Exports", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)] Hidden in Plain Bytes: Investigating Interpersonal Account Compromise with Data Exports
2025 CCS M [51Xian, Lu; Tran, Van Hong; Lee, Lauren; Kumar, Meera; Zhang, Yichen; Schaub, Florian (2025): "Layered, Overlapping, and Inconsistent: A Large-Scale Analysis of the Multiple Privacy Policies and Controls of U.S. Banks", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)] Layered, Overlapping, and Inconsistent: A Large-Scale Analysis of the Multiple Privacy Policies and Controls of U.S. Banks
2025 IMC R [12Le, Tu; Baldesi, Luca; Markopoulou, Athina; Butts, Carter T.; Shafiq, Zubair (2025): "From Voice to Ads: Auditing Commercial Smart Speakers for Targeted Advertising based on Voice Characteristics", in: Proceedings of the ACM Internet Measurement Conference. (DOI)] From Voice to Ads: Auditing Commercial Smart Speakers for Targeted Advertising based on Voice Characteristics
2025 PoPETs R [11Khezresmaeilzadeh, Tina; Zhu, Elaine; Grieco, Kiersten; Dubois, Daniel; Psounis, Konstantinos; Choffnes, David (2025): "Echoes of Privacy: Uncovering the Profiling Practices of Voice Assistants", Proceedings on Privacy Enhancing Technologies 2025(2). (DOI)] Echoes of Privacy: Uncovering the Profiling Practices of Voice Assistants
2025 PoPETs M [52Cheng, Cheng; Ramokapane, Kopo M. (2025): ""Erasing the Echo": The Usability of Data Deletion in Smart Personal Assistants", in: Proceedings on Privacy Enhancing Technologies. (DOI)] ``Erasing the Echo'': The Usability of Data Deletion in Smart Personal Assistants
2025 PoPETs S [23Rasaii, Ali; Dao, Ha; Feldmann, Anja; Javid, Mohammadmahdi; Gasser, Oliver; Gosain, Devashish (2025): "Intractable Cookie Crumbs: Unveiling the Nexus of Stateful Banner Interaction and Tracking Cookies", in: Proceedings on Privacy Enhancing Technologies, pp. 429-445. (DOI)] Intractable Cookie Crumbs: Unveiling the Nexus of Stateful Banner Interaction and Tracking Cookies
2025 PoPETs R [15He, Jiahui; Snyder, Peter; Haddadi, Hamed; Bustamante, Fabián E.; Tyson, Gareth (2025): "Measuring the Accuracy and Effectiveness of PII Removal Services", in: Proceedings on Privacy Enhancing Technologies. (DOI)] Measuring the Accuracy and Effectiveness of PII Removal Services
2025 PoPETs S [30Mai, Cat; Coelho, Bruno; Kieserman, Julia; Matsumoto, Lexie; Spinelli, Kyle; Yang, Eric; Andreou, Athanasios; Greenstadt, Rachel; Lauinger, Tobias; McCoy, Damon (2025): "More and Scammier Ads: The Perils of YouTube's Ad Privacy Settings", in: Proceedings on Privacy Enhancing Technologies. (DOI)] More and Scammier Ads: The Perils of YouTube's Ad Privacy Settings
2025 USENIX Sec R [13Niksirat, Kavous Salehzadeh; Velykoivanenko, Lev; Mätzler, Samuel; Mulders, Stephan; Tamò-Larrieux, Aurelia; Boldi, Marc-Olivier; Humbert, Mathias; Huguenin, Kévin (2025): "Addressing the Address Books' (Interdependent) Privacy Issues", in: Proceedings of the USENIX Security Symposium. (Link)] Addressing the Address Books' (Interdependent) Privacy Issues
2025 USENIX Sec D [37Akgul, Omer; Roberts, Richard; Shroyer, Emma; Levin, Dave; Mazurek, Michelle L. (2025): "As Advertised? Understanding the Impact of Influencer VPN Ads", in: Proceedings of the USENIX Security Symposium. (Link)] As Advertised? Understanding the Impact of Influencer VPN Ads
