Aug 30, 2026
ManyPress

Advertisement

Technology

A test of 100 companies found that requests to access personal data under the California Consumer Privacy Act often resulted in confusion, errors, or unauthorized account deletions.

ManyPress

ManyPress

ManyPress Editorial

3 min readSource:Ars Technica
Testing 100 Companies Reveals Challenges in Data Access Requests

Key facts

  • The California Consumer Privacy Act (CCPA) allows residents to request access to, delete, or opt out of the sale of their personal data.
  • Companies are legally required to provide at least two methods for consumers to submit privacy requests.
  • Crunchbase attributed the deletion of an account to a processing error by a customer success team member.
  • BeenVerified stated that the agent who handled the request was mistaken and plans to provide refresher training.
  • Cash App's spokesperson stated that customers can access or delete information directly through the app to facilitate faster identity verification.
  • Experts suggest 'data minimization'—limiting data collection to only what is necessary—as a potential solution to reduce the burden on consumers.

A recent investigation involving over 100 data access requests filed under the California Consumer Privacy Act (CCPA) revealed significant friction for consumers. While the law grants Californians the right to access, delete, or opt out of the sale of their personal information, many companies struggled to process simple access requests correctly. Testers frequently encountered support representatives who misinterpreted requests, leading to unwanted account deletions or refusals to follow established privacy policy procedures.

Misinterpretation and Unauthorized Deletions

Several companies, including Crunchbase and BeenVerified, incorrectly processed access requests as deletion requests despite explicit instructions to the contrary. In the case of Crunchbase, a support representative deleted the user's account after being told not to erase any data. BeenVerified similarly removed information from search results and later claimed it could not verify the user's identity, despite having previously located the user's details.

Procedural Hurdles and Compliance Issues

Testing Cash App revealed difficulties in using designated contact methods. Although the company's privacy policy lists a toll-free phone number for CCPA requests, support agents were unable to process the request, with one agent suggesting the user call back later. Consumer advocates, including representatives from the Consumer Federation of America and the Electronic Privacy Information Center, noted that these issues suggest companies may be under-resourcing their compliance efforts.

Timeline

  1. August 17
    An access request was emailed to Crunchbase.
  2. August 19
    An access request was emailed to BeenVerified.
  3. August 21
    A response was received from BeenVerified regarding the removal of information.

Advertisement

This article was independently rewritten by ManyPress editorial AI from reporting originally published by Ars Technica.

Technology