← THE DISPATCH

ISSUE No. 25 · The Status Quo

Nobody can ask on your behalf

Researchers filed hundreds of privacy requests for real people, as their appointed agent, with the law behind them. Most were ignored. One company asked the agent for its mother's maiden name. The refusal is not a glitch, it is the shape of the thing, and it decides who can actually ask.

You are allowed to send someone. They are not obliged to like it.

The law in several places lets you appoint an authorised agent. You sign something, a service files your privacy requests, and the company is supposed to treat that as coming from you. It is the mechanism every "we delete you from the internet" subscription runs on. Without it, those products do not exist.

A consumer research group tested it. Volunteers appointed them, and they filed the requests by hand, properly authorised, at real companies. In the first pass, more than two hundred requests went out on behalf of real people. Fewer than a quarter got anywhere.

They ran it again, larger: a hundred and twenty-four people, against twenty-one companies you would recognise, retailers and carriers and credit bureaus among them. Some companies said the opt-out did not apply to them. Some demanded extra steps the law does not require. Some processed half of it. Some made the request impossible to submit at all. Plenty simply never replied, and close to a fifth were refused outright.

One company, handed a signed authorisation from a person who wanted their data dealt with, responded by asking the agent security questions. What is your mother's maiden name. What street did you grow up on. It was talking to the wrong entity entirely and could not tell, which is its own kind of answer.

The refusal has a shape, and it is not incompetence

It is tempting to read all that as companies being bad at their jobs. Some of it is. But look at what the refusals have in common and a pattern comes up that is much less flattering and much more useful.

A company that holds a mailing list has no reason to interrogate whoever turns up with a request. There is nothing behind the door worth defending. A company that holds your identity documents, your payment history, your claims file or your application does have a reason, and it is the reason it will state if you ask: it cannot hand your file to somebody claiming to be you.

That is a real duty. It is also extremely convenient. The same sentence that protects you from an impostor keeps out the service you paid to do this for you, and the company never has to decide which of those it meant.

So the friction is not evenly spread. It concentrates exactly where the file is worth having. The places that wave an agent through are the places holding least. The places that put up a wall are telling you, in the only way an intake process can, that there is something behind it.

Even the machine built to do this makes you prove it is you

At the start of this year California switched on a state-run platform for exactly this problem. One request, sent to every data broker registered in the state, free, with real penalties behind it once the compliance date lands: a fine per request, per day, for brokers that ignore it. It is the most serious attempt anyone has made to automate this.

Read the two conditions on it, though.

It covers registered data brokers, and nothing else. Not the app you signed up to, not the platform that screened your job application, not the service holding your messages. Those are outside it entirely.

And to use it you verify your own residency through a state identity gateway. The system built specifically to send requests for you still begins by making you prove, personally, that you are you.

Even the best version of the automated route arrives at the same place the companies did.

What this does to the thing you were about to buy

A removal subscription is a bet that someone else can do your asking. The evidence says that bet fails at the companies that matter most, and the one place it is being made to work is a public platform aimed at a layer these products already crowd. We have been through what that layer is actually worth, and it is the shallow end: names, addresses, relatives, scraped public records. The deep end is your application, your intake form, your chat history, your ID check. No subscription writes to those. It does not know your life, and it could not authenticate as you if it did.

That is not an argument for doing nothing. It is an argument about who has to send the letter.

The asking is the part you get to keep

This looks like bad news. It is not.

If a request only counts when it comes from you, then the request is yours. Nobody can outsource it, which means nobody can mislay it for you either. The reply does not land in a vendor's dashboard where it becomes a green tick and then a renewal notice. It lands in your inbox, in writing, from the company, dated.

That reply is the only thing in this entire process that is evidence. A dashboard counts what was sent. Their own words count what was answered, what was refused, what they admitted keeping and on what ground. The company will not keep that record for you, and now we know it will not accept anyone else keeping it either.

Which leaves you. It was always going to be you.

The record worth keeping. Where is your data? Log who holds it, and what they took from you to let you in. Staying with them? Object to the uses that were never part of the deal: the profiling, the ad targeting, the model training, the sharing. Leaving? Send it yourself, in your own name, and keep what comes back. Start your record →