2025 USENIX Sec R [14Yan, Jingwen; Liao, Song; Ma, Jin; Aldeen, Mohammed; Kumar, Salish; Cheng, Long (2025): "No Way to Sign Out? Unpacking Non-Compliance with Google Play's App Account Deletion Requirements", in: Proceedings of the USENIX Security Symposium. (Link)] No Way to Sign Out? Unpacking Non-Compliance with Google Play's App Account Deletion Requirements
2025 USENIX Sec S [22Hausladen, Katherine; Wang, Oliver; Eng, Sophie; Wang, Jocelyn; Wijaya, Francisca; May, Matthew; Zimmeck, Sebastian (2025): "Websites' Global Privacy Control Compliance at Scale and over Time", in: Proceedings of the USENIX Security Symposium. (Link)] Websites' Global Privacy Control Compliance at Scale and over Time
2026 IEEE S&P R [1Kempen, Elina van; Bagayatkar, Isita; Frolikov, Pavel; Georgiou, Chloe; Tsudik, Gene (2026): "Consumer Beware! Exploring Data Brokers' CCPA Compliance", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] Consumer Beware! Exploring Data Brokers' CCPA Compliance
2026 IEEE S&P R [17Karnam, Sai Keerthana; Dash, Abhisek; Das, Antariksh; Mousavi, Sepehr; Bechtold, Stefan; Gummadi, Krishna P.; Mukherjee, Animesh; Weber, Ingmar; Zannettou, Savvas (2026): "Setting the Course, but Forgetting to Steer: Analyzing Compliance with GDPR's Right of Access to Data by Instagram, TikTok, and Youtube", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] Setting the Course, but Forgetting to Steer: Analyzing Compliance with GDPR's Right of Access to Data by Instagram, TikTok, and Youtube
2026 PoPETs S [29Zimmeck, Sebastian; Aggarwal, Nishant; Liu, Zachary; Altman, Sage; Kollnig, Konrad (2026): "Exercising the CCPA Opt-out Right on Android: Legally Mandated but Practically Challenging", in: Proceedings on Privacy Enhancing Technologies. (DOI)] Exercising the CCPA Opt-out Right on Android: Legally Mandated but Practically Challenging
2026 PoPETs M [43Sun, Chen; Vekaria, Yash; Nithyanand, Rishab (2026): "On the Suitability of LLM-Driven Agents for Dark Pattern Audits", Proceedings on Privacy Enhancing Technologies 2026(4):927-946. (DOI)] On the Suitability of LLM-Driven Agents for Dark Pattern Audits
2026 TheWebConf D [35Karnam, Sai Keerthana; Dash, Abhisek; Gummadi, Krishna P.; Mukherjee, Animesh; Weber, Ingmar; Zannettou, Savvas (2026): "Bowling with ChatGPT: On the Evolving User Interactions with Conversational AI Systems", in: Proceedings of the ACM Web Conference. (DOI)] Bowling with ChatGPT: On the Evolving User Interactions with Conversational AI Systems
2026 TheWebConf R [16Mousavi, Sepehr; Dash, Abhisek; Zannettou, Savvas; Gummadi, Krishna P. (2026): "Does Ad-Free Mean Less Data Collection? An Empirical Study of Platform Data Practices and User Expectations", in: Proceedings of the ACM Web Conference. (DOI)] Does Ad-Free Mean Less Data Collection? An Empirical Study of Platform Data Practices and User Expectations

By instrument: R 17, S 12, M 10, D 10, O 2. By venue: PoPETs 25 (4.9% of its own papers), USENIX Security 9 (0.6%), CCS 5, IEEE S&P 5, TheWebConf 4, NDSS 2, IMC 1 (0.2%). Thirty-one of the 51 assess a named law — 60.8%, against a corpus base rate of 6.9% — and the laws, counted by paper after folding, are GDPR 19, CCPA 15, CPRA 5, ePrivacy Directive 2.

