{
  "type": "article",
  "title": "Filing 100 Personal Data Requests Exposed Severe Privacy Compliance Failures Across Major Tech Platforms",
  "summary": "A comprehensive test involving over 100 data access requests under the California Consumer Privacy Act revealed systemic corporate failures, where major companies frequently deleted user accounts or refused phone requests instead of providing stored personal data.",
  "content": "A rigorous investigation into corporate data privacy compliance involving more than 100 data access requests filed under the California Consumer Privacy Act (CCPA) has uncovered systemic failures across major tech platforms, financial services, and data brokers. The exercise began with a data request submitted to fast-food giant McDonald's, which promptly returned a detailed 515-page dossier outlining granular app interactions and even predicting future dining habits. However, when similar requests seeking copies of stored personal records were submitted to over 100 other commercial entities, the process descended into bureaucratic dysfunction, resulting in unauthorized account deletions, automated opt-outs, and flat refusals to process requests via mandated communication channels.\n\n \n\nLegal Mandates of the CCPA and Procedural Obstacles\n\nEnacted in 2020, the California Consumer Privacy Act (CCPA) establishes three foundational consumer rights: the right to opt out of the sale of personal information, the right to request deletion of personal data, and the right to obtain a copy of all collected personal records. The test specifically focused on the third provision—data access requests—to evaluate what information commercial entities compile on individual consumers. Under state regulatory standards, companies must designate at least two filing methods in their privacy policies, typically including online web forms, toll-free phone numbers, or designated email addresses. Once a request is formally submitted, businesses are granted a statutory window of 45 days to fulfill the disclosure.\n\nDespite these clear regulatory guidelines, executing data access requests proved extraordinarily tedious and frustrating. The process required navigating complex verification steps, but the most severe compliance failures occurred when companies responded to explicit data access requests by permanently erasing user accounts or opting users out of search results. Consumer advocates expressed deep concern over these widespread missteps. Ben Winters, director of AI and privacy at the Consumer Federation of America, characterized the situation as unacceptable, emphasizing that it exposes inherent flaws in regulatory frameworks that rely on voluntary corporate compliance. During the study, generative AI tools were utilized to draft routine administrative communications and maintain tracking spreadsheets, while primary investigative logs were recorded manually.\n\n \n\nCrunchbase Permanently Erases User Account After Access Request\n\nOne of the earliest and most glaring compliance blunders occurred with Crunchbase, a major business information database focused on tech startups. On August 17, a formal data access request was sent to Crunchbase's designated privacy email address. The message explicitly detailed the legal rights being exercised and included an unambiguous instruction specifying that the filing was strictly an access request, stating: \"I am not requesting deletion at this time. Please do not treat this as a deletion request.\" Despite this explicit warning, a support representative responded two days later, on August 19, informing the user that their account had been permanently deleted from Crunchbase.\n\nA follow-up email was immediately transmitted to clarify that the submission sought data access rather than account termination. Crunchbase support responded by stating that while the user account had been deleted, other public record data remained intact, noting that accessing account features would require registering a brand-new user profile. When formally contacted for comment, a Crunchbase spokesperson attributed the mistake to a processing error by a customer success team member rather than an automated AI system, assuring that the company would resume fulfilling the original data access request as initially filed.\n\n \n\nBeenVerified Repeatedly Misclassifies Requests and Cancels Records\n\nInteractions with BeenVerified, a public records search engine, further highlighted the friction consumers face when exercising privacy rights. A formal CCPA access request was emailed to BeenVerified's compliance address on the morning of August 19, explicitly identifying the requester as a California resident seeking a copy of their personal data rather than information removal. Two days later, on August 21, a support agent responded that the person report, associated phone number, and email address had been removed from search results within 24 hours, completely misinterpreting the request.\n\nWhen a second email was sent clarifying the error, the support representative replied 15 minutes later denying the claim and stating the company could not verify the user's identity, despite having located the records earlier in the same email thread. A third email expressing frustration yielded yet another misclassified response confirming that the opt-out request had been processed and information removed. Academic research confirms that such errors are widespread. Elina van Kempen, a PhD student at UC Irvine and coauthor of \"Consumer Beware! Exploring Data Brokers' CCPA Compliance,\" previously submitted data access requests to over 500 data brokers under the CCPA and encountered identical systemic misclassifications. Following inquiries, Greg Hammond, senior counsel and senior director of compliance at BeenVerified's parent company, acknowledged via email that the support agent was mistaken despite receiving annual privacy training, promising refresher training and an internal audit of recent compliance cases.