Development
I asked 100 companies for my data. Some deleted it instead.
August 29, 2026 Development Source: Ars Technica
Share this article
One of the first errors came from Crunchbase, known for its database about tech startups. I emailed my access request to its privacy address on August 17. My message laid out the rights I wanted to exercise and included a direct request not to erase anything: “I am not requesting deletion at this time. Please do not treat this as a deletion request.” I received a reply two days later from a Crunchbase support representative.
“Thanks so much for your patience. Your account has been permanently deleted from Crunchbase. Please let me know if you need anything else!” the message read in full.
I followed up via email almost immediately, reiterating that I wanted data access, not data deletion. “Your Crunchbase user account was deleted. Other data located on Crunchbase was not deleted,” read the follow-up support response explaining what happened. If I wanted to have a Crunchbase account, I would have to reregister.
When I reached out to Crunchbase for comment, a spokesperson blamed the mistake on a “processing error” and said that the company would proceed with my original access request as filed. The spokesperson also claimed the misclassified response came from “a person on our customer success team” and not a generative AI tool.
My interactions with BeenVerified, a searchable database that gathers public records, also encapsulate my friction-filled experience placing these access requests.
I emailed BeenVerified’s dedicated CCPA compliance address on the morning of August 19. It laid out that I was a California resident placing an access request, not a deletion request. You’ll never guess what happened next.
At my wit’s end, I sent another email explaining how confused I was feeling by these responses. “Please be assured that we’re able to process your opt-out request and have removed your information from our website,” read the support representative’s response. If I wasn’t already bald, I would have pulled out the rest of my hair at that moment.
I found solace in chatting with an academic researcher who had previously helped place access requests with over 500 data brokers under the same California law and also encountered multiple misclassifications. “Sometimes I would make an access request, and the automatic answer was ‘We will opt you out’ or ‘We will delete your data,’” says Elina van Kempen, a PhD student at UC Irvine and coauthor of Consumer Beware! Exploring Data Brokers’ CCPA Compliance. While some data brokers followed up with corrections, other times the researcher was left without any resolution.
When I reached out to BeenVerified for comment, Greg Hammond, senior counsel and senior director of compliance at its parent company, claimed via email that support agents receive annual privacy training, including how to process CCPA requests. “Unfortunately, despite the training, the agent who handled this matter was mistaken and misunderstood the request type,” he wrote. Hammond says the company now plans to provide refresher training on correct processing and to audit recent work.
My attempts to place an access request with Cash App, a money-sending service offered by Block, were equally frustrating, even without a deletion mistake. The company’s privacy policy, in bold, states that California residents can place access requests through Cash App’s website or by a toll-free phone call. I opted to test out the phone number.
The first time I called and explained that I was a California resident who wanted to place an access request, it was as if I had started speaking in a language from outer space. I was placed on hold multiple times before being told to check the privacy policy and call the number listed there, which I had just done to get to this point. My attempt to process an access request over the phone was being effectively denied.
“OK, sure, I’ll call this number right back,” I said before I hung up, a bit of anger bubbling up in my voice despite my best efforts to remain professional. My interactions with the next customer support agent were similarly burdensome. After being put on hold, I was asked to call back later so the support team would have more time to review their resources and understand how to handle my call.
“Customers can access or delete their personal information directly through Cash App, which allows us to more quickly verify identity before providing access to financial account information or deleting an account,” a Cash App spokesperson wrote over email when I reached out for comment. “Our phone support teams are trained to help customers understand how to submit these requests, and we also provide customers with instructions they can access through our online Help Center.”
The spokesperson did not respond to follow-up questions asking why the phone number was explicitly listed in Cash App’s privacy policy as a way for consumers to exercise their data rights.
Experts I spoke with questioned whether companies are putting in enough effort to be legally compliant. “It shows how potentially little resources the companies are putting toward compliance and making sure that people can have access to their data,” says Mayu Tobin-Miyaji, a law fellow at the Electronic Privacy Information Center.
Both Winters and Tobin-Miyaji mentioned a beefed-up approach to “data minimization” as a potential better path forward for consumers. This would essentially mean companies can collect only the data they need to process standard business operations. For example, saving your credit card information in the app for future purchases might be allowed, but collecting personal demographic information to sell to brokers might be blocked.
Data minimization is a more holistic approach that shifts the burden away from consumers, who are currently forced to navigate a bureaucratic obstacle course just to see what companies know about them. Instead, by limiting what companies can collect about you in the first place, consumers can have more peace of mind without going through the headache-inducing process I endured.
This story originally appeared on wired.com.