You Asked 100 Companies for Your Data. Some Just Deleted It Instead.
Key takeaways
- A test of 100 companies found widespread failures in responding to personal data access requests
- Some companies deleted data when asked for it rather than providing access to it
- Many imposed verification burdens with no legal basis, such as notarised identity documents
- GDPR requires data responses within 30 days, but enforcement for individual requests remains inconsistent
Someone at Ars Technica sent data access requests to 100 companies. What they found is the kind of thing that makes you want to audit every privacy settings page you have ever half-heartedly clicked through. Some companies deleted the data instead of providing it. Others sent back useless or incomplete responses. A significant number created procedural obstacles that would have deterred anyone less determined.
Privacy rights, specifically the right to know what data a company holds about you, are enshrined in law across much of the world now. In Europe, the General Data Protection Regulation has given individuals strong rights to access, correct, and erase their data since 2018. California's Consumer Privacy Act offers similar protections in the United States. Brazil, Canada, and a growing list of other countries have passed comparable legislation. On paper, the right to your own data has never been more robust.
In practice, it is chaos.
What the Experiment Found
Sending a data subject access request (or a DSAR, in the jargon) to a company should, in theory, result in the company providing you with a copy of everything it holds about you within a legally mandated timeframe, typically 30 days under GDPR. The Ars Technica experiment found that reality is considerably messier.
Among the 100 companies tested, responses ranged from genuinely comprehensive and prompt to actively harmful. The deletion cases are particularly troubling: if you ask for your data and a company deletes it instead of providing it, you have lost the ability to audit what they had, and potentially lost data you wanted to keep. Whether this happens through incompetence or a deliberate interpretation of privacy law as purely about removal rather than access is hard to say without seeing the internal processes.
Other common failure modes included requests routed to dead-end email addresses, verification processes so burdensome they effectively functioned as deterrents, and responses that provided data in formats so poorly organised as to be meaningless. Several companies required physical notarised identity documents to process a request, a requirement that has no legal basis under most privacy frameworks and serves mainly to make the process inaccessible.
Why Companies Get Away With This
Enforcement of privacy rights, particularly in the United States, remains patchy. The GDPR has teeth: the Irish Data Protection Commission, which handles complaints against many large tech companies, has issued fines running into the hundreds of millions of euros. But individual consumers rarely go through the formal complaint process, partly because it is time-consuming and partly because the consequences of a single non-compliant data request are relatively minor for most people.
Companies rationally calculate that most people who send data requests will not follow up if their first request goes wrong. Building genuinely robust data access infrastructure costs money. If the expected cost of enforcement is low, the business incentive to invest properly in compliance is also low.
This dynamic is particularly pronounced for smaller companies that do not face the same scrutiny as major tech platforms. Big companies like Google and Meta have invested significantly in self-service privacy portals precisely because regulators watch them closely. A mid-sized data broker or loyalty programme is much less likely to have properly designed systems.
What You Can Actually Do
If you want to exercise your data rights effectively, a few things improve your chances. First, send your request in writing and keep a copy with a timestamp. Second, reference the specific legal framework you are invoking, whether that is GDPR, CCPA, or another regulation relevant to your jurisdiction. Third, follow up if you do not receive a response within the legal timeframe, and escalate to your data protection authority if the company fails to comply. In the UK, that is the Information Commissioner's Office. In Ireland, the Data Protection Commission handles many EU complaints.
The gap between privacy law on paper and privacy practice in reality is one of the most underreported tech policy stories of the past few years. The Ars Technica experiment is a useful reminder that the right to your data exists mainly to the extent that you are willing to fight for it.