In August 2026, a journalist tested the data access practices of 100 companies by submitting formal requests for personal information under privacy laws. The goal was to assess how easily individuals could obtain their data, but many responses revealed systemic confusion, delays, and unexpected outcomes, including outright deletion of accounts instead of data provision.
The experiment highlighted a gap between legal rights and real-world execution. While regulations like GDPR and CCPA grant users the right to access their data, the process often requires navigating opaque portals, vague instructions, or unresponsive support teams. In several cases, companies interpreted the request as a desire to delete data, triggering account termination without clarification.
Some firms appeared to conflate data access requests with deletion requests, possibly due to poorly designed internal workflows or automated systems that flag certain keywords. One tech company sent a confirmation that the user’s account had been permanently deleted, despite no such instruction being given. When contacted for clarification, the company cited a „standard security protocol” but could not explain why access requests triggered deletion.
This suggests a lack of training or clear differentiation between user intent in privacy handling systems. Legal experts warn that such errors could violate consumer protection laws if users are not given a chance to confirm or reverse the action.
Among the 100 companies tested, nearly 30% either failed to respond within the legally required timeframe, provided incomplete data, or took actions unrelated to the request. Retail and streaming services were more likely to deliver usable data, while social media platforms and financial apps showed higher rates of non-responsiveness or incorrect actions.
One respondent noted receiving a spreadsheet with only login timestamps, despite requesting full behavioral data. Another said they were asked to verify identity through a method that required access to the very account they were trying to query—a logical loop that blocked progress entirely.
What laws govern data access requests? In regions like the European Union and California, laws such as GDPR and CCPA require companies to provide users with a copy of their personal data upon request, typically within one month, and to explain how it is being used.
Can a company delete my account if I ask for my data? No, a data access request does not authorize account deletion. If a company deletes your account in response, it may be acting outside legal guidelines unless you explicitly requested deletion.
What should I do if a company mishandles my privacy request? You can file a complaint with a data protection authority, such as the Irish DPC for GDPR matters or the California Attorney General’s office for CCPA violations, especially if the company fails to correct the error after being notified.