Government Regulations, Security Program Controls/Technologies, Identity, Privacy, Compliance Management

Botched data requests reveal a new headache for security leaders

(Adobe Stock)

Individuals attempting to access their personal data collected by companies are encountering significant challenges and bureaucratic obstacles, often receiving incorrect responses or facing outright refusal, as first reported by Ars Technica.

Consumers exercising their rights under the California Consumer Privacy Act (CCPA) to request access to their personal data are frequently met with misdirected responses, such as deletion notices when data access was requested. Companies like Crunchbase and BeenVerified have mistakenly deleted user data or denied requests, citing processing errors or inability to verify identity. Cash App has also made it difficult for users to exercise their data access rights via phone, directing them back to their website. Consumer advocates express concern that these issues highlight a lack of resources dedicated to CCPA compliance by some companies. Experts suggest that a stronger emphasis on data minimization, where companies collect only necessary data, could alleviate the burden on consumers and improve compliance.

Source: Ars Technica

You can skip this ad in 5 seconds