I Asked 100 Companies for My Data. I Got Deletion Notices Instead

Staff
By Staff 12 Min Read

For weeks, I had been living with a digital ghost in my pocket, a quietly omnipresent companion that knew the ebb and flow of my cravings with unnerving precision. So, in an act of both curiosity and systematic challenge to the modern data ecosystem, I filed a request with McDonald’s to see exactly what they had assembled about me. I was braced for a dry and technical list of pixels and identifiers, but within days, the reply arrived: a staggering 515-page report, composed not just of simple click logs, but of a dense narrative of my life as seen through the lens of greasy fries and breakfast sandwiches. It detailed my app interactions to the granular level of how long I pondered the menu, and then it did something surreal. At the very end of the document, buried amidst the metadata, a subtle algorithm presented its verdict: it flattered itself by assuming I would never stop coming back, a prediction that felt less like a forecast and more like a pre-ordained fate. The report mapped my habits, my cravings, and my comings and goings with such specificity that for the first time, I felt less like a consumer and more like a closely guarded trophy. I closed my laptop, stared at my streak of drive-thru visits, and realized that this was the true face of the modern loyalty program—not a reward system, but an intimate surveillance and prognostication session. It was this uncanny experience that kicked off a new obsession: wheeling outward to see just what kind of files the rest of the corporate world had compiled on me, tucking me into their massive servers.

Empowered by the California Consumer Privacy Act, which explicitly grants residents the right to know what data is hoarded, I officially became a one-woman privacy audit team. The CCPA offers a robust handful of rights: the right to opt out of the sale of your personal data, the right to wipe those records from existence, and the right to access a copy of what’s actually in your profile. In the spirit of archaeological inquiry rather than existential sanitation, I decided to meticulously focus on the latter—the access requests—and set about assembling a week-long offensive of confidential forensics. I dedicated myself to filing over one hundred requests across every sector: streaming services, fitness trackers, fast food joints, and tech databases simmered in my spreadsheet. Yet, in practice, the experience quickly devolved into a chaotic part-time job. Corporations typically offer two mandated paths for you to file a request: often through a web form or an email dedicated to legal requests. However, the logistical nightmare of initiating these requests—locating the specific portals, patchwork email addresses, and navigating helpf outlining that were buried within legalese—was damnably time-consuming. Once I entered the system, the exhausting 45-day waiting window began, waving me off into an encrypted abyss where my identity would be silently verified and my humanity edited down into an access key. It was a dizzying amount of administrative overhead just to uncover that what I was simply breathing through the connected world.

The worst of that bureaucracy was the obfuscation and the appalling habit of companies misinterpreting the word “access.” My correspondence became a series of correctives and defensive somewhere in the void. In one egregious instance, I reached out to Crunchbase, the technical database that catalogs tech startups, explicitly stating in an email that I was exercising my data access rights over any deletions. I even underlined the direction so they would not miss it. Yet, two days later, a rather cheerful response came back from its compliance team, declaring: “Your account has been permanently deleted from Crunchbase.” My heart lurched. They had wiped my digital identity from existence, destroying the research trail I had wanted to inspect. When I asked for clarification to the company, they blamed a human “processing error” and claimed my actual account had been deleted, while other public data was untouched. This kind of absolute disobedience, the refusal to see beyond a binary of data, and the sheer annoyance of having to “re-register” as if my history meant nothing, resonated as a theme. The circled course was riddled with such roadblocks. Companies would ignore their own privacy policies by refusing to honor the request via the exact web form they promised, or they would reply to my access request with verbose instructions for how to delete my data, completely side-stepping the very concept of information retrieval. These interactions were like digital Rube Goldberg machines, designed to exhaust, frustrate, and ultimately demoralize. I felt less like a person with rights and more like an orphaned user whom they refused to give their own data back, the only for the way they would any version of institutional “moving”.

Such treatment did not sit well with the consumer protection gurus either. When I explained my adventure to Ben Winters, the Director of AI and Privacy at the Consumer Federation of America, and who has spent an entire lifetime fighting pal and right to obscure, his response was flagrantly dissenting. He called out the behavior without hesitation as “crazy” and “refusing to accept the status quo,” highlighting that the current frameworks are built upon optimistic good faith, meaningfully expecting companies to act with ethically gentle discretion. He saw my experience—the laughing at the mistaken deletions, the stubborn refusal to comply after hearing the details—attesting to the failure of those policies. The legislation only matters if the law is enforceable, and even then, the fact that a company will calmly delete a requests rather than admit their response is a fabricated error is nothing short of corporate resistance. The constant state of opportunism became the norm, and this endless series of toe-dipping was suppressing the spirit of regulation. It lacked even the basic “customer success” gesture; it was hostile towards the easiest forms of compliance. It highlighted the sad, fundamental truth of the current digital economics: that we are the most precious, active payload for traffickers all the way through.

To level the ethics, I must be transparent about my own methods folded into this report. I used generative AI (i.e., AI tools) to draft the bureaucratic emails and to update the massive tracking spreadsheet every time a request was sent or needed to follow up. That does not mean I automated the humanity of my voice; I wrote this article primarily by hand in a scratch notebook, feeling for the words as I did a few years ago with a pen. That weekend my days were filled with rewriting requests to allow their clerks to actually understand the words. But when the privacy request reached the mailbox of the searchable public record database, BeenVerified, I was again met with an eerie pattern that almost felt like a challenge. I prepared their dedicated CCPA address with strict instruction that this was not a deletion request, laying out all the rallies clearly. I furiously refreshed my email, knowing I had overlooked no details: I am a California resident, forming a rights request, non-compliance with prior norms. And yet, as a narrative arc closes in on this episode, the same email chain would be the narrative spot where this frustrating story both concludes and becomes a humorous one. But because it’s the same story as before. Like a cyclone of certain digital fashion, it’s telling me that the only thing they have learned about me is that they don’t want me to know it. It’s a simulation of my actual experience: personal data is not merely monetary, but informational architecture that refuses to yield to its own master.

Through this labyrinth of endless confirmations and deleted request, I find that the starkest truth is the sheer asymmetry in the relationship between the company and the consumer. They have highly sophisticated data collection omnipresence, I have an outdated 15-digit request portal that they promptly ignore. The 515-page McDonald’s report that launched this crazy sprint is the most readable documentation I have ever experienced. It gave me the unexpected interest of seeing exactly what your own free market thinks of me. In the end, after filing over 100 requests, I am ending my experiment with the exact taste of exhaustion. The right to demand a copy of the data remains the foundation, but the experience is so massively reactive and thoughtless that it becomes worse than no right at all. I do not give you email address to any company anymore without hesitation. The whole time I was waiting for files, I kept asking myself a base question: What would happen if these companies were forced to hand over information not in the PDF but in a human reading? They want to shield themselves from one thing—the fact that, given the evidence, you will eventually wake up and see the margin of correlation. The system’s current states are finished-the-broken, flawed steps, and the only thing the CCPA has given us is a weapon that we have to reload with our tears and effort to use. The future of privacy demands more simplicity, not less: make the plumbing for access that tracks and walk with purpose.

Share This Article
Leave a Comment

Leave a Reply

Your email address will not be published. Required fields are marked *