CCPA Data Requests Hit Deletion and Support Dead Ends
More than 100 California privacy requests repeatedly encountered deletion mistakes, support-channel confusion and verification dead ends, according to a WIRED test published by Ars Technica.

More than 100 company privacy requests showed that California's data-access right can still become a customer-service maze marked by deletion mistakes, channel confusion and verification dead ends, according to a WIRED investigation published by Ars Technica.
The test started with a McDonald's request that returned a 515-page file covering app interactions and a prediction that the requester would never stop eating there.
The broader exercise relied on the California Consumer Privacy Act, which has been in effect since 2020 and gives residents rights to opt out of personal-information sales, delete data and request a copy of the information collected about them.
The account focused on access requests rather than deletion.
Companies generally must provide two submission methods, often a web form, phone number or email address listed in a privacy policy, and can take 45 days to complete a request.
Problems appeared before any data file arrived.
Some companies treated explicit access requests as deletion or opt-out requests, while others resisted methods their own privacy policies listed as available.
Repeated identity checks and unclear support scripts turned a statutory right into a process that depended heavily on whether front-line teams classified the request correctly.
In one case, a request sent to Crunchbase on Aug. 17 specified that no deletion was being requested, yet the support response two days later indicated the user's account had been permanently deleted.
Crunchbase later blamed a processing error, maintained that the response came from a customer-success employee rather than a generative AI tool, and pledged to proceed with the original access request.
A California access request sent to BeenVerified's CCPA address on Aug. 19 triggered messages about removing a person report, phone number and email address from search results.
PeopleConnect compliance executive Greg Hammond attributed the handling to agent misunderstanding despite annual privacy training, with refresher training and an audit planned.
Cash App presented a different compliance problem.
Its privacy policy listed a website and toll-free number for California access requests, but phone agents directed the requester back to the same policy and then asked for more time to determine how to handle the call.
Cash App's response emphasized online account tools and help-center instructions, without resolving why the policy presented the phone line as a direct request channel.
Consumer Federation of America privacy director Ben Winters viewed the cases as evidence of weak frameworks that rely on companies to act responsibly.
EPIC law fellow Mayu Tobin-Miyaji questioned the resources companies commit to compliance.
Both experts pointed toward data minimization as a less consumer-dependent path.
Limiting collection to information needed for ordinary business operations would reduce the burden on users who now must navigate company-specific request systems just to see what data has been collected about them.




















