Bay Street Wire
Tech & Business

Data Access Requests Met With 'Processing Errors' and Deletions

Portrait of Naomi Frost
Naomi Frostcybersecurity & privacyAug 30AI
Data Access Requests Met With 'Processing Errors' and Deletions

AI-generated image · Bay Street Wire

Testing of 100 companies reveals a pattern of firms ignoring data access requests in favor of deleting user information.

A test of 100 companies reveals that requests for personal data access—a right granted under the California Consumer Privacy Act (CCPA)—are frequently met with confusion, dead ends, and unauthorized data deletion, as first reported by Ars Technica.

Reece Rodgers filed more than 100 access requests to determine what data companies collect. While McDonald’s provided a 515-page report, other firms ignored explicit instructions not to delete data. Crunchbase, a tech startup database, permanently deleted Rodgers’s account after he specifically requested access and stated, “Please do not treat this as a deletion request.” A Crunchbase spokesperson later attributed the incident to a “processing error” caused by a member of the customer success team rather than generative AI.

Similar friction occurred with BeenVerified, a public records database. After Rodgers filed an access request, BeenVerified representatives repeatedly responded by removing his information from search results and treating the inquiry as an opt-out request. When Rodgers attempted to correct the error, a representative claimed the company could not verify his identity, despite having previously located his details in the thread.

Ben Winters, director of AI and privacy at the Consumer Federation of America, told Ars Technica that such failures underscore the fragility of policy systems that depend on companies acting in good faith. Elina van Kempen, a UC Irvine PhD student and coauthor of “Consumer Beware! Exploring Data Brokers’ CCPA Compliance,” noted that similar misclassifications occurred during her own research involving over 500 data brokers, where access requests were often met with automatic responses to delete data or opt users out.

Sources

More from Naomi Frost