Your right to this export: GDPR Article 15, audited
The Instagram data download is your Article 15 right of access in practice — here is what the law promises, what a 2025 academic audit found platforms actually deliver, and which promised pieces are missing from the ZIP.
Every article about this feature frames the Instagram export as a download: a folder
you request, a ZIP you open, a set of folders to read. That framing is accurate about
the mechanism and silent about the reason it exists. The ZIP is not a product feature
Meta volunteers; it is how the platform discharges a legal obligation — the right of
access in Article 15 of the GDPR, which says you may obtain a copy of your personal
data and a defined set of information about that data. The mechanism and the
promise are different objects, and the interesting reading of your export starts by
holding them side by side: what does Article 15 promise, what did an independent audit
find the real packages contain, and which promised piece is not in your ZIP?
This post does exactly that comparison — the law's own list against the audit's
measured delivery — and it stays on the Meta side of a line this site draws carefully:
Article 15 is a right you hold against the platform. What custody claims this app
itself makes (or refuses to make) about your archive are a separate question with a
separate answer, and the security post owns it.
Your export is the Article 15(3) copy — the legal obligation wearing a download
button. A 2025 academic audit of Instagram, TikTok and YouTube packages found the
data copy broadly delivered but three promised information items systematically
missing from all three platforms' packages: the purposes of processing, the retention
periods, and the recipients of your data. In the same audit, Instagram's watch
history reached back at most two weeks, while its like history spanned the account's
lifetime — durations chosen without disclosed criteria, which is itself one of the
information items Article 15 requires. So: the copy you can have; the explanation
around it, not yet.
- 2minwhat Article 15 promises, itemised.
- 5minthe audit's findings against that item list, including the two-week watch
- history and the missing purposes/retention/recipients.
- ongoing — how to use the right: timelines, free-of-charge copy, where complaints go.
The right, as written
Article 15 of Regulation (EU) 2016/679 — the right of access — gives a data subject
two distinct things, and conflating them is most of the confusion around this
feature:1
- Confirmation and access. Confirmation that personal data concerning you is
being processed, and access to that data — plus a copy of the personal data
undergoing processing, under Article 15(3), free of charge. - The information around the data. Under Article 15(1), alongside the copy: the
purposes of the processing; the categories of personal data concerned; the
recipients or categories of recipient to whom the data have been or will be
disclosed, particularly recipients in third countries; the envisaged period for
which the data will be stored, or the criteria used to determine it; the existence
of rights to rectification, erasure, restriction and objection; the right to lodge
a complaint with a supervisory authority; where the data were not collected from
you, any available information about their source; and the existence of automated
decision-making including profiling, with meaningful information about the logic
and the envisaged consequences.
Article 12 wraps the whole thing: concise, transparent, intelligible, easily
accessible, in clear language — and a response clock of one month, extendable by
two further months for complex or numerous requests. Article 15(3) also caps the copy
right: it must not adversely affect the rights of others, which is a legal footnote
until you remember it is the reason your export contains your side of other people's
conversations and not their accounts.
Note what kind of obligation this is. The copy and the information list are not
aspirations in a privacy policy; they are enforceable requirements, backed by the
supervisory-authority complaint route the article itself names. The ZIP exists because
a regulator can ask whether you can actually get your copy.
How the export became the compliance mechanism
Nobody designed the Download Your Information page to be readable. It exists because
"provide a copy of the personal data undergoing processing" has to be satisfiable at
platform scale, and a generated archive is how a company with a few hundred million EU
users answers the same request a few hundred million times. The request flow itself —
pick format, pick date range, pick media options, verify, wait — is the identity check
and the assembly line in one; this site's request post walks the mechanics, ten clicks
deep from the content page as last measured by the audit, with packages typically
ready within minutes — comfortably inside the one-month deadline.2
Two consequences follow from reading the ZIP as a legal instrument rather than a
feature. First, the format debate (HTML versus JSON) is a readability choice inside
an obligation that also demands intelligibility — arguably the reason both formats
exist at all. Second, and less comfortably: a compliance mechanism is answerable to
the list in Article 15(1), not only to the copy in 15(3). You can check that list
against your own package. That is what the audit did.
