Original briefings. Zero spin.
Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.
Reporter Files 100 Data Requests Under California's Privacy Law. Companies Deleted Accounts Instead of Handing Over Data

The California Consumer Privacy Act says you have a right to see what companies collect on you. A Wired reporter decided to test that right against reality, filing data access requests with more than 100 companies. The results, reported by Wired and separately covered by Ars Technica, show a system that barely works.
McDonald's actually delivered. The reporter got a 515-page report detailing app interactions in granular detail, right down to a prediction that the customer would never stop eating there. Creepy, sure. But at least it's what the law asks for.
Crunchbase did the opposite. The reporter emailed Crunchbase on August 17, explicitly stating: "I am not requesting deletion at this time. Please do not treat this as a deletion request." Two days later, a Crunchbase support rep replied that the account had been "permanently deleted." When the reporter pushed back, Crunchbase said the account was deleted but other data was not, according to Wired's reporting.
That's a company either not reading the request or choosing to nuke the account rather than do the harder work of compiling the data.
Ben Winters, director of AI and privacy at the Consumer Federation of America, didn't mince words when Wired asked him about it. "That's crazy," he said. "That's not an acceptable status quo." Winters noted that the CCPA and laws like it assume companies will act in good faith. When they don't, there's no cop on the beat catching it in real time.
What the Law Actually Promises
The CCPA, in effect since 2020, gives Californians three core rights: opt out of having their data sold, request deletion of it, and request a copy of it. The reporter focused only on the access requests, the third option, specifically to find out what companies actually hold.
Companies are required to list at least two ways to file a request, usually a web form, an email, or a phone number, per their own privacy policies. Once filed, companies have up to 45 days to respond.
In practice, according to Wired, the process was a slog: multiple identity verifications, unclear filing channels, and a pattern of companies routing legitimate access requests into their deletion pipeline instead. Whether that reflects sloppy customer service, an ill-designed automated system, or a preference for erasing a paper trail rather than producing one is not established by the reporting. No regulator has opened an investigation into Crunchbase or any other company named in these two reports, and no claim here should be read as an allegation of intentional misconduct beyond what the companies' own responses show.
The Fair Pushback
Companies handling privacy requests at scale have a real operational problem. Verifying that the person asking for data is actually the account holder, without creating a new security hole, is genuinely hard. Some confusion between "access" and "delete" tickets in a high-volume support queue is a plausible explanation. A reasonable defender of these companies would say Wired's sample of over 100 requests is bound to surface some support-desk errors that don't reflect a systemic pattern of evasion.
That defense only goes so far. The CCPA has been law for six years as of 2026. Companies operating in California have had ample time to build access-request workflows that don't confuse deletion with disclosure. Crunchbase's error wasn't an edge case buried in fine print. It happened after the reporter stated the opposite request in plain English.
Where This Leaves Enforcement
California's privacy apparatus, including the California Privacy Protection Agency, relies heavily on complaints and audits rather than continuous monitoring of every company's request-handling process. That design choice is the crux of Winters' criticism: the law creates a right but puts the burden of catching violations on individual consumers filing requests one company at a time, exactly what Wired's reporter did.
Ars Technica's write-up largely mirrors Wired's own account point for point, since it's drawn from the same underlying reporting. Neither outlet identifies a broader CPPA enforcement action stemming from these specific incidents. That means the fix, if one comes, isn't visible yet. No agency action has been announced tied to the Crunchbase deletion or the other reported failures. Whether California regulators treat a pattern of "we auto-deleted it instead" as a compliance violation worth penalizing, or whether it takes a formal complaint from someone like this reporter to trigger a review, remains an open question.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.