\n\n \n\nCash App Phone Compliance System Collapses Under Testing\n\nSubmitting an access request to Cash App, a financial service offered by Block, revealed severe operational breakdowns even without an accidental deletion mistake. Cash App's published privacy policy explicitly states in bold text that California residents may exercise data rights via its website or through a toll-free phone number. When the designated phone number was tested, customer service agents appeared completely unfamiliar with CCPA compliance procedures. The call involved multiple extended holds before the representative instructed the caller to review the online privacy policy and dial the number listed there—the exact number currently being called.\n\nA second attempt to process the request over the phone met a similar outcome. After being placed on hold again, the caller was asked to phone back later so the support team could review internal resources to figure out how to process a data access call. When asked for comment, a Cash App spokesperson stated via email that customers can access or delete personal records directly through the mobile app, which facilitates faster identity verification for financial accounts. The spokesperson added that phone teams receive training to guide users toward proper submission channels, but failed to respond to follow-up questions asking why a toll-free phone line was explicitly advertised in the privacy policy if agents could not process requests directly over the phone.\n\n \n\nPrivacy Advocates Push for Structural Data Minimization Laws\n\nReflecting on the findings, Mayu Tobin-Miyaji, a law fellow at the Electronic Privacy Information Center (EPIC), observed that these operational failures illustrate how few resources companies dedicate toward regulatory compliance and fulfilling user data rights. Experts argue that placing the entire burden of privacy enforcement on individual consumers forces them to navigate an overwhelming bureaucratic maze with minimal success.\n\nTo solve these systemic issues, both Ben Winters and Mayu Tobin-Miyaji advocate for a comprehensive transition toward \"data minimization\" standards. Under a data minimization framework, commercial entities are legally restricted to collecting only the specific data elements necessary for immediate business operations. For instance, an application could retain payment details to facilitate future checkouts, but would be legally prohibited from gathering demographic and behavioral metrics to sell to data brokers. Shifting toward data minimization removes the burden of compliance monitoring from consumers, protecting personal privacy at the point of collection.\n\nWhat this means for you\nThis report highlights the critical need for everyday digital consumers to remain vigilant about their personal data and online privacy rights.\n\n• Data Rights and Complexities: Major platforms log extensive personal and behavioral details about users. While laws grant you the right to inspect this data, navigating corporate compliance mechanisms often proves inefficient and confusing.\n• Risk of Account Deletion: Submitting data access requests can trigger accidental account deletions by customer support representatives. When exercising privacy rights, clearly state that you are requesting a copy of data rather than account removal.\n• Limited Effectiveness of Phone Support: Even when privacy policies list toll-free phone lines for data requests, customer service agents are often unprepared to process them. Utilizing secure in-app portals or web forms yields more reliable results.\n• Adopting Data Minimization Habits: Consumers should limit the amount of personal information shared with digital platforms. Restricting voluntary demographic disclosures reduces the risk of data broker profiling.\n\nQuestions & Answers\n\n1. What is the California Consumer Privacy Act (CCPA)?\nEnacted in 2020, the CCPA is a data privacy law granting consumers the legal right to request a copy of their personal data, opt out of data sales, and delete stored information.\n\n2. What error did Crunchbase commit during the data access request?\nDespite receiving an explicit data access request, Crunchbase permanently deleted the user account, later attributing the mistake to a support agent processing error.\n\n3. How did BeenVerified handle the privacy request?\nBeenVerified removed the user information from search results instead of providing data access, and later claimed it could not verify the user identity.\n\n4. What issue occurred when contacting Cash App phone support?\nAlthough Cash App lists a toll-free number for data requests in its privacy policy, phone support representatives were unfamiliar with the procedure and refused to process the request.\n\n5. What solution do privacy experts propose to fix these issues?\nExperts recommend adopting data minimization standards, which restrict companies to collecting only the essential data necessary for immediate business operations.",
  "url": "https://trendkia.com/en/gear/100-knpaniyon-se-mangi-parsanala-deta-ki-janakari-to-badale-men-mile-akaunta-dilita-hone-ke-notisa-23721",
  "category": "Gear",
  "publishedAt": "2026-08-28",
  "tags": [
    "Data Privacy",
    "CCPA Compliance",
    "Cyber Security",
    "Personal Data",
    "Cash App",
    "Crunchbase",
    "BeenVerified"
  ],
  "language": "en",
  "site": "TrendKia"
}