Under the California Consumer Privacy Act, a reporter filed more than 100 data access requests with large companies and found that some firms deleted his information instead of providing it. The law, which took effect in 2020, grants consumers the right to request a copy of their personal data, to delete it, and to opt out of its sale. Consumer advocates said the missteps reveal a broken system. Ben Winters, director of AI and privacy at the Consumer Federation of America, called the responses unacceptable and said they show the weakness of policies that depend on companies acting in good faith.

The reporter’s first setback came from Crunchbase, a database of technology startups. He emailed an access request on August 17, explicitly stating he was not asking for deletion. Two days later, a support representative replied that his account had been permanently deleted. A follow-up explanation said his user account was gone, though other data on Crunchbase remained, and he would need to reregister. A company spokesperson blamed the incident on a processing error and said the original access request would be fulfilled.

BeenVerified, a public records search service, also mishandled the request. The reporter emailed its CCPA compliance address on August 19, again specifying an access request. Days later, a representative said his information had been removed from search results. When the reporter objected, the company said it could not verify his identity, despite having located his details earlier. After further confusion, the representative claimed his opt-out request had been processed. A compliance official at the parent company acknowledged the agent was mistaken and said refresher training and an audit were planned.

This experience matches broader patterns in the industry. Elina van Kempen, a PhD student at UC Irvine and coauthor of a study on data brokers’ CCPA compliance, said she has placed access requests with over 500 brokers and repeatedly received automatic responses offering opt-out or deletion instead. Some companies corrected their errors, but others left her without a resolution. The reporter also encountered problems with Cash App, where phone support asked him to call back later so agents could review how to handle the request. A Cash App spokesperson said customers can access or delete their own information through the app, which allows faster identity verification.

Legal experts argue the problem is not just individual mistakes. Mayu Tobin-Miyaji, a law fellow at the Electronic Privacy Information Center, said the incidents show how little resources some companies put toward compliance and ensuring people can access their data. Both Tobin-Miyaji and Winters pointed to data minimization as a better approach. That would mean companies only collect the information needed for standard business operations, such as saving payment details for future purchases, rather than gathering demographic data for sale to brokers.

Such a policy would shift the burden away from consumers, who currently face a bureaucratic process just to see what companies hold about them. By limiting what can be collected in the first place, consumers could avoid the frustration the reporter endured. For now, the reporter’s week of requests shows that the legal right to access data does not always translate into a straightforward response.

More technology news from TechManNews.