A test of 100 companies found that requests to access personal data under the California Consumer Privacy Act often resulted in confusion, errors, or unauthorized account deletions.

Key facts
- •The California Consumer Privacy Act (CCPA) allows residents to request access to, delete, or opt out of the sale of their personal data.
- •Companies are legally required to provide at least two methods for consumers to submit privacy requests.
- •Crunchbase attributed the deletion of an account to a processing error by a customer success team member.
- •BeenVerified stated that the agent who handled the request was mistaken and plans to provide refresher training.
- •Cash App's spokesperson stated that customers can access or delete information directly through the app to facilitate faster identity verification.
- •Experts suggest 'data minimization'—limiting data collection to only what is necessary—as a potential solution to reduce the burden on consumers.
A recent investigation involving over 100 data access requests filed under the California Consumer Privacy Act (CCPA) revealed significant friction for consumers. While the law grants Californians the right to access, delete, or opt out of the sale of their personal information, many companies struggled to process simple access requests correctly. Testers frequently encountered support representatives who misinterpreted requests, leading to unwanted account deletions or refusals to follow established privacy policy procedures.
Misinterpretation and Unauthorized Deletions
Several companies, including Crunchbase and BeenVerified, incorrectly processed access requests as deletion requests despite explicit instructions to the contrary. In the case of Crunchbase, a support representative deleted the user's account after being told not to erase any data. BeenVerified similarly removed information from search results and later claimed it could not verify the user's identity, despite having previously located the user's details.
Procedural Hurdles and Compliance Issues
Testing Cash App revealed difficulties in using designated contact methods. Although the company's privacy policy lists a toll-free phone number for CCPA requests, support agents were unable to process the request, with one agent suggesting the user call back later. Consumer advocates, including representatives from the Consumer Federation of America and the Electronic Privacy Information Center, noted that these issues suggest companies may be under-resourcing their compliance efforts.
Timeline
- August 17An access request was emailed to Crunchbase.
- August 19An access request was emailed to BeenVerified.
- August 21A response was received from BeenVerified regarding the removal of information.
Advertisement
This article was independently rewritten by ManyPress editorial AI from reporting originally published by Ars Technica.



