Master'sOpen Access

GDPR compliance of CRAs: Looking through the lens of twitter

2021
0 views
0 downloads
Advisor: Dr. Öğr. Üyesi Muhammed Abdullah Bülbül

Abstract (EN)

Collecting information about consumers and businesses from various sources, Credit reference agencies (CRAs) help many organizations. CRAs' business model depends on processing a high volume of personal data including highly sensitive ones, which must be processed within the relevant legal frameworks in different countries they operate their business, e.g., the European Union's new GDPR (General Data Protection Regulation). This thesis is about a data-driven analysis of CRA- and GDPR related discussions on Twitter. Our analysis covers the three largest multi-national CRAs: Equifax, Experian and TransUnion and we also looked at the UK's data protection authority, ICO, and two UK-based privacy-advocating NGOs, Privacy International and Open Rights Group (ORG). We have analyzed public tweets of their official Twitter accounts and other public tweets talking about them. We performed a two-stage analysis in our study. The first phase is a descriptive analysis where we manually labelled tweets and identified main themes in the discussions. Our analysis revealed a very surprising lack of awareness of CRA- and GDPR-related data privacy issues within the general public and an surprising lack of active communications of CRAs to the general public on relevant GDPR-related privacy issues: out of 39,549 collected tweets we identified only 153 relevant tweets. This small number of tweets are dominated by mentions of security issues, especially data breaches affecting CRAs, not data subject rights or privacy issues directly. At the second stage, we applied an automatic text classification by using the pretrained model BERT and neural network algorithms. By dividing the whole set into three main labels GDPR/CRA_Related, GDPR/CRA_Unrelated and NONGDPR we train our machine and apply the model on the raw 39,549 data to find if there are data missed while manual labelling. Both the automatic and manual results give consistent results. It is observed in both manual and automatic results that most of the tweets are posted by individuals. Our study reveals that CRAs don't prefer to be salient about data privacy discussions from GDPR's point of view.

Author

Kübra Aydin

How to Cite

Kübra Aydin (Master Thesis). GDPR compliance of CRAs: Looking through the lens of twitter, 2021, Ankara Yıldırım Beyazıt University.

Keywords

License

Tüm Hakları Saklıdır

This work is shared under the specified license terms.

More theses from Ankara Yıldırım Beyazıt University