I asked 100 companies for my data. Some deleted it instead.
A consumer's CCPA test reveals widespread mishandling of data access requests, with some companies deleting data instead of sharing it - a compliance and trust risk.

A consumer filed over 100 CCPA requests and found that while McDonald's provided a 515-page report, many companies deleted data or gave confusing responses. This highlights the ongoing compliance challenges for businesses under privacy laws, risking penalties and customer trust.
When I filed a data access request with McDonald's under the California Consumer Privacy Act, I expected a few pages of my order history. Instead, the fast-food giant sent a 515-page report detailing my app interactions, location data, and even a prediction that I would never stop eating there. That experience sparked a broader experiment: I decided to test how 100 different companies handle the same legal request. Over the next week, I submitted more than 100 requests to a mix of retailers, tech platforms, financial services, and other businesses, tracking every response and non-response.
The CCPA, which went into effect in 2020, gives California residents the right to request the personal information a business has collected about them, ask for its deletion, and opt out of its sale. Companies have 45 days to respond, and they must provide the data in a readily usable format. The law was designed to give consumers control over their digital footprints, but my test revealed that compliance is far from uniform. Some companies responded quickly with comprehensive data dumps, while others seemed to have no idea what the law required.
The most troubling response came from companies that deleted my data entirely. Instead of providing the information I requested, they treated the request as a deletion request and wiped my records. That is a direct violation of the CCPA, which requires businesses to honor access requests before any deletion. It suggests that many companies are conflating the two distinct rights, a mistake that could expose them to enforcement actions. The California Attorney General has already fined several businesses for non-compliance, and the number of investigations is growing.
Other responses were simply confusing. Some companies sent PDFs with unreadable formatting, others provided data from only one division, and a handful asked me to resubmit the request through a different portal. A few sent links to their privacy policies instead of the actual data, clearly misunderstanding the request. The inconsistency points to a lack of standardized processes for handling privacy requests, even among well-known brands. In one case, a company asked for additional verification, which is allowed under the law, but then never followed up despite my prompt response.
For businesses, this is a wake-up call. The CCPA is enforced by the California Attorney General, and violations can result in fines of up to $7,500 per intentional violation. But the bigger risk may be reputational. Consumers are increasingly aware of their privacy rights, and a botched response can erode trust. A 2023 survey found that 68% of consumers are more likely to do business with companies that are transparent about data usage. Companies that treat privacy requests as a compliance checkbox rather than a customer service opportunity are setting themselves up for failure.
The good news is that some companies got it right. They had clear processes, responded within the legal timeframe, and provided data in a usable format. These companies are likely to benefit from the growing demand for transparency. For the rest, the lesson is simple: invest in the systems and training needed to handle privacy requests correctly, or risk falling behind. This is not just a California issue. Over a dozen states have passed similar laws, and federal legislation is being debated. The trend is clear: privacy is becoming a competitive differentiator.
My experiment shows that privacy laws are still a work in progress. While the CCPA has empowered consumers, many companies are struggling to implement it. The confusion I encountered suggests that businesses need clearer guidance from regulators and more robust internal tools. As more states pass similar laws, the pressure will only increase. Businesses that embrace privacy as a core value, rather than a legal obligation, will be the ones that thrive in this new landscape. For consumers, the message is to exercise your rights, but also to be patient. The system is far from perfect, but it is improving.
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Technology
BASF sues Apple over Face ID, dragging iPhone and iPad into Texas court
The world's largest chemical company claims dozens of Apple devices infringe its face authentication patents - and it chose a venue known for fast, plaintiff-friendly patent trials.
Google's Gemini 3.8 Flash targets agents, Cyber twin finds 13-year-old Chrome bug
Two new Flash models: one for agentic work, one for cybersecurity, with Flash Cyber already patching Chrome and finding a decade-old flaw.
Uber's UK robotaxi debut: 15 self-driving cars, safety drivers inside
The ride-hailing giant's first UK autonomous fleet is a cautious pilot; here's what it signals for the robotaxi race.


