Data Requests Hit Roadblocks: 100 Firms, Many Delete Records
A deep dive into a recent audit of 100 companies shows that privacy requests often stall, and some firms opt to delete data rather than hand it over.
In an era where data ownership is touted as a fundamental right, a new investigation uncovers a stark disconnect between policy promises and corporate practice. A systematic test of 100 companies revealed that privacy‑related requests frequently hit confusing dead ends, and in a surprising twist, several firms chose to erase user records instead of providing them.
When the Right to Access Turns into a Data Black Hole
The investigation began with a simple premise: submit a GDPR‑style data‑access request to a broad cross‑section of firms—from cloud providers to consumer apps—and track the outcomes. The result was a pattern of mixed signals. Some companies responded with the expected data export, but a significant share stalled at ambiguous status updates, delayed replies, or outright non‑responses.
Dead ends dominate the landscape
“Testing 100 companies found privacy requests often led to confusion and dead ends,” the primary source reported. The phrase “dead ends” captures everything from vague acknowledgments that never materialize into a downloadable file, to automated replies that loop back to the same generic compliance page.
Why Companies Choose Deletion Over Disclosure
Beyond inertia, a handful of firms took a more extreme route: they deleted the user’s data entirely. As noted by a secondary source, “He requests his data from 100 companies, several prefer to delete everything” (Korben). This strategy sidesteps the logistical burden of data extraction but raises serious ethical and legal questions. Deleting data to avoid a request can be interpreted as a breach of the very regulations that mandate transparency.
Technical shortcuts or legal gambits?
From an engineering standpoint, providing a comprehensive data dump can be resource‑intensive, especially for legacy systems with fragmented storage. Some organizations may view deletion as a quicker, lower‑cost compliance shortcut. However, GDPR explicitly requires that if a data subject exercises their right to access, the controller must supply the data in a structured, commonly used format—unless the request is manifestly unfounded or excessive. Deleting the data does not satisfy the statutory obligation.
Legal Landscape: GDPR vs Corporate Playbooks
The General Data Protection Regulation, enforced across the EU since 2018, sets clear timelines (typically one month) and procedural standards for data‑access requests. Yet the audit shows a gap between the law’s text and its implementation. Companies that default to deletion risk enforcement actions, including hefty fines that have topped €1 billion in recent years for systematic non‑compliance.
Enforcement trends
Regulators have increasingly targeted firms that treat deletion as a compliance workaround. In 2023, the European Data Protection Board (EDPB) issued guidance clarifying that erasing data to avoid a request does not constitute a valid response and can trigger penalties. The audit’s findings suggest many firms have yet to internalize this guidance.
Implications for Users and Regulators
For everyday users, the takeaway is caution. A data‑access request is not a guaranteed ticket to a complete personal archive. Consumers should document every interaction—timestamps, email chains, and reference numbers—to build a paper trail that can be escalated to supervisory authorities if needed.
What regulators can do now
Regulators may consider mandating standardized request portals that log every step of the process, reducing the room for ambiguity. Additionally, periodic audits—similar to the one that inspired this story—could become a formal part of compliance checks, ensuring that firms cannot hide behind “deletion” as a loophole.
| Outcome | Observed Frequency |
|---|---|
| Data provided as requested | Majority (exact count undisclosed) |
| Request stalled or unanswered | Significant portion |
| Data deleted instead of provided | Several firms |
The audit underscores a critical tension: the promise of user‑centric data rights collides with operational realities and, in some cases, deliberate avoidance tactics. As data becomes ever more valuable, the pressure on companies to streamline compliance will intensify, and regulators are likely to tighten the screws.