Methodology and limitations of these figures

Every corpus figure on this page comes from scripts/dsr_report.mjs, which prints each number with its own denominator and throws rather than guessing: it refuses to run if a request-sending paper is missing from the hand-keyed controllers asked table, if the instrument categories do not sum to the population, or if a verdict names a paper that is not in the corpus. The candidate sweep is scripts/dsr_probe.mjs, which pairs every tight probe with a loose superset and fails if the “narrowing” pattern is not in fact a narrowing. The hand audit is scripts/dsr_verdicts_build.py, which asserts that every one of the 471 candidates carries exactly one verdict and refuses to default a rejection reason. The script, its unedited output, all 471 verdicts, the probe history including two probes added mid-run after the first audit missed a paper, the quote checks and the external sources that were rejected are on data_subject_rights. Corpus-level caveats — venue scope, the selection funnel, the provisional 2025–2026 years, extraction stability — are on Corpus.

Six limitations belong on the page itself:

  1. Fifty-one papers is not a base rate. Every figure in What has actually been measured is one study's result about one population. None has been replicated, several have n below 50, and the two that look like a time series (12% GPC compliance in 2022, 44% in 2023) are different site sets measured different ways. Treat them as existence proofs and as related work.
  2. The population is a hand audit, and hand audits have a false-negative rate nobody can measure. Two probes — for industry opt-out tools and for self-service export surfaces — were added after the first audit was complete, because the first candidate set could not see Do Opt-Outs Really Opt Me Out?. They added 182 candidates and 10 population papers. A third blind spot of the same kind is likely and is not measurable from inside.
  3. The category boundary between S, M and D is a judgement, not a fact. A paper that pulls interest profiles out of an ad preference manager is coded D; a paper that checks whether disabling a setting changes the ads is coded S. Several papers could defensibly be either. The per-category counts should be read as a shape, not as measurements.
  4. The corpus is seven venues. SOUPS, CHI, ARES, PETS' own workshops and the law reviews are not in it, and a large part of the DSAR literature lives there — [1Kempen, Elina van; Bagayatkar, Isita; Frolikov, Pavel; Georgiou, Chloe; Tsudik, Gene (2026): "Consumer Beware! Exploring Data Brokers' CCPA Compliance", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)]'s own comparison table cites four earlier response-rate studies, none of which is in this corpus. An absence measured here is an absence from seven security and measurement venues, not an absence of work.
  5. The external legal and standards material is a currency check, not a legal analysis. Each external claim names one primary source read on 2026-09-16. Jurisdictions not named here — Virginia, Connecticut, Texas, Oregon, Montana, the EU member states' national variations — have their own rules and are out of scope.
  6. 2026 is provisional. Six 2026 papers are in the population and the venue-years they come from are incomplete by construction. Do not read the 2026 row as the end of a trend.

Read first

  • [1Kempen, Elina van; Bagayatkar, Isita; Frolikov, Pavel; Georgiou, Chloe; Tsudik, Gene (2026): "Consumer Beware! Exploring Data Brokers' CCPA Compliance", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] — read this before designing anything. A census of a statutory registry, 454 requests sent by hand, the response rate reported raw and on-time, the effort cost stated in hours, and a comparison table of every earlier response-rate study. It is also the clearest statement of the ethics problem: exercising the right made the researcher disclose more than the brokers held.
  • [17Karnam, Sai Keerthana; Dash, Abhisek; Das, Antariksh; Mousavi, Sepehr; Bechtold, Stefan; Gummadi, Krishna P.; Mukherjee, Animesh; Weber, Ingmar; Zannettou, Savvas (2026): "Setting the Course, but Forgetting to Steer: Analyzing Compliance with GDPR's Right of Access to Data by Instagram, TikTok, and Youtube", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] — the strongest design in the corpus. Instrument the behaviour with sock puppets, then request the export and diff it. Read it for the completeness-and-correctness metrics.
  • [5Rupp, Eduard; Syrmoudis, Emmanuel; Grossklags, Jens (2022): "Leave No Data Behind – Empirical Insights into Data Erasure from Online Services", in: Proceedings on Privacy Enhancing Technologies. (DOI)] — the two-stage erasure-then-access design, and the button-versus-formal-request contrast.
  • [9Borem, Arthur; Pan, Elleen; Obielodan, Olufunmilola; Roubinowitz, Aurelie; Dovichi, Luca; Mazurek, Michelle L.; Ur, Blase (2024): "Data Subjects' Reactions to Exercising Their Right of Access", in: Proceedings of the USENIX Security Symposium. (Link)] — what actually arrives, and why coding it is the hard part. Read §5 for the export-complexity measures.
