I Asked 100 Companies For My Data. Several Deleted It Instead.
A 515-page report from McDonald's. That's what arrived a few days after filing a routine data access request under California's Consumer Privacy Act. It logged app interactions in exhausting detail and, apparently, concluded the requester would be a customer for life. Fine. But what happened next, across more than 100 similar requests, was considerably less amusing.
The CCPA has been law since 2020. Among its core provisions: you can ask a company to stop selling your data, you can request deletion, and you can request a copy of everything they hold on you. This exercise focused entirely on that third option. Simple enough in theory. In practice, an obstacle course.
Filing these requests is slow, tedious work. Companies are required to offer at least two submission methods, typically a web form, a phone number, or an email address buried in their privacy policy. Once submitted, they have 45 days to respond. What they're not supposed to do is delete your data when you explicitly ask them not to.
Crunchbase managed that one spectacularly. An access request was emailed to its privacy address in August, with a line written in plain English: 'I am not requesting deletion at this time. Please do not treat this as a deletion request.' The reply, two days later, confirmed the account had been permanently deleted. Crunchbase later blamed a 'processing error' and a human on its customer success team, not an AI tool, which is a distinction that probably matters less to the person who just lost their account.
BeenVerified, a public records aggregator, managed to be simultaneously more chaotic and more infuriating. An access request sent to its dedicated CCPA compliance address was answered with confirmation that a person report had been removed from search results, along with associated phone numbers and email addresses. The opposite of what was asked. When this was pointed out, the support rep denied the request had been misclassified and claimed they couldn't verify identity. This from a company that had just located personal details well enough to delete them. A follow-up email got a cheerful response about processing the opt-out request. At no point did anyone at BeenVerified appear to understand what an access request was.
Greg Hammond, senior counsel at BeenVerified's parent company, confirmed via email that staff receive annual CCPA training. He attributed the mess to an agent who 'misunderstood the request type' and said the company would be conducting refresher training and auditing recent work. Reassuring.
Cash App, meanwhile, managed to frustrate without even making the deletion mistake. Its privacy policy explicitly lists a toll-free number as a valid channel for California residents to submit access requests. Calling that number resulted in being put on hold, told to check the privacy policy, and effectively sent in circles. A second call ended with a request to call back later so staff could 'review their resources.' When Cash App was asked why a number listed in its own privacy policy wasn't actually equipped to handle these requests, the spokesperson did not respond to the follow-up.
Researchers who have studied this problem at scale aren't surprised. Elina van Kempen, a PhD student at UC Irvine who co-authored a study on data broker CCPA compliance across more than 500 brokers, found the same pattern repeatedly. Access requests triggering opt-out confirmations. Deletions happening instead. Some companies corrected themselves; others simply never resolved it.
Ben Winters of the Consumer Federation of America called the mishandling 'not an acceptable status quo,' which is polite for what it actually is: companies treating legal compliance as a box-ticking exercise rather than something that requires functioning processes. Mayu Tobin-Miyaji from the Electronic Privacy Information Center was blunter, suggesting the problems reveal how little resource many companies are actually dedicating to making these rights work in practice.
Both advocates pointed toward data minimisation as a more structurally sound approach. Rather than asking consumers to fight through bureaucracy to find out what's been collected, limit what companies can collect in the first place. Demographic data harvested for resale to brokers would be off the table. Payment details needed to complete a transaction would not. The burden shifts from the individual to the system, which is where it probably should have been from the start.
As things stand, exercising your legal right to see your own data requires patience, persistence, and a tolerance for being accidentally deleted.