Asking 100 Companies for Your Data Is a Mess and Here Is Proof
Key takeaways
- A journalist submitted data access requests to 100 companies and documented wildly inconsistent responses
- Some companies deleted personal data instead of providing it, which is illegal under most data protection laws
- GDPR requires companies to respond to access requests within 30 days
- Regulators in the UK and EU can fine companies for inadequate data subject access responses but enforcement is typically slow
A journalist at Ars Technica went through the process of requesting their personal data from 100 different companies, and the results are as chaotic as anyone who has ever tried to do this would probably expect. Companies deleted data instead of providing it. Forms led nowhere. Emails went unanswered. In some cases, the company's privacy policy and its actual practice turned out to have nothing to do with each other. The investigation is a practical stress test of privacy rights infrastructure, and it finds that infrastructure in genuinely poor shape.
The right to access your own personal data exists in various forms across different legal frameworks. In California, the California Consumer Privacy Act gives residents the right to know what data a company holds about them and to request its deletion. In Europe, GDPR Article 15 provides broadly similar rights to EU residents. The UK has equivalent provisions under the UK GDPR. On paper, these are meaningful rights. In practice, the experience of trying to exercise them is frequently maddening.
What Actually Happened When They Asked
The investigation reportedly found that companies responded in wildly inconsistent ways to the same type of request. Some provided data promptly and in a useful format. Many did not. A notable failure mode was companies that deleted data when the request was for access rather than deletion, which is both illegal in most jurisdictions with data protection law and exactly the opposite of what was asked for. Whether this happened through incompetence or as a deliberate strategy to reduce liability by eliminating records is not always clear.
Dead-end forms were another recurring problem. Companies with complicated privacy request processes often design those processes in ways that make completion difficult, whether intentionally or simply through poor design. A form that requires you to verify your identity through a system that doesn't work, or a portal that generates an error every time you submit, or an email address for privacy requests that nobody monitors, all of these are barriers that most people will give up in front of, which is entirely in the company's interest.
The investigation also found that some companies' responses were technically compliant but practically useless, sending back enormous data exports in formats that were difficult to parse, or providing data that was clearly incomplete compared to what the company would need to provide the services it offers.
Why This Matters Beyond the Inconvenience
Data access rights are not just about giving curious people a peek at their own files. They serve several concrete functions. They allow people to verify whether data about them is accurate, which matters when inaccurate data affects things like credit decisions, insurance pricing, or algorithm-driven service access. They allow people to find out whether their data has been shared with third parties they weren't aware of. And they provide a check on companies that claim to have deleted data when they have not.
When the process for exercising these rights is systematically broken, the rights themselves become performative. Laws that exist on paper but cannot be practically exercised don't protect anyone. Regulators in the UK and EU have both issued fines for inadequate data subject access responses, but enforcement is slow and typically follows formal complaints rather than proactive audits. The practical experience documented in this investigation suggests that most companies face little real consequence for getting this wrong.
The Fix Is Not Complicated, Just Unpopular
The technical requirements for responding properly to a data access request are not especially demanding. What's needed is a designated, monitored contact point for requests, a clear internal process for pulling together the relevant data, a reasonable response time (GDPR sets 30 days as the standard), and the ability to provide that data in an accessible format. Many companies could do this with modest investment in process and staffing.
The reason most don't is that it's not in their immediate commercial interest to make it easy for users to audit their own data. Advertising-supported companies in particular hold data that, if examined closely, might make users uncomfortable with the extent of tracking they've consented to through terms and conditions they never read.
Regulatory pressure is the only reliable mechanism for changing this, and that pressure needs to include meaningful enforcement rather than occasional high-profile fines that most companies treat as a cost of doing business. Until then, the experience of asking 100 companies for your data will continue to look a lot like what this investigation found.