Breaking
DEKevin Warsh versucht nach missglückter Juli-Pressekonferenz das Vertrauen der Märkte zurückzugewinnenRUTrump Announces U.S. Deal to Gain Control of Venezuela's Oil ReservesINTLMilo Yiannopoulos detained by ICE in New Orleans after overstaying visaTRKahta yakınlarındaki trafik kazasında Şevket Aslan yaşamını yitirdiINJio Platforms Secures Sebi Approval for $4 Billion IPOTRABD, Venezuela ile tarihî petrol anlaşması imzaladığını ilan ettiKR셀틱·레인저스, 팬 충돌로 스코티시컵 첫 홈 경기 무관중 징계INTLAlpharetta Police Share Flock Data with Over 2,300 Agencies NationwideDEEhemaliger ukrainischer Verteidigungsminister Fedorow wird italienischer MilitärberaterTRSultangazi'de yeni spor tesisi inşaatı başlatıldı, Naim Süleymanoğlu'na ad verildiDEKevin Warsh versucht nach missglückter Juli-Pressekonferenz das Vertrauen der Märkte zurückzugewinnenRUTrump Announces U.S. Deal to Gain Control of Venezuela's Oil ReservesINTLMilo Yiannopoulos detained by ICE in New Orleans after overstaying visaTRKahta yakınlarındaki trafik kazasında Şevket Aslan yaşamını yitirdiINJio Platforms Secures Sebi Approval for $4 Billion IPOTRABD, Venezuela ile tarihî petrol anlaşması imzaladığını ilan ettiKR셀틱·레인저스, 팬 충돌로 스코티시컵 첫 홈 경기 무관중 징계INTLAlpharetta Police Share Flock Data with Over 2,300 Agencies NationwideDEEhemaliger ukrainischer Verteidigungsminister Fedorow wird italienischer MilitärberaterTRSultangazi'de yeni spor tesisi inşaatı başlatıldı, Naim Süleymanoğlu'na ad verildi
BackFiling Over 100 Data Access Requests Reveals Widespread CCPA Compliance Failures
Filing Over 100 Data Access Requests Reveals Widespread CCPA Compliance Failures
Developing
Wired3 hours agoTech2 min read

Filing Over 100 Data Access Requests Reveals Widespread CCPA Compliance Failures

Quick Look

After filing more than 100 data access requests under the California Consumer Privacy Act, the author received a 515-page report from McDonald's detailing app interactions and encountered repeated misclassifications by companies like Crunchbase and BeenVerified, which processed access requests as deletion requests despite explicit instructions, highlighting systemic failures in corporate compliance with privacy laws.

AI-generated summary

Why It Matters

The California Consumer Privacy Act (CCPA) went into effect in 2020, granting residents the right to access, delete, and opt out of the sale of their personal data held by companies. The author exercised the right to access to understand what data corporations collect.

Font size

I filed a request with McDonald’s earlier this month to access all of the personal data the fast food company collected about me, and I received a stunning 515-page report a few days later that detailed my app interactions in granular detail and predicted I would never stop eating there.

Under the California Consumer Privacy Act, I have the legal right to request access to information from large companies that collect personal data. So I was curious what others might have on me, and I spent the next week filing more than 100 requests.

The CCPA went into effect in 2020, and three of its key provisions are the right to opt out of the selling of personal information, the right to delete that info, and the right to request a copy for yourself.

I focused solely on the latter—access requests—to better understand what data is being collected. Most companies must list two ways for you to file. These are often via a web form, phone number, or email address, as designated in their privacy policy. After you submit a request, companies can take 45 days to complete it.

My experience placing these data access requests was incredibly time-consuming, from finding the right filing methods to verifying my identity multiple times. Most exasperating during this process were the companies that either responded to my access requests with messages concerning the deletion of information, which I explicitly said not to do, or refused to process the request through a method listed in their privacy policy.

Consumer advocates I spoke with were upset with how these requests were handled. “That's crazy,” said Ben Winters, director of AI and privacy at the Consumer Federation of America. “That's not an acceptable status quo.” Winters sees these examples as exhibiting the weaknesses of policy frameworks that rely on companies to act responsibly and in good faith.

In accordance with WIRED’s policies, I am disclosing that I used generative AI to draft bureaucratic emails and update my tracking spreadsheet as part of this report. I wrote the body of this article mainly by hand in my scratch notebook.

One of the first errors came from Crunchbase, known for its database about tech startups. I emailed my access request to its privacy address on August 17. My message laid out the rights I wanted to exercise and included a direct request not to erase anything: “I am not requesting deletion at this time. Please do not treat this as a deletion request.” I received a reply two days later from a Crunchbase support representative.

“Thanks so much for your patience. Your account has been permanently deleted from Crunchbase. Please let me know if you need anything else!” the message read in full.

I followed up via email almost immediately, reiterating that I wanted data access, not data deletion. “Your Crunchbase user account was deleted. Other data located on Crunchbase was not deleted,” read the follow-up support response explaining what happened. If I wanted to have a Crunchbase account, I would have to reregister.

When I reached out to Crunchbase for comment, a spokesperson blamed the mistake on a “processing error” and said that the company would proceed with my original access request as filed. The spokesperson also claimed the misclassified response came from “a person on our customer success team” and not a generative AI tool.

