Companies facing data access requests are deleting information instead of disclosing it. The legal architecture built to prevent this is proving as porous as the one it replaced. A researcher's test of 100 firms found deletion presented as compliance while actual disclosure landed behind walls of process failures, unresponsive support channels. Requests that simply vanished into corporate email.
This is not incompetence. It is rational cost accounting. Deleting data costs time and engineering resources. Disclosing it costs the same things plus the exposure of what you actually collect and how you use it. The GDPR handed companies a choice between two expensive options and then failed to make one substantially more expensive than the other.
Safe Harbor was supposed to govern US-EU data flows from 1995 to 2015. Companies ignored it for two decades with minimal consequence because the mechanism for enforcement was distributed across national regulators with mismatched budgets, conflicting priorities. No power to levy coordinated penalties. The system produced so little friction that violation became standard practice. When Safe Harbor finally collapsed, it was not because enforcement worked—it was because one country's court (Austria's) got impatient and sued unilaterally.
The GDPR was explicitly designed to fix this. It created a unified framework, elevated data protection to a fundamental right, and promised penalties that would actually wound corporations. What it did not create was a single enforcement body. Instead it replicated the same distributed, underfunded DPA structure that Safe Harbor relied on, then added 28 separate national regulators with different interpretations and political pressures. The infrastructure meant to enforce privacy law is too fragmented and underfunded to make non-compliance costly.
The infrastructure meant to enforce privacy law is too fragmented and underfunded to make non-compliance costly.
The gap between what the law requires and what companies do is not a bug in the system—it is the system's actual function. You see this pattern everywhere power meets obligation: the law names the standard, funding never arrives to enforce it. The organization that would lose money by complying learns that the alternative costs less. If you are designing a compliance program that requires either transparency or deletion. You know that deletion will face investigation from exactly no one with resources to pursue it, the choice is already made. The GDPR promised to break that cycle. Seven years in, it is running the same playbook.