  • [22Hausladen, Katherine; Wang, Oliver; Eng, Sophie; Wang, Jocelyn; Wijaya, Francisca; May, Matthew; Zimmeck, Sebastian (2025): "Websites' Global Privacy Control Compliance at Scale and over Time", in: Proceedings of the USENIX Security Symposium. (Link)] — the current reference for detecting GPC compliance at scale, and for what “compliance” can even mean when the signal is honoured by omission.
  • [29Zimmeck, Sebastian; Aggarwal, Nishant; Liu, Zachary; Altman, Sage; Kollnig, Konrad (2026): "Exercising the CCPA Opt-out Right on Android: Legally Mandated but Practically Challenging", in: Proceedings on Privacy Enhancing Technologies. (DOI)] — the newest opt-out-signal measurement and the one that moves the question to mobile, where the mechanism largely does not exist.
  • [2Martino, Mariano Di; Meers, Isaac; Quax, Peter; Andries, Ken; Lamotte, Wim (2022): "Revisiting Identification Issues in GDPR ‘Right Of Access’ Policies: A Technical and Longitudinal Analysis", in: Proceedings on Privacy Enhancing Technologies. (DOI)] — read it for the security of the request channel, which every other paper here treats as a given.
  • [45Hils, Maximilian; Woods, Daniel W.; Böhme, Rainer (2021): "Privacy Preference Signals: Past, Present and Future", in: Proceedings on Privacy Enhancing Technologies. (DOI)] — the history of DNT, P3P, the TCF and GPC in one place. Read it to understand why the current signal is shaped the way it is, and then check every status claim in it against the table above, because it is five years old.
[1]
Kempen, Elina van; Bagayatkar, Isita; Frolikov, Pavel; Georgiou, Chloe; Tsudik, Gene (2026): "Consumer Beware! Exploring Data Brokers' CCPA Compliance", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)
[2]
Martino, Mariano Di; Meers, Isaac; Quax, Peter; Andries, Ken; Lamotte, Wim (2022): "Revisiting Identification Issues in GDPR ‘Right Of Access’ Policies: A Technical and Longitudinal Analysis", in: Proceedings on Privacy Enhancing Technologies. (DOI)
[3]
Farooqi, Shehroze; Musa, Maaz; Shafiq, Zubair; Zaffar, Fareed (2020): "CanaryTrap: Detecting Data Misuse by Third-Party Apps on Online Social Networks", in: Proceedings on Privacy Enhancing Technologies. (DOI)
[4]
Syrmoudis, Emmanuel; Mager, Stefan; Kuebler-Wachendorff, Sophie; Pizzinini, Paul; Grossklags, Jens; Kranz, Johann (2021): "Data Portability between Online Services: An Empirical Analysis on the Effectiveness of GDPR Art. 20", in: Proceedings on Privacy Enhancing Technologies. (DOI)
[5]
Rupp, Eduard; Syrmoudis, Emmanuel; Grossklags, Jens (2022): "Leave No Data Behind – Empirical Insights into Data Erasure from Online Services", in: Proceedings on Privacy Enhancing Technologies. (DOI)
[6]
Santhanam, Preethi; Dang, Hoang; Shan, Zhiyong; Neamtiu, Iulian (2022): "Scraping Sticky Leftovers: App User Information Left on Servers After Account Deletion", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)
[7]
Samarin, Nikita; Kothari, Shayna; Siyed, Zaina; Bjorkman, Oscar; Yuan, Reena; Wijesekera, Primal; Alomar, Noura; Fischer, Jordan; Hoofnagle, Chris; Egelman, Serge (2023): "Lessons in VCR Repair: Compliance of Android App Developers with the California Consumer Privacy Act (CCPA)", in: Proceedings on Privacy Enhancing Technologies. (DOI)
[8]
Take, Kejsi; Young, Jordyn; Bhalerao, Rasika; Gallagher, Kevin; Forte, Andrea; McCoy, Damon; Greenstadt, Rachel (2024): "What to Expect When You’re Accessing: An Exploration of User Privacy Rights in People Search Websites", in: Proceedings on Privacy Enhancing Technologies. (DOI)
[9]
