Navigating the Corporate Data Maze: What Happens When You Ask Over 100 Companies for Your Personal Information

Executive Overview

In an era defined by ubiquitous digital surveillance, algorithms profile our daily habits, financial transactions, and physical movements. Consumers are routinely encouraged to take control of their digital footprints by exercising their legal right to access the data corporations accumulate about them.

However, a sweeping investigative experiment reveals a starkly different reality. When one journalist filed formal data access requests with more than 100 prominent companies under the California Consumer Privacy Act (CCPA), the process exposed a Kafkaesque landscape of bureaucratic dead ends, administrative errors, and systemic non-compliance.

Far from receiving transparent dossiers detailing their digital footprints, the tester encountered customer support teams that misconstrued requests, deleted accounts instead of providing data, and erected frustrating communication barriers. Rather than serving as a seamless mechanism for consumer empowerment, data privacy laws frequently collide with corporate apathy and operational incompetence. This investigation lays bare the profound disconnect between statutory rights on paper and their execution in the real world.


Detailed Chronology: A Week of Friction and Confusion

The Genesis: McDonald’s and the 515-Page Dossier

The investigative journey began earlier this month with a straightforward request directed at McDonald’s. Under the CCPA, California residents possess the legal right to request access to the personal data large corporations harvest. Within days, the fast-food giant returned a staggering 515-page report.

The document detailed app interactions with granular precision and even featured predictive analytics indicating that the user would never stop patronizing the chain. Buoyed by this initial success—and curious to see what other corporate entities held—the author embarked on a weeklong campaign to file access requests with more than 100 companies.

Crunchbase and the Accidental Deletion

The first major administrative failure arose from Crunchbase, a premier database tracking technology startups. On August 17, an access request was emailed to the company’s designated privacy address. The message explicitly outlined the rights being exercised and featured a bold, unambiguous instruction: "I am not requesting deletion at this time. Please do not treat this as a deletion request."

Two days later, a Crunchbase support representative replied: "Thanks so much for your patience. Your account has been permanently deleted from Crunchbase. Please let me know if you need anything else!"

An immediate follow-up clarification was met with a perplexing response: "Your Crunchbase user account was deleted. Other data located on Crunchbase was not deleted." In short, the user was forced to completely reregister if they ever wanted an active account again.

When pressed for comment, a Crunchbase spokesperson blamed the fiasco on a "processing error" and promised to process the original access request, insisting the blunder came from a human customer success agent rather than an automated tool.

BeenVerified: The Loop of Bureaucratic Madness

Interactions with BeenVerified, a searchable aggregator of public records, proved even more exasperating. On the morning of August 19, an email was dispatched to the platform’s dedicated CCPA compliance address, explicitly stating that the sender was a California resident filing an access request rather than a deletion request.

Two days elapsed before a support representative replied with an entirely unrelated action: "It appears your person report has already been removed from our Person Search results. In addition, we have removed the requested phone number and email address from our search results."

I asked 100 companies for my data. Some deleted it instead.

When the user reiterated that they had asked for data access—not data scrubbing—the same representative responded 15 minutes later, denying the claim entirely and asserting that the company could not verify the user’s identity. This was done despite the fact that the platform had successfully located the user’s details earlier in the thread, offering zero guidance on what verification documents were actually required.

Pushed to wits’ end, the user sent another email expressing utter confusion. The representative’s final reply sealed the bureaucratic absurdity: "Please be assured that we’re able to process your opt-out request and have removed your information from our website."

Cash App: Speaking a Foreign Language

The hurdles extended beyond email channels into phone-based requests. Cash App, a popular peer-to-peer payment service operated by Block, explicitly states in its privacy policy that California residents can initiate access requests via its website or through a toll-free phone number.

Opting to test the phone channel, the caller explained their status as a California resident seeking data access. The representative responded as if spoken to in an alien language. Following multiple transfers and periods on hold, the caller was curtly instructed to consult the privacy policy and dial the exact same number they had just called.

When the call was redialed, a second support agent proved equally unequipped, ultimately asking the user to call back later so the support team could review their internal resources.


Supporting Context & Metrics: The Broader Landscape of Compliance Failures

The frustration experienced during this 100-company audit is far from an isolated anomaly; it reflects a broader, systemic failure within the data broker and corporate compliance ecosystems.

