The Friction Tax: How Tech Companies Use Bureaucracy to Nullify Privacy Rights

AI-generated image · US National Wire
California's CCPA promises data access, but a pattern of 'processing errors' and identity hurdles suggests that for many, the right to know is designed to be exhausted.
OPINION: Data privacy laws are often presented as a victory for the consumer, a legislative shield against the unchecked harvesting of our digital lives. But as any user attempting to actually exercise these rights can tell you, there is a vast chasm between a legal right and a functional one. When the process for exercising a right is intentionally designed to be a burdensome nightmare, the law becomes a hollow promise.
Reporting from Wired and Ars Technica highlights a systemic failure in how companies handle requests under the California Consumer Privacy Act (CCPA). Enacted in 2020, the CCPA grants California residents three primary rights: the ability to opt out of the sale of personal information, the right to request the deletion of that information, and the right to request a copy of the data a company has collected. On paper, this is empowerment. In practice, it is a war of attrition.
Reece Rogers Gear recently tested these protections by filing more than 100 data access requests. While some companies complied—McDonald's, for instance, provided a granular 515-page report detailing app interactions and predictive analytics—the broader experience was defined by friction. Gear described the process as incredibly time-consuming, requiring multiple identity verifications and a scavenger hunt to find the correct filing methods (which companies must list as two options, such as a web form, email, or phone number) within their privacy policies.
More insidious than the bureaucracy is the active misclassification of requests. In several instances, Gear explicitly requested data access and specifically instructed companies *not* to delete any information. Despite this, companies responded by deleting the data anyway, effectively erasing the evidence the user was trying to uncover.
Crunchbase provides a stark example. After Gear emailed a request on August 17 stating, "I am not requesting deletion at this time," a support representative replied two days later confirming the account had been "permanently deleted." While a Crunchbase spokesperson later attributed this to a "processing error" by a member of the customer success team—denying the use of generative AI for the response—the result remained the same: the user's request for transparency was met with a deletion that forced the user to reregister if they wanted an account.
Then there is BeenVerified, a public records database. Gear's experience here was a masterclass in corporate obfuscation. After requesting access on August 19, BeenVerified responded by removing the user's person report, phone number, and email from search results. When Gear corrected them, the company suddenly claimed it could not verify the user's identity—despite having successfully located the user's details just moments prior to issue the deletion. The cycle ended with a representative insisting they had processed an "opt-out request," completely ignoring the original demand for data access.
This is not an isolated series of glitches; it is a pattern. UC Irvine PhD graduate Elina van Kempen, who coauthored *Consumer Beware! Exploring Data Brokers' CCPA Compliance*, noted similar trends while helping place access requests with over 500 data brokers. Van Kempen observed that access requests were frequently met with automatic answers stating the company would "opt you out" or "delete your data." In many cases, these misclassifications left the user with no resolution at all.
When the machinery of compliance is used to thwart the intent of the law, the burden falls entirely on the individual. Ben Winters, director of AI and privacy at the Consumer Federation of America, described this status quo as unacceptable, noting that these failures expose the inherent weakness of policy frameworks that rely on companies to act in good faith.
If the goal of the CCPA was to give users a window into the data silos of Big Tech, companies have responded by frosting the glass and locking the door. When "processing errors" consistently lead to the deletion of requested data, it isn't a mistake—it's a strategy. By exhausting the user into submission, companies ensure that the cost of transparency remains too high for the average person to pay.