Borem, Arthur; Pan, Elleen; Obielodan, Olufunmilola; Roubinowitz, Aurelie; Dovichi, Luca; Mazurek, Michelle L.; Ur, Blase (2024): "Data Subjects' Reactions to Exercising Their Right of Access", in: Proceedings of the USENIX Security Symposium. (Link)
[10]
Nonnenkamp, Julia; Gupta, Naman; Gupta, Abhimanyu Dev; Chatterjee, Rahul (2025): "Hidden in Plain Bytes: Investigating Interpersonal Account Compromise with Data Exports", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)
[11]
Khezresmaeilzadeh, Tina; Zhu, Elaine; Grieco, Kiersten; Dubois, Daniel; Psounis, Konstantinos; Choffnes, David (2025): "Echoes of Privacy: Uncovering the Profiling Practices of Voice Assistants", Proceedings on Privacy Enhancing Technologies 2025(2). (DOI)
[12]
Le, Tu; Baldesi, Luca; Markopoulou, Athina; Butts, Carter T.; Shafiq, Zubair (2025): "From Voice to Ads: Auditing Commercial Smart Speakers for Targeted Advertising based on Voice Characteristics", in: Proceedings of the ACM Internet Measurement Conference. (DOI)
[13]
Niksirat, Kavous Salehzadeh; Velykoivanenko, Lev; Mätzler, Samuel; Mulders, Stephan; Tamò-Larrieux, Aurelia; Boldi, Marc-Olivier; Humbert, Mathias; Huguenin, Kévin (2025): "Addressing the Address Books' (Interdependent) Privacy Issues", in: Proceedings of the USENIX Security Symposium. (Link)
[14]
Yan, Jingwen; Liao, Song; Ma, Jin; Aldeen, Mohammed; Kumar, Salish; Cheng, Long (2025): "No Way to Sign Out? Unpacking Non-Compliance with Google Play's App Account Deletion Requirements", in: Proceedings of the USENIX Security Symposium. (Link)
[15]
He, Jiahui; Snyder, Peter; Haddadi, Hamed; Bustamante, Fabián E.; Tyson, Gareth (2025): "Measuring the Accuracy and Effectiveness of PII Removal Services", in: Proceedings on Privacy Enhancing Technologies. (DOI)
[16]
Mousavi, Sepehr; Dash, Abhisek; Zannettou, Savvas; Gummadi, Krishna P. (2026): "Does Ad-Free Mean Less Data Collection? An Empirical Study of Platform Data Practices and User Expectations", in: Proceedings of the ACM Web Conference. (DOI)
[17]
Karnam, Sai Keerthana; Dash, Abhisek; Das, Antariksh; Mousavi, Sepehr; Bechtold, Stefan; Gummadi, Krishna P.; Mukherjee, Animesh; Weber, Ingmar; Zannettou, Savvas (2026): "Setting the Course, but Forgetting to Steer: Analyzing Compliance with GDPR's Right of Access to Data by Instagram, TikTok, and Youtube", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)
[18]
Shezan, Faysal Hossain; Su, Zihao; Kang, Mingqing; Phair, Nicholas; Thomas, Patrick William; van Dam, Michelangelo; Cao, Yinzhi; Tian, Yuan (2023): "CHKPLUG: Checking GDPR Compliance of WordPress Plugins via Cross-language Code Property Graph", in: Proceedings of the Network and Distributed System Security Symposium. (Link)
[19]
Abramova, Svetlana; Böhme, Rainer (2023): "Anatomy of a High-Profile Data Breach: Dissecting the Aftermath of a Crypto-Wallet Case", in: Proceedings of the USENIX Security Symposium. (Link)
[20]
Zimmeck, Sebastian; Wang, Oliver; Alicki, Kuba; Wang, Jocelyn; Eng, Sophie (2023): "Usability and Enforceability of Global Privacy Control", Proceedings on Privacy Enhancing Technologies 2023(2). (DOI)
[21]
Aziz, Muhammad Abu Bakar; Wilson, Christo (2024): "Johnny Still Can't Opt-out: Assessing the IAB CCPA Compliance Framework", in: Proceedings on Privacy Enhancing Technologies. (DOI)
[22]
Hausladen, Katherine; Wang, Oliver; Eng, Sophie; Wang, Jocelyn; Wijaya, Francisca; May, Matthew; Zimmeck, Sebastian (2025): "Websites' Global Privacy Control Compliance at Scale and over Time", in: Proceedings of the USENIX Security Symposium. (Link)
[23]
