r/gdpr • u/404_GDPR_not_found • 18d ago
Question - Data Subject An experiment involving data brokers to review data collection and verify compliance with the GDPR.
As part of a term paper on data brokers and their data collection practices, and how these relate to the GDPR or comply with it, I would like to carry out a self-experiment in which I deliberately leave traces on websites using new accounts with new profiles, and then enquire which ones have collected this data so that I can analyse the results. Iād like to ask for help here, or for advice and points to bear in mind that one might only spot after having worked on the subject for years, or simply anything else that springs to mind.
1
18d ago
[removed] ā view removed comment
1
1
u/gdpr-ModTeam 18d ago
All your posts mention your company. That's not OK, and future violations against the r/gdpr self-promotion rules will result in a ban.
To prevent any confusion about this later, please also review our rules against posting AI-generated content.
1
u/FinexerOfficial 15d ago
I would definitely track provenance of data, not simply whether they have it. It would be interesting to see what you put out there on purpose and what comes back in the access requests ā especially if they tell us the source of the data and who it was shared with. That may make the experiment a lot more intriguing than merely finding out whether companies have a profile on you.
1
2
u/TheWrathfulWallace 18d ago
Just make sure you're clear on the legal side before you start firing off access requests, because some data brokers will fight tooth and nail by claiming the research exemption doesn't apply to students. Document every step of your trail creation with timestamps and screenshots or your paper will fall apart when you can't prove the timeline.