I submitted the request Earlier this month, I asked McDonald’s for access to all the personal data the fast-food company had collected about me. A few days later, I received an astonishing 515-page report detailing my interactions with the McDonald’s app—and predicting that I would never stop eating there.
Under the California Consumer Privacy Act (CCPA), California residents have the legal right to request access to personal information collected by large companies. Curious to learn how other businesses viewed me, I submitted more than 100 personal data access requests over the following week.
The CCPA took effect in 2020 and provides three key privacy rights: the right to opt out of the sale of personal information, the right to request deletion of that information, and the right to receive a copy of the personal data a company has collected.
To better understand what data companies collect, I focused exclusively on access requests. Most businesses require consumers to submit requests through one of several channels, including online forms, phone numbers, or email addresses listed in their privacy policies. Companies may take up to 45 days to respond after receiving a valid request.
Submitting these data access requests was an extremely time-consuming process. I often had to search for the correct submission method and verify my identity multiple times. The most frustrating experiences involved companies that responded to access requests with information about deleting data—even when I had clearly stated that I did not want anything deleted—or refused to process requests according to the procedures outlined in their privacy policies.
Consumer advocates I interviewed were outraged by the way some companies handled these privacy requests. “It’s crazy,” said Ben Winters, director of AI and privacy at Consumer Federation of America. “That’s not an acceptable status quo.” Winters said these examples expose weaknesses in privacy laws that rely on companies to act responsibly and follow the rules in good faith.
In keeping with WIRED’s disclosure policy, I acknowledge that I used generative AI to draft administrative emails and update tracking spreadsheets during the project. I wrote the main text of this article by hand in a notebook.
One of my first mistakes involved Crunchbase, a company known for its database of technology startups. On August 17, I emailed a data access request to the privacy address listed by the company. The message explained which rights I wanted to exercise and explicitly stated that I was not requesting deletion: “You have not requested deletion at this time. Please do not treat this as a deletion request.” Two days later, I received a response from a Crunchbase support representative.
“Thank you for your patience. Your account has been permanently removed from Crunchbase. If you need anything else, please let us know,” the entire message read.
I immediately replied and clarified that I wanted access to my personal data—not deletion. A follow-up response from customer support said, “Your Crunchbase user account has been deleted. No other data on Crunchbase has been deleted.” The representative added that I would need to register again if I wanted to create another Crunchbase account.
When I contacted Crunchbase for comment, a spokesperson attributed the mistake to a “processing error” and said the company would continue handling my original data access request. The spokesperson also said the incorrect responses were sent by “humans on our customer success team,” not generated by AI tools.
My experience with BeenVerified, a searchable public records database, further illustrated the obstacles consumers can face when submitting California privacy requests.
On the morning of August 19, I emailed BeenVerified’s dedicated CCPA compliance address. I identified myself as a California resident making a personal data access request—not a deletion request. You can probably guess what happened next.
Source: www.wired.com


