The Daily Signal
Technology

100 Companies — Data Requests Met With Deletion

Holt·Sunday, August 30, 2026 Edition
The Same Dysfunction, Rebranded

Companies facing data access requests are deleting information instead of disclosing it. The legal architecture built to prevent this is proving as porous as the one it replaced. A researcher's test of 100 firms found deletion presented as compliance while actual disclosure landed behind walls of process failures, unresponsive support channels. Requests that simply vanished into corporate email.

This is not incompetence. It is rational cost accounting. Deleting data costs time and engineering resources. Disclosing it costs the same things plus the exposure of what you actually collect and how you use it. The GDPR handed companies a choice between two expensive options and then failed to make one substantially more expensive than the other.

Safe Harbor was supposed to govern US-EU data flows from 1995 to 2015. Companies ignored it for two decades with minimal consequence because the mechanism for enforcement was distributed across national regulators with mismatched budgets, conflicting priorities. No power to levy coordinated penalties. The system produced so little friction that violation became standard practice. When Safe Harbor finally collapsed, it was not because enforcement worked—it was because one country's court (Austria's) got impatient and sued unilaterally.

When Fines Don't Matter

The GDPR was explicitly designed to fix this. It created a unified framework, elevated data protection to a fundamental right, and promised penalties that would actually wound corporations. What it did not create was a single enforcement body. Instead it replicated the same distributed, underfunded DPA structure that Safe Harbor relied on, then added 28 separate national regulators with different interpretations and political pressures. The infrastructure meant to enforce privacy law is too fragmented and underfunded to make non-compliance costly.

The infrastructure meant to enforce privacy law is too fragmented and underfunded to make non-compliance costly.

The gap between what the law requires and what companies do is not a bug in the system—it is the system's actual function. You see this pattern everywhere power meets obligation: the law names the standard, funding never arrives to enforce it. The organization that would lose money by complying learns that the alternative costs less. If you are designing a compliance program that requires either transparency or deletion. You know that deletion will face investigation from exactly no one with resources to pursue it, the choice is already made. The GDPR promised to break that cycle. Seven years in, it is running the same playbook.

Related Stories
Insight
When Did Thinking Start Feeling Like Winning?
Motivated reasoning mimics careful thought so closely that the only way to catch it is to stop asking whether you're right and start asking what you'd need to b
Sports
Tottenham spent 1.5 billion, still chasing trophies since 2014
Tottenham's £1.5 billion spending spree has failed to produce trophies because the club cycles managers every two years, erasing institutional memory before it
Science
Lab Roaches Fail in Rubble Like Brazil's Mosquitoes Failed
Cyborg roaches with implanted electrodes seem reliable in the laboratory but face the same collapse when deployed into real disaster sites as genetically modifi
More From Today's Edition
Comics
Saga and Nimona Unlocked Permission for Villains
Two graphic novels—Brian K. Vaughan and Fiona Staples' Saga and ND Stevenson's Nimona—proved that young readers will follow morally compromised protagonists if
Film
Did Van Peebles time New Jack City for the Rodney King moment
Mario Van Peebles' 1991 crime film arrived days after the King beating, but the real story is not coincidence—it is precedent. Spike Lee's earlier films establi
View Past Editions >