The audit
In 2025, a research team published a systematic audit of data download packages from
Instagram, TikTok and YouTube — sock-puppet accounts with known histories,
user-donated real exports, and a 400-participant comprehensibility survey — asking
three questions: what do the platforms share, how reliably, and can people understand
it.3 The findings that matter for anyone holding an Instagram ZIP today:
The shared failure: purpose, retention, recipients. All three platforms failed to
disclose, in their packages, the purposes of data collection, the retention periods,
and the recipients of the data — the exact items Article 15(1)(a)–(c) require to come
with the information. The researchers note the material may exist elsewhere in
privacy-policy pages, and answer that the regulation places the obligation on making
it explicit and accessible alongside the data. Their verdict is blunt: all three fail
to report purpose, recipients and retention, and these shortcomings defeat the
purpose of the right.
Instagram's two-week watch history. The platforms carve different amounts of
history out of the same lifetime of account activity: YouTube's watch history spanned
the account's entire life; TikTok's, about six months; Instagram's, at most the last
two weeks — with no disclosed criteria for the cut, which is precisely what
Article 15(1)(d) asks for (storage period, or the criteria used to determine it). The
inconsistency inside one package is the tell: Instagram shipped like history for the
account's lifetime while watch history covered two weeks. Both are your behaviour; the
archive's depth in each is a retention decision, not a measurement of what exists.
Different platforms implement the same article differently. YouTube's package was
materially smaller than the others; Instagram's contained more categories than any.
The right is one; the delivery is three incompatible shapes — evidence, in the
researchers' framing, that the implementations lack shared technical guidance and
stronger enforcement.
Nobody can really read it. The 400-person survey found current packages fall
substantially short of GDPR comprehensibility standards, and the team demonstrated a
prototype (a layered concise/raw view plus a browser extension) that measurably
helped. A copy you cannot understand is not nothing — but Article 12 asks for
accessible and intelligible, and the gap between those words and a folder of JSON is
where the audit lives.
Your ZIP against the Article 15(1) list
One clarification before the exercise: Article 15 does not travel alone. The rights it
announces in its own information list — rectification of inaccurate data, erasure
under conditions, restriction, objection to processing — are Articles 16 through 21,
each with its own conditions and its own request path, and "the right to be forgotten"
is the famous subset of them. The export touches them only as evidence: you cannot
rectify an interest label you have not seen, and the dossier section is exactly where
the unseen labels live. The practical exercise this post exists for, though, is 15's
own list against your package:4
| Article 15(1) item | In your package? | Notes |
|---|---|---|
| Confirmation that data is processed | Yes, in effect | The delivered package is the confirmation |
| Copy of the data (15(3)) | Yes | The ZIP itself — free of charge |
| Categories of personal data | Mostly, as folders | Present as content; not stated as a legal category list |
| Purposes of processing | **No** | Not disclosed in the package — the audit's first shared failure |
| Recipients / categories of recipients | **No** | Not disclosed as such; the advertisers folder shows *your* matched advertisers, which is data, not a recipient disclosure |
| Envisaged storage period or criteria | **No** | Missing — and the two-week watch-history cut shows why it matters |
| Rights to rectification, erasure, objection | Not stated in-package | The rights exist regardless; the package does not enumerate them |
| Right to complain to a supervisory authority | Not stated in-package | Also exists regardless |
| Source of data not collected from you | Partly | Inferred data appears as lists (interests, advertisers) without a source statement |
| Automated decision-making / profiling logic | **No** | The dossier section shows *outputs* of profiling; the meaningful logic and consequences Article 15(1)(h) asks for are not included |
Seven rows are content; five are information the article wants delivered about the
content. The audit's central observation is that platforms treat Article 15 as the
copy clause when it is the copy clause plus the explanation clause — and your
ZIP's folder structure, however complete as data, does not contain a purpose, a
retention clock, or a list of who else received what.
What this does and does not mean for you
Three honest readings, and one caution:
- The right is real and worth using. The copy half works: turnaround within the
deadline, free of charge, in machine-readable and human-readable forms, repeatable
whenever you ask again. Whatever else the audit shows, the mechanism delivers the
object — and the file you are holding while reading this is the proof, not a
metaphor for it. - The missing items are requestable. Purpose, retention and recipient information
are things you are entitled to be told — the audit's point is that they do not come
in the package, not that they may never be provided. A access request made through
the platform's privacy channels is the Article 15(1) follow-up to the Article 15(3)
copy you already hold. What you do with a response that still omits them is a
supervisory-authority conversation, which the article itself names. - Your archive's shallowness has a cause you can now name. When the watch-history
section of your export feels absurdly short next to years of posts, you are seeing a
retention decision the audit measured across platforms — not an error in your
download and not evidence that you barely watched anything. The activity post maps
the files; this post explains why one of them is two weeks deep.5
The caution: none of this is legal advice, and none of it is a compliance verdict —
"indications of non-compliance" is the auditors' own careful phrasing, and formal
determinations belong to regulators, not to blog posts or to us. The audit is also a
snapshot: packages change, platforms adjust, and a 2026 re-run could read differently.