Rasaii, Ali; Dao, Ha; Feldmann, Anja; Javid, Mohammadmahdi; Gasser, Oliver; Gosain, Devashish (2025): "Intractable Cookie Crumbs: Unveiling the Nexus of Stateful Banner Interaction and Tracking Cookies", in: Proceedings on Privacy Enhancing Technologies, pp. 429-445. (DOI)
[24]
Charatan, Jan; Birrell, Eleanor (2024): "Two Steps Forward and One Step Back: The Right to Opt-out of Sale under CPRA", in: Proceedings on Privacy Enhancing Technologies. (DOI)
[25]
Van Nortwick, Maggie; Wilson, Christo (2022): "Setting the Bar Low: Are Websites Complying With the Minimum Requirements of the CCPA?", in: Proceedings on Privacy Enhancing Technologies. (DOI)
[26]
Bui, Duc; Tang, Brian; Shin, Kang G. (2022): "Do Opt-Outs Really Opt Me Out?", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)
[27]
Acar, Gunes; Eubank, Christian; Englehardt, Steven; Juarez, Marc; Narayanan, Arvind; Díaz, Claudia (2014): "The Web Never Forgets: Persistent Tracking Mechanisms in the Wild", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)
[28]
Liu, Zengrui; Iqbal, Umar; Saxena, Nitesh (2024): "Opted Out, Yet Tracked: Are Regulations Enough to Protect Your Privacy?", in: Proceedings on Privacy Enhancing Technologies. (DOI)
[29]
Zimmeck, Sebastian; Aggarwal, Nishant; Liu, Zachary; Altman, Sage; Kollnig, Konrad (2026): "Exercising the CCPA Opt-out Right on Android: Legally Mandated but Practically Challenging", in: Proceedings on Privacy Enhancing Technologies. (DOI)
[30]
Mai, Cat; Coelho, Bruno; Kieserman, Julia; Matsumoto, Lexie; Spinelli, Kyle; Yang, Eric; Andreou, Athanasios; Greenstadt, Rachel; Lauinger, Tobias; McCoy, Damon (2025): "More and Scammier Ads: The Perils of YouTube's Ad Privacy Settings", in: Proceedings on Privacy Enhancing Technologies. (DOI)
[31]
Bashir, Muhammad Ahmad; Farooq, Umar; Shahid, Maryam; Zaffar, Muhammad Fareed; Wilson, Christo (2019): "Quantity vs. Quality: Evaluating User Interest Profiles Using Ad Preference Managers", in: Proceedings of the Network and Distributed System Security Symposium. (Link)
[32]
Caravaca, Francisco; González-Cabañas, José; Cuevas, Ángel; Cuevas, Rubén (2024): "Overprofiling Analysis on Major Internet Players", in: Proceedings on Privacy Enhancing Technologies. (DOI)
[33]
Gkiouzepi, Eleni; Andreou, Athanasios; Goga, Oana; Loiseau, Patrick (2023): "Collaborative Ad Transparency: Promises and Limitations", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)
[34]
Wei, Miranda; Stamos, Madison; Veys, Sophie; Reitinger, Nathan; Goodman, Justin; Herman, Margot; Filipczuk, Dorota; Weinshel, Ben; Mazurek, Michelle L.; Ur, Blase (2020): "What Twitter Knows: Characterizing Ad Targeting Practices, User Perceptions, and Ad Explanations Through Users' Own Twitter Data", in: Proceedings of the USENIX Security Symposium. (Link)
[35]
Karnam, Sai Keerthana; Dash, Abhisek; Gummadi, Krishna P.; Mukherjee, Animesh; Weber, Ingmar; Zannettou, Savvas (2026): "Bowling with ChatGPT: On the Evolving User Interactions with Conversational AI Systems", in: Proceedings of the ACM Web Conference. (DOI)
[36]
Zaman, Anis; Acharyya, Rupam; Kautz, Henry A.; Silenzio, Vincent (2019): "Detecting Low Self-Esteem in Youths from Web Search Data", in: Proceedings of the ACM Web Conference. (DOI)
[37]
Akgul, Omer; Roberts, Richard; Shroyer, Emma; Levin, Dave; Mazurek, Michelle L. (2025): "As Advertised? Understanding the Impact of Influencer VPN Ads", in: Proceedings of the USENIX Security Symposium. (Link)
[38]
Onaolapo, Jeremiah; Leontiadis, Nektarios; Magka, Despoina; Stringhini, Gianluca (2021): "SocialHEISTing: Understanding Stolen Facebook Accounts", in: Proceedings of the USENIX Security Symposium. (Link)
[39]
