I filed a request with McDonald’s earlier this month to access all of the personal data the fast food company collected about me, and I received a stunning 515-page report a few days later that detailed my app interactions in granular detail and predicted I would never stop eating there.
Under the California Consumer Privacy Act, I have the legal right to request access to information from large companies that collect personal data. So I was curious what others might have on me, and I spent the next week filing more than 100 requests.
The CCPA went into effect in 2020, and three of its key provisions are the right to opt out of the selling of personal information, the right to delete that info, and the right to request a copy for yourself.
I focused solely on the latter—access requests—to better understand what data is being collected. Most companies must list two ways for you to file. These are often via a web form, phone number, or email address, as designated in their privacy policy. After you submit a request, companies can take 45 days to complete it.
My experience placing these data access requests was incredibly time-consuming, from finding the right filing methods to verifying my identity multiple times. Most exasperating during this process were the companies that either responded to my access requests with messages concerning the deletion of information, which I explicitly said not to do, or refused to process the request through a method listed in their privacy policy.
Consumer advocates I spoke with were upset with how these requests were handled. “That’s crazy,” said Ben Winters, director of AI and privacy at the Consumer Federation of America. “That’s not an acceptable status quo.” Winters sees these examples as exhibiting the weaknesses of policy frameworks that rely on companies to act responsibly and in good faith.
In accordance with WIRED’s policies, I am disclosing that I used generative AI to draft bureaucratic emails and update my tracking spreadsheet as part of this report. I wrote the body of this article mainly by hand in my scratch notebook.
One of the first errors came from Crunchbase, known for its database about tech startups. I emailed my access request to its privacy address on August 17. My message laid out the rights I wanted to exercise and included a direct request not to erase anything: “I am not requesting deletion at this time. Please do not treat this as a deletion request.” I received a reply two days later from a Crunchbase support representative.
“Thanks so much for your patience. Your account has been permanently deleted from Crunchbase. Please let me know if you need anything else!” the message read in full.
I followed up via email almost immediately, reiterating that I wanted data access, not data deletion. “Your Crunchbase user account was deleted. Other data located on Crunchbase was not deleted,” read the follow-up support response explaining what happened. If I wanted to have a Crunchbase account, I would have to reregister.
When I reached out to Crunchbase for comment, a spokesperson blamed the mistake on a “processing error” and said that the company would proceed with my original access request as filed. The spokesperson also claimed the misclassified response came from “a person on our customer success team” and not a generative AI tool.
My interactions with BeenVerified, a searchable database that gathers public records, also encapsulate my friction-filled experience placing these access requests.
I emailed BeenVerified’s dedicated CCPA compliance address on the morning of August 19. It laid out that I was a California resident placing an access request, not a deletion request. You’ll never guess what happened next.







