The news
One person submitted formal access requests to 100 companies under California privacy law. Many organizations responded by deleting the data rather than supplying copies of the records they held.
The outcome turned the intended right to know into an exercise that often left the requester with less information than before. Companies treated deletion as the simpler path, and the pattern appeared across multiple sectors without a consistent process for delivering the requested files.
Context
California law gives residents the ability to ask companies for the personal data those firms have collected. The same statutes permit requests for deletion. In this test, the deletion option surfaced more often once the access requests arrived.
Before the submissions, the companies maintained the data under ordinary collection practices. After the requests, several firms erased records instead of assembling and sending them. This change removed the prior state in which the information stayed available for later review.
The two reports that covered the test reached similar conclusions about the practical result. Access remained possible on paper, yet the steps required to obtain it produced uneven or absent replies.
Details
The Ars Technica account described repeated internal confusion at the companies contacted. Requests entered company systems and sometimes ended without any confirmation that data existed or had been located. Follow-up messages were often needed simply to learn whether the request had been understood.
The Wired account recorded a comparable sequence. Deletion notices began arriving soon after the submissions, sometimes before any data had been reviewed or provided. The notices themselves rarely explained what records had been removed or why deletion had been chosen over delivery.
No dominant format appeared across the 100 responses. Some companies sent nothing. Others issued deletion confirmations without listing the categories of data involved. The sample spanned various industries, though neither report broke results down by sector. The shared observation was that locating and formatting records for delivery proved more difficult for the companies than simply erasing them.
Why it matters
Deletion as the default reply undercuts the transparency the statutes were written to create. When companies remove data instead of showing it, individuals lose any chance to check accuracy, understand what categories are stored, or decide whether further action is needed. The legal right to access exists, but the path to exercise it now carries a built-in risk that the information will disappear before it can be seen.
Companies face a clear incentive to delete. Assembling records requires staff time, coordination across systems, and formatting that meets the request. Deletion avoids that work and reduces future exposure. The statutes do not impose equal effort on both options, so organizations rationally select the lower-cost response.
The burden of chasing replies and clarifying intent falls entirely on the person making the request. Someone who wants the data for review must send follow-ups, interpret vague notices, and accept that some organizations will simply end the process without delivering anything. That friction is not required by the text of the law, yet it determines whether the right produces any result.
Over repeated attempts, the pattern is likely to reduce the number of access requests filed. People who encounter deletion notices or dead ends will have less reason to try again. The statutes remain in force, but their practical effect narrows to deletion for many companies and continued opacity for the individuals the rules were meant to inform.
---
Sources:
{"word_count": 682, "headline": "Data Requests to 100 Companies Yielded Deletions Rather Than Access", "sources": 2}
No comments yet