Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Asking a company for a copy of your personal data is not the same as asking it to delete that data or stop selling or sharing it. Yet in a 2026 WIRED account, senior writer Reece Rogers said that after he made more than 100 California consumer access requests, some companies sent deletion-related responses or struggled to handle the request through a channel their own privacy policy listed. One company, McDonald’s, returned a 515-page report.

The reported cases show the gap between having a formal access right and getting a clear response in practice. They are individual examples, not a representative study or a measure of how often companies mishandle requests.

What an access request asks a company to do

An access request asks a company for a copy of personal information it holds about you. It is different from a deletion request, which asks the company to erase information, and from an opt-out request, which asks it to stop selling or sharing information where applicable.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Rogers said he made that distinction explicit in his requests. The WIRED feature describes the process as involving both locating a company’s request channel and verifying identity; it says a response can take as long as 45 days. That timing is the feature’s description, not a substitute for checking current California rules or getting advice about a particular request.

#1 Best Overall
10PCS USB-A Port Blockers with 1 Keys-Removable Type-A Data Protection - Dust & Moisture Resistant Shield for Laptops, PCs, Gaming Devices & Tamper Protection (Blue)
  • 【PROTECT DATA】USB-A data shield k can stop data from being sent from your mobile device without data synchronization function. There is no risk of data leakage or uploading viruses or information leakage in public places. A must-have item for business trips and travel to protect your data
  • 【METAL & ANTI-SLIP DESIGN】Compared with other USB data shields, our key is made of high quality j metal material for added durability, and the USB lock is made of PC material to resist high temperature and prevent damage to internal chips and circuits. The unique anti-slip design makes it easier to insert and remove.
  • 【COMPACT & PORTABLE 】This USB protector is more lightweight and portable, you can even put it in your purse or pocket when you travel.
  • 【STOP IDENTITY THEFT AND MOBILE HACKING】 - Protect data and networks from malware and ransomware; buy this product to fight against hacking and spying
  • 【AFTER-SALE】:If you have any dissatisfaction with the product, please feel free to contact us through the inbox message, we will provide you with satisfactory after-sales service.

What Rogers reported receiving

McDonald’s: a detailed data report

Rogers said McDonald’s sent him a 515-page report. In his account, it detailed interactions with the app and included a prediction about his future engagement. This describes the document he received; it does not establish what every customer’s report contains or summarize the company’s data practices as a whole.

Crunchbase: a deletion notice after an access request

Rogers said he asked Crunchbase for access and expressly said he was not asking for deletion. A company representative reportedly told him his account had been deleted. Crunchbase later characterized the outcome as a processing error and said it would proceed with his original access request.

BeenVerified: a request-type misunderstanding and identity dispute

The feature describes replies focused on removing Rogers’s information from search results, followed by a disagreement about identity verification. Greg Hammond, senior counsel and senior director of compliance at BeenVerified’s parent company, told WIRED that an agent had misunderstood the request. Hammond said refresher training and an audit were planned.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cash App: phone support did not complete the request

Rogers said phone agents did not successfully process his access request, even though the privacy policy listed phone support as an available method. A company spokesperson pointed to in-app access or deletion as a faster way to verify identity. The feature says the spokesperson did not answer a follow-up asking why the phone number appeared in the policy.

Why the examples matter—and what they do not prove

Across the cases, the practical question is not just whether a company publishes a privacy-rights process. It is whether the channel, identity checks, and response line up with the request the person actually made. A deletion notice is not an answer to an access request, and a listed support channel is of limited use if it cannot complete the request.

But Rogers’s more-than-100 requests are a reported count from one journalist’s investigation, not a representative sample. The feature does not establish an industry-wide mishandling rate, and its anecdotes should not be converted into a percentage or a claim about all companies.

Advocates interviewed by WIRED framed the friction as a compliance and resource problem. Mayu Tobin-Miyaji, a law fellow at the Electronic Privacy Information Center, said the cases showed “how potentially little resources the companies are putting toward compliance and making sure that people can have access to their data.” Ben Winters, director of AI and privacy at the Consumer Federation of America, called the situation “not an acceptable status quo.” These are advocates’ interpretations of the reported cases, not a measured finding about companies generally.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to keep an access request distinct

The reporting underscores why it helps to state the request type plainly and keep a record of what happened. These are practical steps for communicating clearly, not a guarantee of a particular legal outcome.

  1. Use the company’s listed privacy-rights channel. Check its privacy policy or rights-request page for the method it says is available, such as a web form, phone, or email.
  2. Name the request you are making. State that you are requesting access to a copy of your personal information. If you are not asking for deletion or opting out of sale or sharing, say so directly.
  3. Complete the identity checks the company requests. Rogers’s account describes identity verification as part of the process. If a channel cannot verify you or complete the request, ask what listed alternative channel can do so.
  4. Keep the request and response together. Save the submission, any confirmation, verification instructions, and the company’s reply. That makes it easier to identify whether the response addressed access, deletion, or an opt-out.

Data minimization as a possible longer-term remedy

Advocates cited in the WIRED feature also pointed to data minimization: collecting and retaining less personal information in the first place could reduce the burden on consumers who later need to find out what a company holds. That is a proposed systemic remedy, not an impact measured by Rogers’s requests.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.