
The proliferation of Brain Computer Interfaces (BCIs), which enable direct interaction with the human brain, poses significant yet underexplored threats to privacy and data protection. These neurotechnologies process neurodata, highly sensitive information with the potential to reflect an individual's mental state. This paper critically examines the potential negative consequences of using BCIs, considering the neurodata lifecycle from acquisition to deletion. The analysis highlights the unique risks posed by neurodata processing, coming from the difficulty individuals face in understanding and controlling the information collected, its potential for linking or identification, and the ability to decode and even modify inner mental states such as thoughts and emotions. A comprehensive understanding of associated threats is crucial as BCIs are deployed in diverse sectors, including healthcare, workplace, education, entertainment, marketing, and safety. This paper proposes a comprehensive and systematic threat model specifically designed to identify privacy and data protection threats unique to BCIs. In addition, the paper discusses the produced threat model to offer practical recommendations and point out possible safeguards, drawing on existing data protection frameworks while also identifying critical gaps that need to be addressed to ensure the responsible and compliant design, development, deployment and use of BCIs and the adequate protection of data subjects' rights and freedoms. The analysis presented in this paper provides crucial insights for researchers, providers, policymakers, and the public regarding the potential impacts of interfacing human brains and the urgent need for robust safeguards.
Social engineering attacks are successful due to the exploitative nature of human psychology. Although security solutions, such as 2FA, aim to reduce the severity of attacks, these approaches tend to be insufficient considering sophisticated phishing attacks. In the present paper, we investigate how the design of the 2FA method may influence the likelihood of a login to a malicious website. Through an online experiment with N = 94 participants, we show that contrary to common assumptions, warning designs prompting to proceed with login might have a contradicting effect. In contrast, designs that prompt users to abort the login have minimal desired effects. Moreover, we identify that involvement in login activity and confidence in the decision made had further significant effects on the likelihood of login. Our exploratory results contribute to the knowledge of susceptibility to phishing attacks and potential misconceptions about the effects of opinionated design in the context of 2FA.
Despite the availability and advancement of privacy solutions, including Privacy Enhancing Technologies (PETs), a gap remains between individuals motivated to protect their online privacy and their actual adoption of PETs. While research has identified a range of discrete factors influencing PET adoption, these insights lack cohesion, limiting their practical applicability. Instead, we interviewed 16 domain experts from Western democratic countries, synthesising fragmented findings to establish strategies for effectively supporting individuals throughout the entire PET adoption process. Grounded in the Security and Privacy Acceptance Framework (SPAF), our study focused on three key areas: motivating action, raising awareness, and aligning adoption pathways with users' needs and abilities. Based on our qualitative analysis, we identified a set of 21 recommendations in five categories to be utilised when assisting individuals in their decision-making and adoption of PETs. Our findings emphasise practical recommendations, such as understanding privacy concerns, leveraging risk awareness, offering personalised recommendations, supporting Uptake and maintaining engagement. By combining expert insights with literature findings, our study informs the design of strategies and software assistants that support individuals in the pre-adoption phase and promote the adoption of PET.
According to the European General Data Protection Regulation (GDPR), a Data Protection Impact Assessment (DPIA) is mandatory for all ongoing and planned processing of personal data if said processing is likely to affect the privacy and data protection rights and freedoms of the data subjects. However, upon examining the real-world implementation of this requirement, various approaches emerged, resulting in a heterogeneous landscape of DPIA processes. In this paper, we present the results of a survey that investigated the state of adoption of DPIA process methodologies in real-world organisations. Our survey reveals that handwritten DPIA reports and ad-hoc methods continue to dominate the DPIA landscape in Europe. Moreover, according to our data, processes involving multiple stakeholders are often not adequately assessed in terms of DPIA-related risks.
In mid-2025, the EU Commission proposed an amendment to the GDPR that extends the derogation to not maintain a record of processing activities under Article 30(5) to small and mid-cap organisations in addition to SMEs, with the intended goal of reducing reporting obligations and based on the Draghi report's recommendations for improving competitiveness. In this article, I systematically show how this exemption does not provide any practical benefits as the information involved must still be collected to assess whether the exemption applies and to be maintained elsewhere to fulfil other GDPR obligations. I also highlight how Article 30 records are a key requirement for oversight and accountability, and that their absence will negatively affect the organisation's data governance and compliance practices, thereby increasing risks and liability. I conclude with alternatives to mere `simplification' based on responding to actual needs of organisations, taking advantage of RegTech/eGov technologies with known success stories, and to avoid diluting the GDPR as it risks damaging the future of EU's digital policies. While the utility of this work is focused on short-term regulatory activities, the arguments and potential solutions proposed here are informative for future rule-making efforts in the EU.
