We are asking companies for the personal data they hold, documenting what actually happens, and building a public benchmark for the lived experience of data rights.
Privacy promises are easy. Asking for your data is the test.
Privacy research often starts with policies, disclosures, and legal text. This project starts with a person doing something the law says they can do: asking a company what it knows about them.
The result is not intended to be a legal verdict. It is a record of the experience: how easy the right is to find, how much friction appears, what arrives, whether it makes sense, and what happens when things go wrong.
The deeper question
A data request is an organizational X-ray.
A company can have a polished product, reliable operations, and sophisticated analytics while still struggling to answer a basic question: what information do you actually have about me? An access request crosses the seams ordinary product use rarely exposes: identity, internal ownership, legacy systems, vendors, support, legal, and retention. This is a working hypothesis, not a legal conclusion: the quality of request handling may be an externally observable signal of how well an organization understands and governs its own data.
01
Data ownership
Does the company actually know which systems hold data about one person?
02
Internal coordination
Can support, privacy, legal, engineering, and vendors produce one coherent response?
03
Traceability
Do old accounts, acquired systems, inferred data, and historical records remain findable?
04
User agency
Can the company give a person a useful account of data it can already use internally?
05
Operational transparency
Can the organization explain what happened when the normal process breaks?
From the research log
Early case signals
These are documented observations, not final rankings. Each case still follows the repository's evidence and audit rules.
CrunchbaseEscalated
An access request ended with a deleted account
Crunchbase said the user account was permanently deleted while an access-only request was active. The deletion event is documented as a company claim; related effects on company-profile information remain disputed.
Apollo.ioEscalated
Access-only request, deletion response
Apollo.io said it deleted the profile while retaining a suppression record after a request that explicitly excluded deletion. The case is being treated as an access-rights handling failure, not as proof of broader GDPR non-compliance.
RunnaNeeds audit
Export delivered quickly
Runna said the archive was ready two days after the recorded request date. The ZIP has been preserved and still needs a completeness and usability audit before any public score is assigned.
CraftWaiting
Clear commitment and deadline
Craft verified the request by email without demanding identity documents and promised Article 15 information plus a machine-readable Article 20 copy by 13 September 2026.
TantanIncomplete
Support could not provide the data
Customer support said it could not provide data copies and did not provide an alternate privacy route in the reviewed response. The request remains incomplete.
AirtableNeeds audit
A dedicated access report
Airtable's Privacy Center reported that the access request was completed and made an Access Report available for download. The export is preserved locally and still needs a full audit.
Method in development
A score for the experience, not a courtroom verdict.
The proposed Data Rights Experience Score will measure observable request handling. No company receives a public score until the underlying response has been audited against a frozen methodology.
01
Findability
Can a normal person figure out where to make the request?
02
Friction
How many forms, redirects, emails, and unnecessary steps stand in the way?
03
Verification
Is identity checked proportionately and securely?
04
Speed
How long does acknowledgement, delivery, and completion actually take?
05
Completeness
Does the response cover the personal data and explanatory information requested?
06
Clarity
Can a human understand what was provided and what remains unanswered?
07
Usability
Is the export structured, machine-readable, and useful after download?
08
Follow-up
What happens when something is missing, disputed, or incorrectly routed?
We are not starting from zero
Related work
Access-request research already has a serious history. This project should cite it, learn from it, and make the work easier for the public to see and compare.
The research is still underway. The next release will freeze the scoring methodology, audit completed exports, publish source-backed company pages, and turn the evidence into a comparable index.