Consumer data rights are colliding with messy real-world systems

A recent test of more than 100 consumer data access requests suggests that a right guaranteed on paper can still break down badly in practice. Reporting highlighted how companies responded unevenly when asked to provide copies of personal information collected under the California Consumer Privacy Act, or CCPA. Some firms delivered large dossiers of user data. Others created confusion, introduced delays, or appeared to treat a request for access as if it were a request to erase records altogether.

The result is a picture of a privacy regime that exists, but often remains difficult for ordinary people to use. The CCPA gives people several important rights, including the ability to opt out of data sales, ask for deletion, and request a copy of the information a company holds about them. In this case, the reporting focused on the access right alone, a relatively straightforward demand in principle: tell a person what data has been collected about them.

What happened instead was often administrative friction. The process required tracking down approved submission channels, navigating web forms, emails, and phone numbers listed in privacy policies, and completing repeated identity verification steps. Companies are allowed time to fulfill these requests, but the reporting found that the route to compliance could still be burdensome even before the waiting period ends.

When access requests are mistaken for deletion requests

One of the most striking failures described in the reporting was not just delay, but category confusion. Some companies reportedly answered access requests with messages about deleting information, despite explicit instructions not to do that. That matters because access and deletion are not interchangeable rights. A consumer asking what a company knows about them is making a different legal and practical request than one asking for records to be removed.

If a company cannot reliably distinguish between those two requests, it raises broader questions about how mature its privacy operations really are. A functioning compliance system should be able to identify the request type, route it correctly, and communicate clearly with the consumer. When that does not happen, the burden shifts back to the individual, who must correct the company, monitor the process, and hope no unwanted action has already taken place.

The reporting included an example involving Crunchbase, where an emailed access request was said to include a direct statement that no deletion was being requested. Even so, confusion emerged early in the process. That kind of breakdown points to a recurring weakness in privacy administration: policies may be written with legal precision, while execution depends on fragmented workflows, outsourced support, or poorly integrated compliance tooling.

Some companies can provide exhaustive records quickly

The reporting also showed that robust response systems are possible. A request filed with McDonald’s produced a 515-page report within days, detailing app interactions in granular form. That response illustrates two parallel realities of the modern data economy. First, many companies collect and retain far more behavioral information than most users likely assume. Second, at least some companies have built the internal infrastructure to retrieve and package that information quickly when required.

Those two realities are important together. A company that can respond in detail demonstrates that compliance is operationally achievable. But the sheer scale of the returned record also underlines how deeply digital services observe and store user activity. Access requests therefore do more than test legal compliance; they expose the underlying volume and texture of personal data collection.

For consumers, that can be clarifying. Seeing the actual record may reveal how much information a mobile app, loyalty platform, or online service has assembled over time. For regulators and advocates, these disclosures can help separate claims about privacy protections from the real capabilities and practices inside a company.

Privacy law is only as effective as the processes behind it

Consumer advocates cited in the reporting reacted sharply to the mishandling of some requests. Their criticism centered on a familiar policy problem: frameworks that depend on companies acting responsibly and in good faith can look strong on paper while producing inconsistent results in practice. If the experience is slow, confusing, or error-prone, many people will simply give up before exercising the right at all.

That practical barrier may be as significant as any formal denial. Rights that require persistence, technical understanding, and repeated follow-up are less accessible than rights that can be exercised through a predictable, well-designed process. The law may define what must happen, but the consumer experiences only the interface, the support system, and the outcome.

There is also a governance question beneath these anecdotes. If companies must list filing methods in their privacy policies, but then resist processing requests through those same methods, the issue is no longer just inconvenience. It becomes a question of whether disclosure, compliance operations, and customer-facing behavior are aligned.

  • The reporting focused on access requests, not deletion or opt-out requests.
  • Companies can take up to 45 days to complete requests.
  • Some responses reportedly confused access rights with deletion workflows.
  • At least one company returned a highly detailed personal data file within days.

The broader lesson is that data rights enforcement now depends heavily on operational competence. Consumers do not interact with statutes directly; they interact with portals, emails, call centers, and verification systems. If those systems are poorly designed, the right becomes fragile even when the law is clear.

For the privacy debate, this is a meaningful signal. The next phase of consumer data protection may hinge less on creating new categories of rights than on making existing ones usable, reliable, and difficult to mishandle. Access rights are supposed to make data collection legible to the public. When companies cannot process them cleanly, they reveal not only compliance gaps, but the still-unfinished state of digital accountability.

This article is based on reporting by Ars Technica. Read the original article.

Originally published on arstechnica.com