Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Business

Consumer’s Data-Access Quest Reveals Widespread Missteps and Deletion Errors

A personal test of California’s privacy law showed that more than 100 firms either mishandled access requests or mistakenly deleted data, highlighting systemic compliance gaps.

After submitting a data-access request to McDonald’s and receiving a detailed report, the author expanded the experiment to over 100 companies under the California Consumer Privacy Act. Requests to Crunchbase and BeenVerified resulted in unintended account deletions and removal of personal records, even though the author explicitly asked only for access. Cash App’s phone-based request process proved cumbersome, with agents repeatedly redirecting the author back to the policy.

Privacy advocates such as Ben Winters and Mayu Tobin-Miyaji criticized the companies’ inadequate handling and suggested broader data-minimization measures. Responses from the firms ranged from attributing mistakes to “processing errors” to promising additional staff training. The episode illustrates how current privacy frameworks rely heavily on companies’ good faith, leaving consumers to navigate a bureaucratic maze to retrieve their own data.

Why it matters

It shows that current privacy laws may not reliably protect consumers' right to see their personal data.

In this story

CCPAdata access requestdeletion mistakeprivacy compliancedata brokersgenerative AIdata minimization
Get the beta ↗