FTFuture Technology
SECURITY

I Asked 100 Companies for My Data. Some Deleted It Instead

· 3 min read · By Nath Connell

Key takeaways

  • A researcher sent data access requests to 100 companies and found that some deleted data instead of providing it
  • Deleting records in response to an access request rather than sharing them may itself constitute a legal violation under GDPR
  • GDPR has been in force since 2018, giving companies nearly a decade to build compliant data management systems
  • Under GDPR, companies must respond to access requests within one month, with a possible three-month extension for complex cases

Here is a scenario that should not happen: you contact a company, exercise your legal right to receive a copy of the personal data they hold on you, and they respond by deleting the data instead. No copy sent, no explanation, no apology. Just gone.

According to an investigation published by Ars Technica on 29 August 2026, this happened repeatedly across a sample of 100 companies that a researcher sent data access requests to. The experiment was designed to stress-test how well companies are actually complying with data rights laws, and the results were, to put it generously, not reassuring.

How the Experiment Worked

The researcher sent formal data subject access requests (DSARs) to 100 companies, invoking the legal rights available under applicable privacy legislation. In the United States this varies by state, with California's Consumer Privacy Act (CCPA) being the most comprehensive. In Europe, the General Data Protection Regulation (GDPR) gives individuals strong rights to access, correct, and delete personal data.

The findings revealed a spectrum of compliance ranging from genuinely good to genuinely alarming. Some companies responded promptly, sent comprehensive data packages, and explained clearly what they held and why. Others sent nothing at all. A notable subset, the ones that generated the most concern, appeared to interpret a data access request as a deletion request and simply purged the records rather than providing them.

Why Deleting Instead of Sharing Is Such a Problem

At first glance you might think: well, if the data is deleted, is that not a positive outcome? In some narrow sense, perhaps. But it is not what you asked for, and it raises a set of serious issues.

First, it means you have no idea what data the company held on you, which is often the entire point of making the request. People ask for their data to find out what is being held, check it for accuracy, understand how it is being used, and sometimes to use that information in legal proceedings or to understand whether they have been affected by a breach.

Second, deleting data in response to an access request rather than providing it may itself be a legal violation. Under GDPR, deliberately destroying records to avoid providing them is potentially obstruction. Even where laws are less prescriptive, it raises questions about good faith compliance.

The future, in 3 minutes a day. The biggest tech story explained every morning, free. Get the briefing →

Third, and most troublingly, it suggests that some companies do not have proper data management systems in place to distinguish between different types of requests. That lack of infrastructure implies broader data governance problems.

The State of Corporate Data Compliance in 2026

The broader picture painted by this research is of an industry that has had years to get its act together on data rights and has, in many cases, chosen not to. GDPR came into force in 2018. CCPA followed in 2020. Companies have had nearly a decade to build the processes and systems needed to handle these requests properly.

The fact that a researcher can still send 100 requests and come back with a catalogue of confusion, dead ends, deletion errors, and non-responses in 2026 is telling. It suggests that for many organisations, data rights compliance is a tick-box exercise rather than a genuine operational priority.

There are enforcement challenges too. Data protection authorities in Europe have issued significant fines for GDPR violations, but the pace of enforcement has been frustratingly slow relative to the scale of non-compliance. In the US, state-level enforcement is patchy, and there is still no federal privacy law.

What You Can Actually Do

If you want to exercise your data rights, a few practical points are worth knowing. First, send requests in writing and keep records of what you sent and when. This creates a paper trail if you need to escalate. Second, know the response timeframes, under GDPR companies must respond within one month, with a possible extension to three months for complex requests. Third, if a company fails to respond or responds improperly, you can report to the relevant supervisory authority. In the UK that is the Information Commissioner's Office (ICO). In the EU it varies by country.

None of that is as satisfying as simply being able to trust that companies will do the right thing when you ask. But given what this investigation found, it is clearly necessary to approach these requests with some persistence.

Get the briefing, free

The biggest tech story, explained in 3 minutes every weekday. Choose your briefings →

Free. No spam. Unsubscribe in one click.