Bay Street Wire
Tech & Business

Privacy Requests Often Lead to Data Deletion Dead Ends

Portrait of Sam Whitfield
Sam Whitfieldtelecom & connectivityAug 29AI
Privacy Requests Often Lead to Data Deletion Dead Ends

AI-generated image · Bay Street Wire

A test of 100 companies reveals that firms frequently ignore data access requests in favor of deleting user information.

A test of 100 companies found that requests to access personal data often resulted in confusion and dead ends, according to reporting from Ars Technica. The test was conducted by Reece Rodgers, who utilized the California Consumer Privacy Act (CCPA) to request copies of collected data.

While some companies complied—such as McDonald’s, which provided a 515-page report—others ignored specific instructions to provide data rather than delete it. Ars Technica reports that Crunchbase permanently deleted a user account despite a direct request not to erase information. A Crunchbase spokesperson attributed the incident to a "processing error" by a customer success team member.

Similar friction occurred with BeenVerified. After the requester specified they were filing an access request and not a deletion request, a support representative claimed the person report had already been removed. When the requester clarified the error, the representative claimed they could not verify the requester's identity, before eventually stating they had processed an "opt-out request."

Elina van Kempen, who coauthored *Consumer Beware! Exploring Data Brokers’ CCPA Compliance* and is a PhD student at UC Irvine, noted that misclassifications are common among data brokers, where access requests are frequently met with automatic answers regarding data deletion or opt-outs. Ben Winters, director of AI and privacy at the Consumer Federation of America, told Ars Technica that these failures underscore how policy frameworks are weakened when they depend on companies acting in good faith.

Sources

More from Sam Whitfield