The Deletion Delusion: Why Your 'Right to be Forgotten' is a Corporate Suggestion

AI-generated image · US National Wire
When companies treat data access requests as deletion triggers, they aren't just making errors—they are proving that user control over personal information is a myth.
In the cybersecurity world, we talk about the 'permanence' of data. Once your information is ingested into a corporate database, the idea that you can simply pluck it back out or erase it is often a comforting fiction. This is the reality of the 'Right to be Forgotten,' which, in practice, appears to be treated as a suggestion rather than a legal mandate.
Reporting from Ars Technica highlights the systemic failure of these privacy frameworks. As Ars Technica first reported, in a test of 100 companies, Reece Rodgers found that attempting to exercise rights under the California Consumer Privacy Act (CCPA)—which grants the right to opt out of data sales, the right to delete information, and the right to request a copy of collected data—was a gauntlet of confusion and dead ends.
Opinion: From a defender's mindset, the most alarming part of this isn't just the inefficiency; it's the weaponization of 'deletion' to avoid transparency. When a company deletes your account in response to a request for *access* to your data, they aren't doing you a favor. They are destroying the evidence of what they held on you, effectively shutting the door on your ability to audit their surveillance.
Take the case of Crunchbase. According to Ars Technica, Rodgers explicitly told the company, “I am not requesting deletion at this time. Please do not treat this as a deletion request.” Despite this, a Crunchbase support representative informed him that his account had been permanently deleted. While a company spokesperson later attributed this to a “processing error” by a member of the customer success team, the result remains the same: the user's request for transparency was met with a wipe of the account.
Then there is BeenVerified. Ars Technica reports that when Rodgers filed an access request, the company responded by claiming his person report and contact details had already been removed from search results. When Rodgers corrected them, a support representative denied his claim and stated the company could not verify his identity—despite having already located his details in the same thread. The company eventually insisted they had processed an "opt-out request," completely ignoring the original demand for data access.
This isn't an isolated occurrence of corporate incompetence. UC Irvine PhD student and *Consumer Beware! Exploring Data Brokers’ CCPA Compliance* coauthor Elina van Kempen told Ars Technica that in her research involving over 500 data brokers, she encountered multiple misclassifications where access requests were met with automatic answers promising deletion or opt-outs. In many cases, these errors were never resolved.
Ben Winters, director of AI and privacy at the Consumer Federation of America, told Ars Technica that these failures highlight how weak policy frameworks are when they depend on companies acting in good faith. When the entities profiting from your data are the ones tasked with managing your requests to see or delete that data, the system is designed to fail. If companies can 'accidentally' delete an account to avoid providing a 515-page report—like the one McDonald's provided to Rodgers—then the law is not a shield; it is a suggestion.