Anonymization is a foundational principle of data privacy regulation, yet its practical application remains riddled with ambiguity and inconsistency. This paper introduces the concept of anonymity-washing -- the misrepresentation of the anonymity level of ``sanitized'' personal data -- as a critical privacy concern. While both legal and technical critiques of anonymization exist, they tend to address isolated aspects of the problem. In contrast, this paper offers a comprehensive overview of the conditions that enable anonymity-washing. It synthesizes fragmented legal interpretations, technical misunderstandings, and outdated regulatory guidance and complements them with a systematic review of national and international resources, including legal cases, data protection authority guidelines, and technical documentation. Our findings reveal a lack of coherent support for practitioners, contributing to the persistent misuse of pseudonymization and obsolete anonymization techniques. We conclude by recommending targeted education, clearer technical guidance, and closer cooperation between regulators, researchers, and industry to bridge the gap between legal norms and technical reality.
Practitioners building online services and tools often turn to online forums such as Reddit, Law Stack Exchange, and Stack Overflow for legal guidance to ensure compliance with the GDPR. The legal information presented in these forums directly impacts present-day industry practitioner's decisions. Online forums can serve as gateways that, depending on the accuracy and quality of the answers provided, may either support or undermine the protection of privacy and data protection fundamental rights. However, there is a need for deeper investigation into practitioners' decision-making processes and their understanding of legal compliance when seeking for legal information online. Using GDPR's “legitimate interests” legal ground for processing personal data as a case study, we investigate how practitioners use online forums to identify common areas of confusion in applying legitimate interests in practice, and evaluate how legally sound online forum responses are. Our analysis found that applying the legal basis of legitimate interest is complex for practitioners, with important implications for how the GDPR is implemented in practice. The legal analysis showed that crowdsourced legal information tends to be legally sound, though sometimes incomplete. We outline recommendations to improve the quality of online forums by ensuring that responses are more legally sound and comprehensive, enabling practitioners to apply legitimate interests effectively in practice and uphold the GDPR.
The rise of cookie paywalls ('pay-or-ok' models) has prompted growing debates around the right to privacy and data protection, monetisation, and the legitimacy of user consent. Despite their increasing use across sectors, limited research has explored how users perceive these models or what shapes their decisions to either consent to tracking or pay. To address this gap, we conducted four focus groups (with n = 14 participants) to examine users' perceptions of cookie paywalls, their judgments of fairness, and the conditions under which they might consider paying, alongside a legal analysis within the EU data protection legal framework. Participants primarily viewed cookie paywalls as profit-driven, with fairness perceptions varying depending on factors such as the presence of a third option beyond consent or payment, transparency of data practices, and the authenticity or exclusivity of the paid content. Participants voiced expectations for greater transparency, meaningful control over data collection, and less coercive alternatives, such as contextual advertising or "reject all" buttons. Although some conditions, including trusted providers, exclusive content, and reasonable pricing, could make participants consider paying, most expressed reluctance or unwillingness to do so. Crucially, our findings raise concerns about economic exclusion, where privacy and data protection might end up becoming a privilege rather than fundamental rights. Consent given under financial pressure may not meet the standard of being freely given, as required by the GDPR. To address these concerns, we recommend user-centred approaches that enhance transparency, reduce coercion, ensure the value of paid content, and explore inclusive alternatives. These measures are essential for supporting fairness, meaningful choice, and user autonomy in consent-driven digital environments.
This work introduces Information Inference Diagrams (I2Ds), a modeling framework aiming to complement existing approaches for privacy and security analysis of distributed systems. It is intended to support established threat modeling processes. Our approach is designed to be compatible with Data Flow Diagrams (DFDs), which form the basis of many established techniques and tools. Unlike DFDs, I2Ds represent information propagation, going beyond mere data flows to enable more formal reasoning in threat modeling while remaining practical. They define inference and sharing (flow) relations on information items to model how information moves through a system. To this end, we provide formal definitions for information items, entities, and flows. By introducing classes as a type system, our formal rules are both generic and allow conformance to existing vocabularies. We demonstrate the applicability of I2Ds through examples, that showcase their versatility in system analysis.
