I asked 100 companies for my data. Some deleted it instead.
A journalist filed over 100 CCPA data access requests to major companies and encountered widespread mishandling, with many firms misclassifying access requests as deletion or opt-out requests McDonald's provided a detailed 515-page report showing granular app interaction data and predictive analytics about the user's eating habits Companies like Crunchbase and BeenVerified deleted user accounts or removed data despite explicit instructions not to, citing "processing errors" or agent misunderstan
Analysis
TL;DR
- A journalist filed over 100 CCPA data access requests to major companies and encountered widespread mishandling, with many firms misclassifying access requests as deletion or opt-out requests
- McDonald's provided a detailed 515-page report showing granular app interaction data and predictive analytics about the user's eating habits
- Companies like Crunchbase and BeenVerified deleted user accounts or removed data despite explicit instructions not to, citing "processing errors" or agent misunderstanding
- Consumer advocates and researchers describe the current compliance landscape as unacceptable, highlighting systemic weaknesses in self-regulatory privacy frameworks
- The process was extremely time-consuming, involving identity verification hurdles, confusing responses, and companies refusing to process requests through designated channels
Why It Matters
This investigation reveals significant gaps between privacy legislation intent and corporate implementation, demonstrating that CCPA rights are not being honored consistently across industries. For AI and data practitioners, it underscores the importance of robust compliance infrastructure and the risks of relying on automated or undertrained support systems to handle sensitive legal requests.
Technical Details
- The California Consumer Privacy Act (CCPA), effective 2020, grants three key rights: opt-out of data selling, right to deletion, and right to data access
- Companies have up to 45 days to respond to access requests and must provide two filing methods per their privacy policies
- The investigation utilized generative AI to draft bureaucratic emails and maintain tracking spreadsheets, as disclosed per editorial policy
- Academic research by UC Irvine's Elina van Kempen involved over 500 data broker requests, revealing similar misclassification patterns with automated responses
- Support systems at multiple companies appeared to lack proper request-type classification, with agents or automated systems conflating access, deletion, and opt-out requests
Industry Insight
- Companies should invest in specialized training and automated classification systems for CCPA requests to prevent costly compliance failures and reputational damage from misprocessed data requests
- The reliance on undertrained support staff or poorly configured automation for legal compliance represents a systemic risk that could expose organizations to regulatory scrutiny and consumer advocacy challenges
- Privacy compliance requires more than annual training; organizations should implement real-time request validation, audit trails, and dedicated compliance teams to ensure proper handling of consumer data rights requests
Disclaimer: The above content is generated by AI and is for reference only.