cd /news/ai-policy/i-asked-100-companies-for-my-data-so… · home topics ai-policy article
[ARTICLE · art-115058] src=arstechnica.com ↗ pub= topic=ai-policy verified=true sentiment=↓ negative

I asked 100 companies for my data. Some deleted it instead.

A WIRED reporter filed more than 100 data access requests under the California Consumer Privacy Act and found that some companies, including McDonald's, responded by deleting data instead of providing it, despite explicit instructions not to. Ben Winters, director of AI and privacy at the Consumer Federation of America, called the handling 'crazy' and 'not an acceptable status quo,' highlighting weaknesses in policy frameworks that rely on corporate good faith.

read2 min views1 publishedAug 29, 2026
I asked 100 companies for my data. Some deleted it instead.
Image: Arstechnica (auto-discovered)

I filed a request with McDonald’s earlier this month to access all of the personal data the fast food company collected about me, and I received a stunning 515-page report a few days later that detailed my app interactions in granular detail and predicted I would never stop eating there.

Under the California Consumer Privacy Act, I have the legal right to request access to information from large companies that collect personal data. So I was curious what others might have on me, and I spent the next week filing more than 100 requests.

The CCPA went into effect in 2020, and three of its key provisions are the right to opt out of the selling of personal information, the right to delete that info, and the right to request a copy for yourself.

I focused solely on the latter—access requests—to better understand what data is being collected. Most companies must list two ways for you to file. These are often via a web form, phone number, or email address, as designated in their privacy policy. After you submit a request, companies can take 45 days to complete it.

My experience placing these data access requests was incredibly time-consuming, from finding the right filing methods to verifying my identity multiple times. Most exasperating during this process were the companies that either responded to my access requests with messages concerning the deletion of information, which I explicitly said not to do, or refused to process the request through a method listed in their privacy policy.

Consumer advocates I spoke with were upset with how these requests were handled. “That’s crazy,” said Ben Winters, director of AI and privacy at the Consumer Federation of America. “That’s not an acceptable status quo.” Winters sees these examples as exhibiting the weaknesses of policy frameworks that rely on companies to act responsibly and in good faith.

In accordance with WIRED’s policies, I am disclosing that I used generative AI to draft bureaucratic emails and update my tracking spreadsheet as part of this report. I wrote the body of this article mainly by hand in my scratch notebook.

── more in #ai-policy 4 stories · sorted by recency
── more on @wired 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/i-asked-100-companie…] indexed:0 read:2min 2026-08-29 ·