← Latest briefing

Technology

CCPA data access requests spark frequent company errors, reporter testing finds

A reporter's attempt to exercise California Consumer Privacy Act rights across 100 companies revealed frequent misclassifications, unexpected account deletions, and compliance friction.

The short version

  • A reporter submitted over 100 data access requests under the California Consumer Privacy Act (CCPA) to examine personal data collection practices.
  • Several major firms mishandled the requests; Crunchbase deleted an account, BeenVerified repeatedly logged access requests as deletions or opt-outs, and Cash App phone support failed to process a request.
  • Company representatives attributed the errors to support staff misunderstandings and processing mistakes rather than automated software failures.
  • Privacy advocates criticized the current framework and argued for broader data minimization policies to reduce the burden on consumers.

Key facts

  • Under the California Consumer Privacy Act, eligible residents can legally request access to personal data collected by major businesses, requiring companies to provide compliant submission methods.[Wired]
  • In a test of more than 100 CCPA access requests, Crunchbase mistakenly deleted the reporter's user account, which a spokesperson stated was caused by a customer success team employee error.[Wired]
  • BeenVerified repeatedly processed an explicit access demand as a data deletion and opt-out request, which senior counsel Greg Hammond attributed to support agent error.[Wired]
  • Cash App phone support representatives struggled to process a data access request made via the toll-free number published in the company's privacy policy, directing the caller to online options instead.[Wired]

What remains uncertain

  • Cash App did not clarify why phone support agents struggled to process the access request despite the toll-free number being explicitly designated in its privacy policy.[Wired]

Sources