Vombatkere, Karan; Mousavi, Sepehr; Zannettou, Savvas; Roesner, Franziska; Gummadi, Krishna P. (2024): "TikTok and the Art of Personalization: Investigating Exploration and Exploitation on Social Media Feeds", in: Proceedings of the ACM Web Conference. (DOI)
[40]
Liu, Yijing; Jia, Yan; Tan, Qingyin; Liu, Zheli; Xing, Luyi (2022): "How Are Your Zombie Accounts? Understanding Users' Practices and Expectations on Mobile App Account Deletion", in: Proceedings of the USENIX Security Symposium. (Link)
[41]
Bertram, Theo; Bursztein, Elie; Caro, Stephanie; Chao, Hubert; Feman, Rutledge Chin; Fleischer, Peter; Gustafsson, Albin; Hemerly, Jess; Hibbert, Chris; Invernizzi, Luca; Donnelly, Lanah Kammourieh; Ketover, Jason; Laefer, Jay; Nicholas, Paul; Niu, Yuan; Obhi, Harjinder; Price, David; Strait, Andrew; Thomas, Kurt; Verney, Al (2019): "Five Years of the Right to be Forgotten", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)
[42]
Xue, Minhui; Magno, Gabriel; Cunha, Evandro; Almeida, Virgilio; Ross, Keith W. (2016): "The Right to be Forgotten in the Media: A Data-Driven Study", in: Proceedings on Privacy Enhancing Technologies. (DOI)
[43]
Sun, Chen; Vekaria, Yash; Nithyanand, Rishab (2026): "On the Suitability of LLM-Driven Agents for Dark Pattern Audits", Proceedings on Privacy Enhancing Technologies 2026(4):927-946. (DOI)
[44]
Datta, Amit; Tschantz, Michael Carl; Datta, Anupam (2015): "Automated Experiments on Ad Privacy Settings", in: Proceedings on Privacy Enhancing Technologies. (DOI)
[45]
Hils, Maximilian; Woods, Daniel W.; Böhme, Rainer (2021): "Privacy Preference Signals: Past, Present and Future", in: Proceedings on Privacy Enhancing Technologies. (DOI)
[46]
Take, Kejsi; Gallagher, Kevin; Forte, Andrea; McCoy, Damon; Greenstadt, Rachel (2022): "“It Feels Like Whack-a-mole”: User Experiences of Data Removal from People Search Websites", in: Proceedings on Privacy Enhancing Technologies. (DOI)
[47]
Sharma, Vandit; Mondal, Mainack (2022): "Understanding and Improving Usability of Data Dashboards for Simplified Privacy Control of Voice Assistant Data", in: Proceedings of the USENIX Security Symposium. (Link)
[48]
Utz, Christine; Michels, Matthias; Degeling, Martin; Marnau, Ninja; Stock, Ben (2023): "Comparing Large-Scale Privacy and Security Notifications", in: Proceedings on Privacy Enhancing Technologies. (DOI)
[49]
Du, Xiaolin; Yang, Zhemin; Lin, Jiapeng; Cao, Yinzhi; Yang, Min (2024): "Withdrawing is believing? Detecting Inconsistencies between Withdrawal Choices and Third-party Data Collections in Mobile Apps", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)
[50]
Zimmeck, Sebastian; Kuller, Eliza; Ma, Chunyue; Tassone, Bella; Champeau, Joe (2024): "Generalizable Active Privacy Choice: Designing a Graphical User Interface for Global Privacy Control", in: Proceedings on Privacy Enhancing Technologies. (DOI)
[51]
Xian, Lu; Tran, Van Hong; Lee, Lauren; Kumar, Meera; Zhang, Yichen; Schaub, Florian (2025): "Layered, Overlapping, and Inconsistent: A Large-Scale Analysis of the Multiple Privacy Policies and Controls of U.S. Banks", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)
[52]
Cheng, Cheng; Ramokapane, Kopo M. (2025): ""Erasing the Echo": The Usability of Data Deletion in Smart Personal Assistants", in: Proceedings on Privacy Enhancing Technologies. (DOI)
1)
EDPB, Guidelines 01/2022 on data subject rights — Right of access, §5.3 Timing for the provision of access, para. 155. https://www.edpb.europa.eu/system/files/2022-01/edpb_guidelines_012022_right-of-access_0.pdf , read 2026-09-16. Quoted from the regulator's restatement because EUR-Lex returned HTTP 202 with an empty body to this sandbox.
