HAAM
PUBLIC RESEARCH · 2026

Can I have my
data, please?

We are asking companies for the personal data they hold, documenting what actually happens, and building a public benchmark for the lived experience of data rights.

100+services in scope
15 + 20GDPR rights tested
0scores published before audit

The premise

Privacy promises are easy.
Asking for your data is the test.

Privacy research often starts with policies, disclosures, and legal text. This project starts with a person doing something the law says they can do: asking a company what it knows about them.

The result is not intended to be a legal verdict. It is a record of the experience: how easy the right is to find, how much friction appears, what arrives, whether it makes sense, and what happens when things go wrong.

The deeper question

A data request is an organizational X-ray.

A company can have a polished product, reliable operations, and sophisticated analytics while still struggling to answer a basic question: what information do you actually have about me? An access request crosses the seams ordinary product use rarely exposes: identity, internal ownership, legacy systems, vendors, support, legal, and retention. This is a working hypothesis, not a legal conclusion: the quality of request handling may be an externally observable signal of how well an organization understands and governs its own data.

01

Data ownership

Does the company actually know which systems hold data about one person?

02

Internal coordination

Can support, privacy, legal, engineering, and vendors produce one coherent response?

03

Traceability

Do old accounts, acquired systems, inferred data, and historical records remain findable?

04

User agency

Can the company give a person a useful account of data it can already use internally?

05

Operational transparency

Can the organization explain what happened when the normal process breaks?

From the research log

Early case signals

These are documented observations, not final rankings. Each case still follows the repository's evidence and audit rules.

CrunchbaseEscalated

An access request ended with a deleted account

Crunchbase said the user account was permanently deleted while an access-only request was active. The deletion event is documented as a company claim; related effects on company-profile information remain disputed.

Apollo.ioEscalated

Access-only request, deletion response

Apollo.io said it deleted the profile while retaining a suppression record after a request that explicitly excluded deletion. The case is being treated as an access-rights handling failure, not as proof of broader GDPR non-compliance.

RunnaNeeds audit

Export delivered quickly

Runna said the archive was ready two days after the recorded request date. The ZIP has been preserved and still needs a completeness and usability audit before any public score is assigned.

CraftWaiting

Clear commitment and deadline

Craft verified the request by email without demanding identity documents and promised Article 15 information plus a machine-readable Article 20 copy by 13 September 2026.

TantanIncomplete

Support could not provide the data

Customer support said it could not provide data copies and did not provide an alternate privacy route in the reviewed response. The request remains incomplete.

AirtableNeeds audit

A dedicated access report

Airtable's Privacy Center reported that the access request was completed and made an Access Report available for download. The export is preserved locally and still needs a full audit.

Method in development

A score for the experience,
not a courtroom verdict.

The proposed Data Rights Experience Score will measure observable request handling. No company receives a public score until the underlying response has been audited against a frozen methodology.

01

Findability

Can a normal person figure out where to make the request?

02

Friction

How many forms, redirects, emails, and unnecessary steps stand in the way?

03

Verification

Is identity checked proportionately and securely?

04

Speed

How long does acknowledgement, delivery, and completion actually take?

05

Completeness

Does the response cover the personal data and explanatory information requested?

06

Clarity

Can a human understand what was provided and what remains unanswered?

07

Usability

Is the export structured, machine-readable, and useful after download?

08

Follow-up

What happens when something is missing, disputed, or incorrectly routed?

What comes next

From private requests
to public accountability.

The research is still underway. The next release will freeze the scoring methodology, audit completed exports, publish source-backed company pages, and turn the evidence into a comparable index.

Research by HAAM ↗
HAAM Data Rights ResearchEstonia · 2026Evidence before scores.