The European Union's General Data Protection Regulation (GDPR) strengthened several rights for individuals (data subjects). One of these is the data subjects' right to access their personal data being collected by services (data controllers), complemented with a new right to data portability. Based on these, data controllers are obliged to provide respective data and allow data subjects to use them at their own discretion. However, the subjects' possibilities for actually using and harnessing said data are severely limited so far. Among other reasons, this can be attributed to a lack of research dedicated to the actual use of controller-provided subject access request packages (SARPs). To open up and facilitate such research, we outline a general, high-level method for generating, pre-processing, publishing, and finally using SARPs of different providers. Furthermore, we establish a realistic dataset comprising two users' SARPs from five services. This dataset is publicly provided and shall, in the future, serve as a starting and reference point for researching and comparing novel approaches for the practically viable use of SARPs.
Data re-identification methods are becoming increasingly sophisticated and can lead to disastrous data breaches. Re-identification is a key research topic for computer scientists as it can be used to reveal vulnerabilities of de-identification methods such as anonymisation or pseudonymisation. However, re-identification, even for research purposes, involves processing personal data. From this background, this paper aims to investigate whether re-identification carried out by computer scientists for research purposes can be considered GDPR-compliant. This issue is paramount to contribute to improving the state of knowledge concerning data security measures.
Smart toys combine traditional playtime with modern technologies, integrating IoT features like communication, computation, and sensing to create interactive toys that respond to their environment, offering children new options for entertainment and playful education. However, despite well-documented privacy and security shortcomings of IoT devices, there are no recent studies on the privacy and security properties of smart toys. This is critical because children are a particularly vulnerable group whose personal data merits special protection. In this paper, we therefore examine 12 smart toys available in the EU market with regard to their security, privacy, and transparency. Our main findings include widespread behavioral profiling of children via toy analytics data and a lack of transparency due to insufficient and not easily accessible information about data collection and processing.
The EU Regulation 2022/868 (Data Governance Act) designs a European data governance framework to facilitate data sharing, shaping the role of the Data Intermediation Service Provider. This paper aims to clarify, from a levelism perspective, the main features of the Data Governance Act framing it as a macro-level model, and to explore the data intermediation service provider's role as one of multiple subjective stand-points in this data governance model. In doing so, it attempts to capture the main legal properties of data intermediation service and it brings them to the fore, identifying potential semantic constraints that may need to be addressed when engineering a data governance model in line with legally desirable outcomes. This paper builds on the existing cross-sectoral literature at the intersection of law and technology by relying on the research method of legal analysis and lays the groundwork for implementing a data governance model that integrates and consolidates different levels, dimensions, and facets of the in-force legal framework.
The paper explores the legal challenges and implications of processing personal data within public-private partnerships (PPPs) in smart city projects. Smart cities use a web of technologies to collect and analyse data from various sources, aiming to improve their efficiency and achieve multiple goals. However, this also raises concerns about privacy and adequate protection of data subjects' rights. The paper focuses on the legal basis for data processing regulated by the General Data Protection Regulation (GDPR) and how it differs between the public and private sectors involved in PPPs. The paper argues that the disparity in goals and legal grounds for data processing may create conflicts and uncertainties for joint data controllers, as well as data subjects. It intends to explore potential grey areas in the lawful grounds for collecting data and its implications for citizens' right to data protection in this context.
In today's digital world, children are encouraged to develop a significant part of their daily lives by online means. Age assurance solutions have become essential tools to ensure the protection of their fundamental rights. This is reflected in different regulatory frameworks, strategies, codes, and recommendations concerning children's protection and a safer Internet. These solutions estimate or verify users' ages, allowing for the establishment of age restrictions for content, services, and goods. However, the intersection of safety and privacy within this field poses significant challenges, not only for children but for all Internet users. This research explores the privacy and data protection implications of age assurance, analyzing existing solutions and proposing a comprehensive privacy threat model. The threat model developed in this paper can be widely applied to improve the design and implementation of current solutions, policy and guidelines formulation, and awareness initiatives about age assurance challenges. By balancing adequate age assurance with robust and compliant data protection, we can create a digital environment for everyone that guarantees the protection of fundamental rights.
