Privacy audit reveals companies often mishandle data access requests

A journalist filed data access requests under California's privacy law with 100 companies. Many responded with deletion notices instead of providing the requested data, and some refused to process requests through listed methods. Consumer advocates say this shows weaknesses in relying on companies to comply with privacy regulations.
The CCPA, effective since 2020, grants California residents three core rights: opting out of data sales, requesting deletion, and requesting copies of collected data. Companies have 45 days to respond and must offer at least two submission methods, typically web forms, phone lines, or email addresses. The journalist's testing revealed that even straightforward access requests frequently triggered confusion, with some firms misclassifying them as deletion demands. Crunchbase acknowledged a "processing error" after permanently removing the journalist's account, while BeenVerified similarly created obstacles. Consumer Federation of America's Ben Winters characterized the responses as an unacceptable status quo, highlighting concerns about regulatory frameworks that depend on corporate good faith.
This reporting could influence how consumers approach their privacy rights, potentially discouraging routine data access requests if companies respond unpredictably. Individuals may hesitate to exercise legal protections when responses risk account deletion or dead ends. Regulators may face pressure to strengthen enforcement mechanisms and penalties, since voluntary compliance appears inconsistent. Businesses could also face reputational consequences as public awareness grows about mishandled requests, prompting some to improve their privacy response procedures.