Request for Data from 100 Companies: Some Chose to Delete Instead
Data Access Requests Turn into Deletion Errors for Users at Major Companies
Recent experiences from users seeking data access rights have revealed alarming errors at prominent companies like Crunchbase and BeenVerified. These missteps point to a troubling trend in how organizations handle user privacy requests, particularly when it comes to distinguishing between access and deletion requests.
On August 17, a user submitted a formal request to Crunchbase, a platform renowned for its database on tech startups. The user clearly articulated their intention to exercise data access rights, explicitly asking that no data be erased. However, just two days later, the user received an unexpected response from a Crunchbase representative: “Your account has been permanently deleted from Crunchbase.” The representative’s message completely misunderstood the original request.
After promptly following up to clarify their intentions, the user was informed that while their account had been deleted, some other data remained intact. To regain access, they would need to create a new account. A spokesperson for Crunchbase later attributed the mistake to a “processing error,” emphasizing that the mix-up was not due to AI involvement.
A similar experience unfolded for the user when they contacted BeenVerified on August 19, utilizing its dedicated compliance email for California Consumer Privacy Act (CCPA) requests. The user clearly stated that they were seeking access to their information, not asking for its removal. Yet, two days later, a support representative informed the user about the deletion of their “person report,” overlooking the specifics of the user’s request.
When the user raised concerns regarding the misunderstanding, they were met with a quick denial from the support team, claiming they could not verify the user’s identity. This assertion was particularly perplexing, as the team had previously identified the user’s information in their responses without requiring additional verification.
Editor’s Take
The mishandling of data access requests highlights a critical lapse in privacy practices within tech companies. These errors not only compromise user trust but also raise important questions about the effectiveness of compliance measures. Organizations must prioritize accurate training and robust systems to ensure that user requests are processed correctly, safeguarding both customer rights and brand integrity.
Source: arstechnica.com