I Asked 100 Companies for My Personal Data. Some Deleted It Instead.
Key takeaways
- Testing 100 companies found that privacy data access requests regularly led to confusion, dead ends, and non-compliance
- Several companies deleted personal data in response to access requests rather than providing it
- GDPR requires companies to provide personal data free of charge within 30 days of a valid request
- Privacy rights function well mainly for persistent, technically literate individuals who are willing to escalate to regulators
Here is a thought experiment that is actually an experiment: what happens if you systematically contact 100 companies and invoke your legal right to access the personal data they hold on you? Ars Technica did exactly this, and the results are a useful snapshot of just how broken the privacy rights ecosystem is in practice, even years after major privacy legislation has been on the books.
The short version: companies are inconsistent, often non-compliant, frequently confusing, and in some cases actively counterproductive. Several companies, when presented with a data access request, deleted the data instead of providing it. That is a significant problem because it defeats the entire purpose of access rights, which are meant to allow individuals to understand what is held about them so they can correct inaccuracies, contest improper processing, or make informed decisions about their relationship with that company.
The Legal Context
Data subject access rights exist in various forms across different jurisdictions. The GDPR in Europe gives individuals the right to a copy of the personal data a company holds on them, free of charge, within 30 days. Similar rights exist under the California Consumer Privacy Act in the US, and several other US states have passed comparable legislation in the years since. In theory, these rights are robust. In practice, exercising them is frequently a maze of awkward forms, unanswered emails, and dead ends.
Ars Technica's investigation tested exactly this gap between theory and practice across a broad sample of companies, spanning tech platforms, retailers, financial services firms, and other categories. The findings included companies that simply ignored requests, companies that provided incomplete data, companies that could not be contacted at all through the required channels, and the particularly alarming group that responded to an access request by deleting the data entirely.
Why Deletion Is the Wrong Response
Deleting data in response to an access request is not the same as honouring a separate deletion request, which is a different right that individuals can also invoke. When a company deletes your data in response to an access request, it may be doing so to avoid the disclosure obligations, to reduce its own liability, or simply because the person handling the request confused the two types of requests. Regardless of the reason, the effect is that the individual never learns what was held about them, cannot verify whether it was accurate, and cannot challenge any improper processing that may have already occurred.
In some jurisdictions this behaviour would itself constitute a breach of data protection law, since the right of access is a legal entitlement and deleting records to avoid fulfilling it could be characterised as obstruction. Whether regulators have the appetite and resources to pursue such cases is a different question.
The Wider Pattern
The investigation is worth taking seriously because it reflects a structural problem rather than a series of isolated failures. Privacy compliance in most companies is handled by small legal or compliance teams who are often working from checklists rather than deep institutional understanding of what the rights actually require. When an access request arrives, the person handling it may have limited guidance, limited training, and limited time.
The result is that privacy rights function reasonably well for people who are persistent, technically literate, and willing to escalate to regulators if necessary, and poorly for everyone else. This is the opposite of how rights are supposed to work. Rights should be easy to exercise by default, not gatekept behind a knowledge barrier.
For anyone reading this who has never tried to exercise their data access rights, it is genuinely worth doing. Start with a company you interact with frequently and that holds significant data about you: a loyalty card provider, a health app, an ad platform, a financial institution. The process is often illuminating even when it works, and even more illuminating when it does not.
The findings from 100 companies are a reminder that the infrastructure of digital privacy rights exists largely on paper. Building it in practice is a project that regulators, companies, and individuals all have a role in, and at the moment, most of that work is still to be done.