Data-driven advancements significantly contribute to societal progress, yet they also pose substantial risks to privacy. In this landscape, differential privacy (DP) has become a cornerstone in privacy preservation efforts. However, the adequacy of DP in scenarios involving correlated datasets has sometimes been questioned and multiple studies have hinted at potential vulnerabilities. In this work, we delve into the nuances of applying DP to correlated datasets by leveraging the concept of pointwise maximal leakage (PML) for a quantitative assessment of information leakage. Our investigation reveals that DP's guarantees can be arbitrarily weak for correlated databases when assessed through the lens of PML. More precisely, we prove the existence of a pure DP mechanism with PML levels arbitrarily close to that of a mechanism which releases individual entries from a database without any perturbation. By shedding light on the limitations of DP on correlated datasets, our work aims to foster a deeper understanding of subtle privacy risks and highlight the need for the development of more effective privacy-preserving mechanisms tailored to diverse scenarios.
The vision for 6G extends beyond mere communication, incorporating sensing capabilities to facilitate a diverse array of novel applications and services. However, the advent of joint communication and sensing (JCAS) technology introduces concerns regarding the handling of sensitive personally identifiable information (PII) pertaining to individuals and objects, along with external third-party data and disclosure. Consequently, JCAS-based applications are susceptible to privacy breaches, including location tracking, identity disclosure, profiling, and misuse of sensor data, raising significant implications under the European Union's general data protection regulation (GDPR) as well as other applicable standards. This paper critically examines emergent JCAS architectures and underscores the necessity for network functions to enable privacy-specific features in the 6G systems. We propose an enhanced JCAS architecture with new network functions and interfaces, facilitating the management of sensing policies, consent information, and transparency guidelines, alongside the integration of sensing-specific functions and storage for sensing processing sessions. Furthermore, we conduct a comprehensive threat analysis for all interfaces, employing security threat model STRIDE and privacy threat model LINDDUN. We also summarise the identified threats using standard common weakness enumeration (CWE). Finally, we suggest the security and privacy controls as the mitigating strategies to counter the identified threats stemming from the JCAS architecture.
Various regulations including the GDPR empower users with the right to request a copy of their personal data processed by data holders. This right of access can serve as the foundation of exercising other data subject rights, including erasure and rectification of the processed data. Like other regulations, the GDPR does not prescribe any specific procedure data holders need to implement to handle data subject access requests but requires them not to erect any material or formal hurdles in the assertions of their rights. In this paper, we focus on popular online service providers as data holders and investigate in which form they allow users to make data access requests directly on their websites and whether they use any strategies to impede such requests. Our systematical analysis of the process of submitting access requests on 166 account-based websites from the top 500 entries of the Tranco list reveals 238 instances of dark patterns impeding the submission of data subject access requests on 113 (68
With the upcoming enforcement of the EU AI Act, documentation of high-risk AI systems and their risk management information will become a legal requirement playing a pivotal role in demonstration of compliance. Despite its importance, there is a lack of standards and guidelines to assist with drawing up AI and risk documentation aligned with the AI Act. This paper aims to address this gap by providing an in-depth analysis of the AI Act's provisions regarding technical documentation, wherein we particularly focus on AI risk management. On the basis of this analysis, we propose AI Cards as a novel holistic framework for representing a given intended use of an AI system by encompassing information regarding technical specifications, context of use, and risk management, both in human- and machine-readable formats. While the human-readable representation of AI Cards provides AI stakeholders with a transparent and comprehensible overview of the AI use case, its machine-readable specification leverages on state of the art Semantic Web technologies to embody the interoperability needed for exchanging documentation within the AI value chain. This brings the flexibility required for reflecting changes applied to the AI system and its context, provides the scalability needed to accommodate potential amendments to legal requirements, and enables development of automated tools to assist with legal compliance and conformity assessment tasks. To solidify the benefits, we provide an exemplar AI Card for an AI-based student proctoring system and further discuss its potential applications within and beyond the context of the AI Act.
European websites increasingly adopt pay-or-tracking walls, sometimes known as “consent or pay models,” “cookie paywalls,” or “pay-or-okay walls.” These walls require users to pay a fee or consent to be tracked in exchange for website access. However, initial evidence suggests that websites might continue to track users even when they pay the fee, constituting user deception. This paper comprehensively assesses whether websites employing pay-or-tracking walls keep their privacy promise to paying users as stated on the pay-or-tracking wall and safeguard their privacy. Data collection and analysis from 341 websites show that while websites reduce tracking for paying users, 32.9