If you are outside the EU
Article 15 as written binds processing in the context of offering goods or services to
data subjects in the EU (or EEA) — the familiar territorial scope of the GDPR. If you
are in scope, the one-month clock and the free copy apply to you. If you are not, your
jurisdiction's own access right is the equivalent hook: several other regimes grant a
"right to know" or access with their own procedures, timelines and thresholds, and
platforms typically run one export machinery for all of them. The honest answer to
"do I have this right?" is therefore jurisdictional, not product-shaped: the download
button is the same; the law standing behind it depends on where you sit. Nothing in
this post changes how the export works for you — it explains the promise that applies
where it applies.
Is the Instagram export actually required by the GDPR?
The data copy is how the platform meets Article 15(3) at scale — confirmation plus a
copy of your processed personal data, free of charge. The request flow, the format
choices and the delivery window are built around that obligation (and similar ones
elsewhere). The audit's critique is precisely that the mechanism delivers the copy
half of Article 15 while omitting the information half.
How long does a request take?
Article 12 allows one month, extendable by two months for complex or numerous
requests, with the extension and reasons notified. The audit observed Instagram
packages typically ready within 10–15 minutes — well inside the deadline in practice,
whatever the legal outer bound.
The ZIP does not say why my data is collected or how long it is kept. Can I ask for that?
Yes — those are Article 15(1) information items in their own right, and the audit's
finding is that they are absent from the packages, not that they are outside the
right. Raise them through the platform's privacy request channels; if the answer still
omits them, the article names the supervisory-authority complaint route.
Does the two-week watch history mean my older watch data is deleted?
It means the export contains at most two weeks of it, with no disclosed criterion for
that cut — which is what the audit flagged as an Article 15(1)(d) gap. Whether the
underlying data is retained beyond the package is a separate question the package
cannot answer, for exactly the same reason: retention periods are one of the
undisclosed items.
Is this post legal advice?
No. It reports a published audit and paraphrases the article it audits; it offers no
assessment of any individual situation and no binding interpretation. The auditors
themselves speak of indicators, not adjudications — formal compliance calls are made
by supervisory authorities, and this post keeps to what the paper and the text say.
Does LMKFR change any of my rights under Article 15?
No. The right runs against the platform that processes your data; a local tool that
reads the copy you already received neither adds to it nor subtracts from it. This
app's own obligations to you are contractual and documented — see the security post
for exactly what is and is not claimed about your archive's custody.
Questions this comes up
The request post for the mechanics of getting the package; the security post for what
happens to it afterwards; the activity post for reading the files the audit found
shallow; the missing-half post for absences that are structural rather than legal.
1: Regulation (EU) 2016/679 (GDPR), Article 15 (right of access by the data
subject) and Article 12 (transparent information and modalities), official text via
EUR-Lex: <https://eur-lex.europa.eu/eli/reg/2016/679/oj>. Paraphrased here, not
reproduced in full.
3: Setting the Course, but Forgetting to Steer: Analyzing Compliance with
GDPR's Right of Access to Data by Instagram, TikTok, and YouTube, arXiv:2502.11208
(2025) — <https://arxiv.org/abs/2502.11208>. Sources for the findings above: their
DDP comparison (watch history: Instagram ≤2 weeks, TikTok ~6 months, YouTube lifetime;
like history lifetime on Instagram), their Article 15(1) disclosure analysis (purpose,
retention and recipients absent from all three platforms' packages), and their
400-participant comprehensibility survey.
2: This site's request walkthrough for the flow itself; click-depth and
turnaround figures as reported by the audit's usability observations (10 clicks on
Instagram, packages often ready in 10–15 minutes).
4: The table maps Article 15(1)(a)–(h) and 15(3) against package contents
as audited and as parsed by this site's tooling. "Not stated in-package" means absent
from the delivered archive — it does not assert the right does not exist elsewhere in
the platform's channels.
5: The activity post documents the watch-history files
(watch_history.json, watched_videos.json, viewed_reels.json,videos_watched.json) and their segmentation by content type — the same
three-file split (ads, posts, videos) the audit observed.
Footnotes
- gdpr
- request
- audit
- checklist
- activity