Academic Insights and Industry Data

Academic research underscores just how fragile statutory data rights can be in practice. Elina van Kempen, a PhD student at UC Irvine and co-author of the study Consumer Beware! Exploring Data Brokers’ CCPA Compliance, noted that her team encountered identical misclassifications when submitting access requests to over 500 data brokers.

"Sometimes I would make an access request, and the automatic answer was ‘We will opt you out’ or ‘We will delete your data,’" van Kempen explains.

While some brokers eventually corrected their course, others left researchers stranded in permanent administrative limbo with no legal resolution in sight.

Legal and Consumer Perspectives

Consumer advocates argue that these widespread failures are indicative of an inherently flawed regulatory model. Ben Winters, director of AI and privacy at the Consumer Federation of America, expressed disbelief at the findings.

"That’s crazy," Winters said. "That’s not an acceptable status quo."

I asked 100 companies for my data. Some deleted it instead.

He views these missteps as clear evidence of the weaknesses inherent in policy frameworks that rely on corporations to act responsibly and in good faith without rigorous oversight.

Similarly, Mayu Tobin-Miyaji, a law fellow at the Electronic Privacy Information Center (EPIC), emphasized that these systemic roadblocks highlight a severe lack of corporate investment in consumer rights compliance.

"It shows how potentially little resources the companies are putting toward compliance and making sure that people can have access to their data," Tobin-Miyaji noted.

(Disclosures: In accordance with professional standards and transparent reporting policies, generative AI was utilized to draft bureaucratic boilerplate emails and manage tracking spreadsheets during the execution of this investigation; however, all core reporting, narrative framing, and analysis were conducted by hand.)


Official Statements and Corporate Responses

Faced with mounting scrutiny over their mishandling of consumer requests, corporate representatives have offered varying explanations ranging from individual human error to procedural adjustments.

  • Crunchbase: A company spokesperson attributed the deletion of the reporter’s account to a "processing error," emphasizing that the misdirected response originated from a human member of the customer success team rather than a rogue generative AI system. The company pledged to honor the original data access request.
  • BeenVerified: Greg Hammond, senior counsel and senior director of compliance at BeenVerified’s parent company, acknowledged the failure in an email statement. He noted that support staff undergo annual privacy training covering CCPA protocols. "Unfortunately, despite the training, the agent who handled this matter was mistaken and misunderstood the request type," Hammond wrote, adding that the company intends to implement refresher training and audit recent workflows.
  • Cash App: A Cash App spokesperson defended the company’s operational approach via email, stating: "Customers can access or delete their personal information directly through Cash App, which allows us to more quickly verify identity before providing access to financial account information or deleting an account. Our phone support teams are trained to help customers understand how to submit these requests, and we also provide customers with instructions they can access through our online Help Center." Notably, the spokesperson declined to address why a non-functional phone number was explicitly listed in their privacy policy as an authorized channel for exercising consumer data rights.

Future Outlook: Moving Beyond the Bureaucratic Obstacle Course

The current paradigm governing digital privacy places an onerous burden squarely on the shoulders of everyday consumers. Navigating a labyrinth of complex privacy policies, identity verification walls, and poorly trained support agents turns exercising a fundamental legal right into an exhausting endurance test.

To break this cycle, privacy advocates and legal scholars are increasingly championing a structural shift toward data minimization.

The Promise of Data Minimization

Rather than forcing individuals to constantly police corporate databases, opt out of data sales, and untangle deletion notices, data minimization would legally restrict organizations from collecting superfluous information in the first place.

  • Operational Limits: Under a strict data minimization framework, companies would be permitted to retain only the data strictly necessary to execute core business functions—such as saving a credit card token for an active purchase.
  • Prohibiting Exploitative Harvesting: Peripheral demographic data collection, behavioral tracking designed for third-party data brokers, and expansive digital profiling would be proactively barred.

By limiting what corporations are allowed to harvest at the ingestion point, regulatory frameworks can offer true peace of mind. Until lawmakers embrace systemic data minimization, however, consumers attempting to discover what tech giants and data brokers know about them will continue to find themselves trapped in a frustrating, error-ridden corporate maze.

Leave a Reply

Your email address will not be published. Required fields are marked *