What a Fast Food App Knows About You
A 515-page document arrived in a journalist’s inbox a few days after they filed a data access request with McDonald’s earlier this month. The report catalogued app interactions in granular detail and included a prediction: this person would never stop eating there. McDonald’s said the quiet part out loud, in writing, formatted as a PDF.
That single report set off a week-long project – more than 100 data access requests filed with major companies, each one leaning on the same law that made the McDonald’s document possible. The California Consumer Privacy Act, which went into effect in 2020, gives California residents three specific rights: the right to opt out of having their personal information sold, the right to have that information deleted, and the right to request a copy of whatever a company has collected on them. What came back from those 100-plus requests ranged from thorough to baffling to, in some cases, legally wrong.

The Law Is Clear. Compliance Is Not.
The CCPA has been on the books since 2020, which means companies have had years to build working pipelines for these requests. Large companies that collect personal data are subject to its provisions – and the law does not leave much room for interpretation on what the three core rights actually mean. You ask for your data, you get your data. You ask for it to be deleted, it gets deleted. You ask them to stop selling it, they stop selling it. The mechanics are supposed to be straightforward.
Supposed to be. Several companies that received access requests responded by deleting the data instead – an action that satisfies one CCPA right while violating another entirely. A request to see your data is not a request to erase it, and conflating the two is not a paperwork error. It means a company received a legally specific request, processed it through whatever internal system handles these things, and produced the wrong outcome. Whether that reflects broken tooling, undertrained staff, or something more deliberate is hard to say from the outside.

Five Hundred Pages of Behavioral Data From a Burger App
The McDonald’s report is the detail that stops you. Five hundred and fifteen pages generated by a fast food app. Not a social media platform with a decade of posts and messages. Not a financial institution tracking spending across categories. A burger app. The volume alone suggests the data collection happening inside consumer-facing applications goes well beyond what most people picture when they imagine “app data.”
App interactions logged in granular detail means timestamps, item selections, session behavior, location data tied to orders, and whatever else gets captured between the moment someone opens the app and the moment they close it. Multiply that by every order, every browse, every abandoned cart, and 515 pages starts to make sense – which is its own kind of unsettling. The prediction that the user would never stop eating there suggests the data isn’t just stored but actively processed into behavioral profiles. McDonald’s is not simply keeping records. It is running models.
That distinction matters more than it might seem. Raw data sitting in a database is one thing. Data fed into a system that produces predictions about your future behavior is another category entirely. The CCPA’s access provisions entitle you to a copy of what’s collected, but a 515-page document raises an immediate follow-up question: does “a copy of your data” include the outputs of models trained on that data? Does the prediction itself count? The law, as written, does not answer that cleanly.
Requesting data from 100-plus companies in a single week is also its own kind of experiment in process friction. Some companies have functional, fast systems – the McDonald’s response arrived within days. Others almost certainly do not, and the variation in response quality across a sample that large would reveal which companies treat compliance as infrastructure and which treat it as an occasional inconvenience to route through legal.
Your Rights, on Paper
The CCPA’s three provisions – opt-out of sale, deletion, and access – were designed to give consumers actual leverage over the data economy rather than just a vague sense of privacy. Access requests in particular are meant to make the invisible visible: you submit the form, a company has to show its work. The McDonald’s report did exactly that, in 515 pages, including a machine-generated verdict on your eating habits.
Filing those requests yourself is legal and free under California law if you’re a California resident dealing with a large company that collects personal data. The friction is real – each company has its own portal, form, or email address, and response times vary – but the right exists. What companies send back, or fail to send back, or accidentally delete instead, is the more complicated question.
Some of those 100-plus requests almost certainly came back empty, or with boilerplate claiming minimal collection, or with documents so vague they communicated nothing. Others probably arrived as dense files full of metadata most people wouldn’t know how to read. A handful, like the McDonald’s response, presumably arrived with enough specificity to be genuinely informative – or alarming, depending on how you feel about a corporation predicting your behavior.

The companies that deleted data instead of providing access created the sharpest legal problem in the set. A deletion request and an access request are distinct rights under the same law, and honoring the wrong one doesn’t count as compliance. It leaves the person who filed the request with neither their data nor any record of what the company held.
McDonald’s, for its part, sent the document. Somewhere in a server, a model looked at years of app behavior and decided you’re a permanent customer. Then it put that in writing and mailed it to you.






