HeadlinesBriefing favicon HeadlinesBriefing.com

100 Data Access Requests Reveal Privacy Compliance Failures

Ars Technica •
×

I filed data access requests with over 100 companies under the California Consumer Privacy Act (CCPA) to understand what personal data they collect. The process was incredibly time-consuming, requiring identity verification and navigating varied submission methods like web forms, emails, and phone numbers. While McDonald’s provided a detailed 515-page report predicting I would never stop eating there, many companies failed basic compliance.

Crunchbase permanently deleted my account despite my explicit instruction not to treat the request as a deletion request. A spokesperson blamed a "processing error" by a customer success team member and promised to fulfill the original request. BeenVerified similarly responded to my access request by removing my person report from their "Pers..." database, ignoring my clear directive. Consumer advocates condemned these failures. Ben Winters, director of AI and privacy at the Consumer Federation of America, called the status quo "crazy" and "not acceptable," highlighting weaknesses in policy frameworks relying on corporate good faith.

Companies have 45 days to respond, but many confused access rights with deletion rights or refused valid submission methods listed in their own privacy policies. The experiment exposed systemic confusion and non-compliance, suggesting current regulations lack enforcement teeth to protect consumer data rights effectively.