New privacy laws have advanced individual data rights, although the ability to request access to all personal information held by a company has created new attack vectors for OSINT, phishing, social engineering, and “legal DDoS.” This talk covers regional data access options, how most companies respond to requests, and exploits for common privacy vulnerabilities. We'll explore the psychology driving corporate responses to requests, ways to exploit these emotions, and the weakest targets for attacks. For the blue teamers, detection and defense strategies will be presented. A cheatsheet with key sections of the laws for exploits and defense will provided.