Consumers seeking personal data from companies under privacy regulations frequently encounter system failures and misinterpretations. One journalist filed over 100 data access requests, receiving a 515-page report from McDonald's detailing app interactions, but faced deletion notices from other firms when asking for data copies.
The California Consumer Privacy Act, effective since 2020, grants consumers three key rights: to opt out of data selling, to delete personal information and to request a copy of collected data. Companies must provide at least two methods for filing requests—typically a web form or email—and are allotted 45 days to fulfill them.
Crunchbase, a database for tech startups, exemplified the operational breakdown. A journalist emailed an access request on August 17, explicitly stating, "I am not requesting deletion at this time. Please do not treat this as a deletion request."
Two days later, Crunchbase responded: "Your account has been permanently deleted from Crunchbase." A subsequent inquiry clarified that only the user account was deleted, while "other data located on Crunchbase was not deleted"—indicating an unsolicited partial deletion despite explicit instructions.
Ben Winters, director of AI and privacy at the Consumer Federation of America, said such responses reveal fundamental weaknesses in policy frameworks that rely on companies to act responsibly. Elina van Kempen, a PhD student at UC Irvine and coauthor of "Consumer Beware! Exploring Data Brokers' CCPA Compliance," reported that access requests frequently triggered automatic opt-out or deletion messages.
Greg Hammond, senior counsel and senior director of compliance at BeenVerified's parent company, said support agents receive annual privacy training on CCPA requests.
The recurring issues—companies misinterpreting requests, deleting data when instructed not to, or refusing to process requests via methods listed in their own privacy policies—suggest that compliance infrastructure at scale remains fragile. The friction also reflects the broader ecosystem in which personal data is aggregated and resold across platforms, with few mechanisms for consumers to exercise basic access rights.
The emerging market for third-party privacy tools underscores the economics of this gap. DeleteMe charges approximately $210 for two years of data removal and protection. Optery offers free self-removal or $4 monthly assisted removal. These services effectively arbitrage the compliance costs companies have failed to internalize.
Beyond California, 11 other U.S. states have enacted privacy laws, though some have not yet taken effect. This expanding patchwork increases the compliance burden on companies operating nationwide and signals that enforcement scrutiny will intensify. Companies that have not invested in robust, automated systems for processing data access requests now face a choice: build internal compliance infrastructure or face regulatory penalties and reputational damage.

