Companies Are Deleting Customer Data Rather Than Complying With Access Requests

When consumers invoke data access rights under GDPR, CCPA, and similar regulations, some companies are destroying records instead of handing them over. This exposes enforcement gaps in privacy law and suggests compliance infrastructure is often performative. The companies making these deletions likely calculate that regulatory risk is lower than the operational burden of data retrieval. Privacy regulations, in other words, work only as well as their consequences for violation.