CCPA requests to 100+ companies: some delete data instead

A reporter used the California Consumer Privacy Act (CCPA) to request the personal data that companies hold on them, starting with McDonald's. Filed earlier this month, that request came back a few days later as a 515-page report that detailed the reporter's app interactions in granular detail and predicted the reporter would never stop eating there.
Curious what other companies might have on file, the reporter spent the following week filing more than 100 similar CCPA access requests. Under the CCPA, in force since 2020, three of the law's key provisions are the right to opt out of the sale of personal information, the right to have it deleted, and the right to request a copy of it. The reporter focused only on the last of these, the access right, to see what data collection actually looks like in practice. Most companies must list two ways to file a request, commonly a web form, a phone number or an email address named in their own privacy policy, and can then take 45 days to complete it.
The process itself was, in the reporter's own account, incredibly time-consuming: finding the correct filing method for each company and verifying identity multiple times ate up most of the week. The most exasperating responses fell into two categories: companies that answered an access request with a message about deleting the data instead, despite being told explicitly not to, and companies that refused to process the request through the very method named in their own privacy policy.
Consumer advocates the reporter spoke with were upset about how the requests were handled. Ben Winters, director of AI and privacy at the Consumer Federation of America, called it 'crazy' and said it is 'not an acceptable status quo.' Winters sees the pattern as evidence of the weakness in policy frameworks that rely on companies to act responsibly and in good faith.
The reporter also disclosed, citing WIRED's policies, that generative AI was used only to draft bureaucratic emails and update a tracking spreadsheet during the process, and that the body of the article was written mainly by hand in a scratch notebook.
Key facts
- A CCPA data access request to McDonald's produced a 515-page report a few days later, detailing the reporter's app interactions and predicting the reporter would never stop eating there.
- The reporter then filed more than 100 similar CCPA access requests to other companies over the following week, focusing only on the access right rather than opt-out or deletion.
- Under the CCPA, in force since 2020, most companies must list two ways to file an access request and can take 45 days to respond.
- Some companies responded to access requests with messages about deleting the data instead, despite being told explicitly not to, while others refused to use the filing method listed in their own privacy policy.
- Ben Winters, director of AI and privacy at the Consumer Federation of America, called the pattern 'crazy' and 'not an acceptable status quo,' saying it shows the weakness of policy frameworks that rely on companies acting in good faith.
Why it matters
This turns a specific legal right, meant to let consumers see what a company holds on them, into a live test of how it performs outside a courtroom or a policy paper. The single McDonald's example already makes the scale of the underlying data collection concrete: one access request produced a 515-page report of app interactions, including a prediction about the reporter's future behavior. Repeating that request across 100+ companies turns an anecdote into a pattern, and the pattern in this account is not simply slow responses. It is requests for access being answered with an unrequested deletion, or with a company declining to use the very channel its own privacy policy lists. Ben Winters frames that as the predictable result of a policy framework with no mechanism to check whether companies are complying beyond trusting them to act in good faith.
Who it affects
Anyone in California who deals with a large company that collects personal data is covered by the underlying CCPA access right the reporter exercised here. That covers the 100+ companies contacted, though the account names only McDonald's specifically and does not break down how the rest responded individually. It also speaks to the concerns of consumer advocates such as Ben Winters, director of AI and privacy at the Consumer Federation of America, who points to exactly this kind of evidence as proof that policy frameworks relying on company good faith are not working.
How to use it
Anyone wanting to exercise this same CCPA access right can start with the company's privacy policy: most companies must list two ways to file there, commonly a web form, a phone number or an email address. The account here is a caution: state explicitly that the request is for access, not deletion, since some companies apparently defaulted to deletion regardless of what was asked. Expect to verify identity more than once and to wait as long as 45 days for a response; the reporter's own description of filing over 100 such requests in a week calls the process 'incredibly time-consuming,' largely for those two reasons.
How solid is it
This is one reporter's first-person account, not an independent audit or a peer-reviewed study: it rests on a single person's experience of filing over 100 requests, and only McDonald's is named as a specific example, with no breakdown of how many of the other companies fell into which failure category. The account does not rest on the reporter's word alone, though; it is corroborated by on-record comment from Ben Winters of the Consumer Federation of America, an outside consumer-advocacy group. The piece also carries an AI-use disclosure citing WIRED's policies, saying generative AI was used only for bureaucratic emails and a spreadsheet while the narrative itself was written by hand, a transparency detail relevant to judging the account's own reliability.
Risks and caveats
The account gives no tally of how many of the 100+ companies fell into each failure category, so there is no way from this piece alone to gauge how common these outcomes are beyond the McDonald's example. The practical risk the piece surfaces is direct: someone requesting their data under the CCPA, or a similar access law, may find it deleted instead, the opposite of what they asked for, which forecloses their own ability to see what was collected in the first place. That also raises a question the piece does not resolve: whether a 45-day response window paired with a good-faith compliance model can catch this kind of failure at scale without an outside party running exactly the manual test described here.
“That's crazy. That's not an acceptable status quo.”
— Ben Winters, director of AI and privacy at the Consumer Federation of America