# Testing 100 Companies Reveals Chaos in Data Access Requests

A test of 100 companies exposed a broken system for accessing and deleting personal data. When people request their information under privacy laws like the California Consumer Privacy Act (CCPA), many companies either ignored requests, asked for excessive verification, or simply deleted data instead of providing it.

The findings come from a systematic audit that treated privacy law compliance as an empirical question rather than trusting corporate promises. Researchers submitted standard data access and deletion requests to a cross-section of firms across retail, finance, healthcare, and technology. The results ranged from deliberate obstruction to apparent incompetence.

Some companies requested notarized documents, government-issued ID photos, or Social Security numbers for what should be routine verification. Others demanded proof of residence or threatened to close customer accounts if the person couldn't answer security questions correctly. A few firms asked users to verify information they had already provided in previous interactions, treating each request as a blank slate.

The deletion requests produced particularly troubling outcomes. Several companies claimed they had deleted data but provided no confirmation or documentation. A few sent deletion confirmation emails that acknowledged removing certain categories but stayed silent on others, leaving users uncertain whether their information actually disappeared. One pattern emerged repeatedly: companies deleted data to make the problem go away rather than complying with the spirit of privacy law.

Response times varied wildly. Some companies answered within days. Others sat on requests for months. A handful never responded at all, even after follow-ups and escalation attempts.

The audit exposed gaps between what privacy regulations promise and what actually happens. The CCPA gives California residents the right to know what data companies hold and to request deletion. Similar laws now exist in Virginia, Colorado, Connecticut, and Utah, with more states considering privacy legislation. Federal privacy reform remains stalled in Congress.

Companies have financial incentives to make requests difficult. Data deletion can disrupt marketing databases, analytics pipelines, and customer relationship management systems. Some firms may genuinely lack the technical infrastructure to access or delete data stored across multiple systems and third-party platforms. Others clearly prefer opacity.

The test found no correlation between company size and compliance quality. Large tech firms sometimes excelled at responding quickly, while others created friction points that seemed deliberately designed to exhaust requesters. Mid-size companies often lacked any clear process.

This research matters because privacy law only works if enforcement reaches beyond formal regulators. State attorneys general handle complaints and violations, but they cannot monitor every company or every request. When consumers cannot easily exercise their rights, the entire system breaks down.

The findings suggest that privacy laws need teeth beyond fines. Companies should face meaningful penalties for ignoring requests, demanding excessive verification, or falsely claiming deletion occurred. Standardized processes and timelines might help. Some proposals suggest third-party auditors or compliance certifications to verify that companies actually follow through.

Until enforcement improves, privacy rights remain theoretical for many people. A law that people cannot exercise is barely a law at all.