Policy

Companies Mishandle CCPA Data Requests, Delete Instead of Sharing

A journalist filed over 100 data access requests and found companies routinely confused them with deletion orders, raising compliance questions.

Omega Editorial· August 28, 2026· 3 min read

A journalist's experiment with California privacy law revealed widespread confusion among companies about how to handle consumer data requests. After filing more than 100 data access requests under the California Consumer Privacy Act, multiple firms responded by deleting information instead—the exact opposite of what was requested.

The reporter explicitly stated in each request that he wanted to access his data, not delete it. Yet companies including Crunchbase and BeenVerified proceeded to remove his information anyway. Crunchbase deleted his entire account despite clear instructions not to, later attributing the error to a "processing error" by a customer success team member. BeenVerified's support staff repeatedly misclassified the request across multiple email exchanges, even after corrections.

The compliance gap

The CCPA, which took effect in 2020, grants California residents three key rights: opting out of data sales, deleting personal information, and requesting copies of collected data. Companies must provide at least two methods for submitting these requests, typically through web forms, phone numbers, or email addresses listed in privacy policies.

Cash App presented a different obstacle. Despite listing a toll-free number in its privacy policy as a way to submit access requests, phone support representatives appeared unfamiliar with the process. After multiple holds, one agent asked the caller to try again later so the team could "review their resources."

Consumer advocates expressed alarm at these findings. "That's not an acceptable status quo," said Ben Winters, director of AI and privacy at the Consumer Federation of America. The failures demonstrate weaknesses in frameworks that depend on companies acting responsibly.

Elina van Kempen, a UC Irvine PhD student who previously filed access requests with over 500 data brokers, encountered similar problems. "Sometimes I would make an access request, and the automatic answer was 'We will opt you out' or 'We will delete your data,'" she said.

Why it matters

These compliance failures reveal a fundamental problem with current privacy regulations: they place the burden entirely on consumers to navigate complex bureaucratic processes, while companies face minimal consequences for mishandling requests. When firms can't distinguish between access and deletion requests—or train staff to handle them properly—the law's protections become largely theoretical. This suggests stronger approaches like data minimization, which limits what companies can collect in the first place, may be necessary to give consumers meaningful control.

A path forward

Experts point to data minimization as a more effective solution. This approach would restrict companies to collecting only data essential for standard business operations—storing payment information for purchases, for example, but not gathering demographic details to sell to brokers. By limiting collection upfront, consumers wouldn't need to navigate the obstacle course of access requests.

Mayu Tobin-Miyaji, a law fellow at the Electronic Privacy Information Center, said the problems show "how potentially little resources the companies are putting toward compliance and making sure that people can have access to their data."

These details were first reported by WIRED, which disclosed that the reporter used generative AI to draft bureaucratic emails and update tracking spreadsheets during the investigation.

#ccpa#data privacy#consumer rights#regulatory compliance#data brokers#privacy law

This is an original analysis by the Omega editorial team. Source reporting: WIRED.

Want systems like this working for your business?

Book a Call

More in Policy

Policy· 3 min read

Wisconsin Congressman Uses AI-Generated Attack Video in Tight Race

Rep. Derrick Van Orden's synthetic deepfake of opponent Rebecca Cooke highlights gaps in social media regulation as states struggle with disclosure laws.

Via AI Watch · Aug 28, 2026
Policy· 3 min read

EU AI Act enforcement begins with transparency requirements

Major tech companies are adopting watermarking and disclosure standards as Brussels tests whether its sweeping rulebook can work in practice.

Via AI Watch · Aug 28, 2026
Policy· 3 min read

Cara Art Platform Scraper Now Helps Build Anti-Scraping Tool

After harvesting 12 million images from the artist portfolio site, a remorseful data scraper is collaborating with its founder on protective technology.

Via WIRED · Aug 28, 2026