My interactions with BeenVerified, a searchable database that gathers public records, also encapsulate my friction-filled experience placing these access requests.

I emailed BeenVerified’s dedicated CCPA compliance address on the morning of August 19. It laid out that I was a California resident placing an access request, not a deletion request. You’ll never guess what happened next.

Two days later, I received a message from a BeenVerified support representative about removing information. “It appears your person report has already been removed from our Person Search results,” read its initial response. “In addition, we have removed the requested phone number and email address from our search results. This change should be reflected within 24 hours.” Not at all what I asked it to do.

When I sent my next email explaining that I had submitted an access request, not a deletion request, the support representative followed up 15 minutes later, denying my claim and saying the company couldn’t verify my identity. That was perplexing, since it located some of my details earlier in the message thread and didn’t even attempt to explain what I might need to share for verification.

At my wit's end, I sent another email explaining how confused I was feeling by these responses. “Please be assured that we're able to process your opt-out request and have removed your information from our website,” read the support representative's response. If I wasn’t already bald, I would have pulled out the rest of my hair at that moment.

I found solace in chatting with an academic researcher who had previously helped place access requests with over 500 data brokers under the same California law and also encountered multiple misclassifications. “Sometimes I would make an access request, and the automatic answer was ‘We will opt you out’ or ‘We will delete your data,’” says Elina van Kempen, a PhD graduate from UC Irvine and coauthor of Consumer Beware! Exploring Data Brokers' CCPA Compliance. While some data brokers followed up with corrections, other times the researcher was left without any resolution.

When I reached out to BeenVerified for comment, Greg Hammond, senior counsel and senior director of compliance at its parent company, claimed via email that support agents receive annual privacy training, including how to process CCPA requests. “Unfortunately, despite the training, the agent who handled this matter was mistaken and misunderstood the request type,” he wrote. Hammond says the company now plans to provide refresher training on correct processing and to audit recent work.

My attempts to place an access request with Cash App, a money-sending service offered by Block, were equally frustrating, even without a deletion mistake. The company’s privacy policy, in bold, states that California residents can place access requests through Cash App’s website or by a toll-free phone call. I opted to test out the phone number.

The first time I called and explained that I was a California resident who wanted to place an access request, it was as if I had started speaking in a language from outer space. I was placed on hold multiple times before being told to check the privacy policy and call the number listed there, which I had just done to get to this point. My attempt to process an access request over the phone was being effectively denied.

“OK, sure, I'll call this number right back,” I said before I hung up, a bit of anger bubbling up in my voice despite my best efforts to remain professional. My interactions with the next customer support agent were similarly burdensome. After being put on hold, I was asked to call back later, so the support team would have more time to review their resources and understand how to handle my call.

What to Watch

AI outlook — possibilities, not facts

  • Regulatory scrutiny of CCPA compliance will increase following reports of widespread misclassification of access requests

    Likely · Within months

Open Questions

  • How many companies correctly processed the author's access requests versus misclassifying them?
  • What specific personal data did McDonald's predict about the author's future behavior?
  • Are there penalties for companies that repeatedly mishandle CCPA access requests?

Related Topics

This article was originally published by Wired.

Related Stories

BlackBerry pivots to AI through secure communications and automotive software, with QNX powering 275 million vehicles
Developing·2 hours ago

BlackBerry pivots to AI through secure communications and automotive software, with QNX powering 275 million vehicles

BlackBerry has transitioned from smartphone manufacturing to focusing on secure communications and QNX automotive software, which powers 275 million vehicles. CEO John Giamatteo highlights the company's push into physical AI for robotics and industrial applications, backed by a $950 million QNX order backlog. The shift has doubled BlackBerry's share price this year as investors embrace its new software-centric strategy.

CNBC World
2 min read
Meta settles $18bn lawsuit with US states over child safety, shares rise as investors see minimal financial impact
Developing·2 hours ago

Meta settles $18bn lawsuit with US states over child safety, shares rise as investors see minimal financial impact

Meta agreed to pay $18bn to settle a lawsuit with 29 US states over allegations that Facebook and Instagram harmed children, but its stock rose over 1% as investors viewed the settlement as financially manageable, amounting to less than a month's revenue and payable over 10 years. The deal includes platform changes like a two-hour daily use cap for teens and default safety settings, but excludes admission of liability, leaves the recommendation algorithm untouched, and applies only in the US despite Meta's global reach. Critics argue the settlement fails to address core business model harms and resembles past ineffective tech regulation, with some calling for breakup or public health-style intervention.

Guardian Business
2 min read
Nvidia CEO Jensen Huang Took a Call From Donald Trump in the Middle of an All-Hands
Developing·3 hours ago

Nvidia CEO Jensen Huang Took a Call From Donald Trump in the Middle of an All-Hands

Nvidia CEO Jensen Huang received a call from Donald Trump during an all-hands meeting hours before Trump posted a congratulatory message on Truth Social about Nvidia's recent earnings. Other news includes Milo Yiannopoulos being detained by ICE in Louisiana, Microsoft Teams being exploited by scammers in China, GSA office issues, AI's impact on doctors, REI Labor Day deals, laptop recommendations, the Cara platform's AI data conflict, Meta's robot testing in data centers, Android-iOS file sharing, and data access requests under California law.

Wired
1 min read
More on this topicccpa