A Wired reporter tested how well California’s privacy access rights work in practice by sending more than 100 requests to companies for copies of the personal data they held. Ars Technica carried the same account, which describes a process that was often slow, confusing, and in some cases apparently misunderstood by the companies receiving the requests. The legal hook is the California Consumer Privacy Act, which went into effect in 2020. As Wired explains, the law gives California residents several core rights over personal information held by large companies: the right to opt out of the sale of personal information, the right to delete that information, and the right to request a copy of it. The reporter tested the access right only. The mechanics were not simple. According to Wired, companies generally must provide two ways to submit requests, often through a web form, phone number, or email address listed in a privacy policy. After a request is submitted, companies can take up to 45 days to complete it. The reporter said the burden started before any data arrived: finding the correct channel and then verifying identity across different companies took significant time. One response showed how much data a single consumer app account can generate. Wired says McDonald’s returned a 515-page file within days of the request. The report described app interactions in granular detail and included a prediction that the reporter would never stop eating at McDonald’s. The more troubling finding was not simply volume. Wired reports that some companies responded to access requests as if they were deletion requests, even when the author said that was not the request. Others allegedly declined to process requests through a channel that their own privacy policies listed as available. Crunchbase is the clearest example in the provided material. Wired says the reporter emailed an access request to Crunchbase’s privacy address on August 17 and explicitly said the request was not a deletion request. Two days later, according to the account, a support representative said the user account had been permanently deleted. In a follow-up, Crunchbase said the user account was deleted but other data on Crunchbase was not, and that the reporter would need to register again to have an account. Wired says a Crunchbase spokesperson later attributed the incident to a processing error and said the company would proceed with the request. Consumer advocates quoted by Wired were critical of the handling. Ben Winters, director of AI and privacy at the Consumer Federation of America, characterized the examples as evidence of a weak system when privacy rights depend on companies correctly interpreting and executing individual requests. The story is not a statistical audit of the entire privacy market. It is a reported stress test by one California resident across more than 100 companies. But the examples are specific enough to matter for operators: an access workflow that confuses “show me my data” with “delete my account” turns a compliance right into an operational failure. Who benefits: Companies that correctly route and process access requests are less likely to create the kind of confusion Wired described. Who's exposed: Companies that rely on brittle support queues or ambiguous privacy intake forms are exposed to mishandling user requests. The Wired examples suggest the risk is not only slow responses, but taking the wrong action on a user account.