4)
Verbraucherzentrale Bundesverband, Court Prohibits LinkedIn's Data Privacy Infringements, 30 October 2023, https://www.vzbv.de/en/court-prohibits-linkedins-data-privacy-infringements — read 2026-09-16. vzbv was the plaintiff; the judgment is of the Landgericht Berlin.
5)
California Business and Professions Code §22575(b)(5), https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=BPC&sectionNum=22575 , read 2026-09-16.
6)
https://github.com/InteractiveAdvertisingBureau/USPrivacy — repository README, read 2026-09-16.
7)
https://iabtechlab.com/gpp/ , read 2026-09-16.
8)
https://www.w3.org/TR/gpc/Global Privacy Control (GPC), W3C Working Draft 11 June 2026; editors Sebastian Zimmeck, Peter Snyder, Justin Brookman, Aram Zucker-Scharff. Read 2026-09-16.
9)
https://coag.gov/uoom/ , read 2026-09-16.
10)
https://developer.mozilla.org/en-US/docs/Web/API/Navigator/globalPrivacyControl and the underlying mdn/browser-compat-data record for api.Navigator.globalPrivacyControl, read 2026-09-16.
11)
https://globalprivacycontrol.org/orgs , read 2026-09-16. The list names Brave Software and DuckDuckGo among browser and extension vendors; it does not state default-on behaviour, and neither vendor's own documentation was reachable from this sandbox — Brave's support site returns 403 and DuckDuckGo's help page renders client-side.
12)
California AB 566 (Lowenthal), California Consumer Privacy Act of 2018: opt-out preference signal, Chapter 465, approved by the Governor 8 October 2025, adding Civil Code §1798.136. https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260AB566 , read 2026-09-16.
13)
chromestatus.com feature 5137324344213504, Global Privacy Control; read through the chromestatus API on 2026-09-16. Read the stages array, not the summary status field: here they agree, and there is no origin-trial or ship milestone in either.
14)
EDPB, 2024 Coordinated Enforcement Action: Implementation of the right of access by controllers, adopted 16 January 2025, https://www.edpb.europa.eu/system/files/2025-01/edpb_cef-report-2024_20250116_rightofaccess_en.pdf — figures read from the PDF on 2026-09-16.
15)
EDPB, 2025 Coordinated Enforcement Action: Implementation of the right to erasure by controllers, adopted 10 February 2026, https://www.edpb.europa.eu/system/files/2026-02/edpb_cef-report_2025_right-to-erasure_en.pdf — read 2026-09-16.
16)
California Privacy Protection Agency (CalPrivacy), Data Broker Registry, https://cppa.ca.gov/data_broker_registry/ , read 2026-09-16.
17)
EDPB, CEF 2026: EDPB launches coordinated enforcement action on transparency and information obligations under the GDPR, 19 March 2026, https://www.edpb.europa.eu/news/news/2026/cef-2026-edpb-launches-coordinated-enforcement-action-transparency-and-information_en , read 2026-09-16.
You could leave a comment if you were logged in.
privacy/data_subject_rights.1789557554.txt.gz · Last modified: by karel.kubicek.claude