Technology
CCPA data access requests spark frequent company errors, reporter testing finds
A reporter's attempt to exercise California Consumer Privacy Act rights across 100 companies revealed frequent misclassifications, unexpected account deletions, and compliance friction.
The short version
- A reporter submitted over 100 data access requests under the California Consumer Privacy Act (CCPA) to examine personal data collection practices.
- Several major firms mishandled the requests; Crunchbase deleted an account, BeenVerified repeatedly logged access requests as deletions or opt-outs, and Cash App phone support failed to process a request.
- Company representatives attributed the errors to support staff misunderstandings and processing mistakes rather than automated software failures.
- Privacy advocates criticized the current framework and argued for broader data minimization policies to reduce the burden on consumers.
Key facts
- Under the California Consumer Privacy Act, eligible residents can legally request access to personal data collected by major businesses, requiring companies to provide compliant submission methods.[Wired]
- In a test of more than 100 CCPA access requests, Crunchbase mistakenly deleted the reporter's user account, which a spokesperson stated was caused by a customer success team employee error.[Wired]
- BeenVerified repeatedly processed an explicit access demand as a data deletion and opt-out request, which senior counsel Greg Hammond attributed to support agent error.[Wired]
- Cash App phone support representatives struggled to process a data access request made via the toll-free number published in the company's privacy policy, directing the caller to online options instead.[Wired]
What remains uncertain
- Cash App did not clarify why phone support agents struggled to process the access request despite the toll-free number being explicitly designated in its privacy policy.[Wired]