In a revealing exploration of data access requests, an individual filed over 100 inquiries to various companies, uncovering troubling patterns in how these requests are handled. Under the California Consumer Privacy Act (CCPA), consumers have the right to request access to their personal data, but the responses received were often inadequate or misclassified.
Initial Findings from Major Brands
One of the first requests was directed at McDonald’s, which resulted in a comprehensive 515-page report detailing the requester’s interactions with the app. This starkly contrasts with responses from other companies, such as Crunchbase, which mistakenly deleted the requester’s account instead of providing the requested data. A spokesperson attributed this error to a “processing error” and noted that the company would fulfill the original access request.
Frustrations with Data Brokers
The experience with BeenVerified was similarly frustrating. After submitting a clear access request, the response focused on deleting information instead. When the requester sought clarification, BeenVerified denied the claim of having received an access request, citing an inability to verify identity despite having previously located the requester’s details. This prompted a response from Greg Hammond, senior counsel at BeenVerified’s parent company, who acknowledged the error and indicated plans for refresher training on processing requests.
Challenges with Compliance and Customer Support
Attempts to engage with Cash App also highlighted systemic issues. The requester faced significant hurdles when trying to process an access request over the phone, with customer support failing to recognize the request type. A spokesperson later stated that the company’s privacy policy allows for such requests but did not address why phone support was ineffective.
Expert Opinions on Compliance Practices
Consumer advocates expressed concern over the handling of these requests, indicating that many companies may not be dedicating sufficient resources to ensure compliance with the CCPA. Mayu Tobin-Miyaji from the Electronic Privacy Information Center suggested that a more robust approach to data minimization could alleviate the burden on consumers, limiting the data companies collect to what is necessary for business operations. This shift could enhance consumer trust and reduce the complexities involved in accessing personal data.
The investigation underscores the need for companies to improve their compliance practices and the overall consumer experience regarding data access under the CCPA.
This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.








