#7
Ars Technica Security
general
August 29, 2026 at 10:50 UTC
I asked 100 companies for my data. Some deleted it instead.
By Reece Rodgers, wired.com
AI Summary
A privacy audit of 100 companies found that submitting data access or deletion requests — rights guaranteed under laws like GDPR and CCPA — frequently resulted in confusion, non-responses, or unintended deletion of accounts rather than data. The investigation exposes widespread non-compliance and operational failures in privacy request handling across industries. Security and compliance teams should treat data subject request workflows as a concrete audit target, not just a legal checkbox.
Relevance score: 70.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →