The easiest way to misunderstand a data profile is to imagine it contains only things you personally typed into a form.
A real profile may be much stranger.
It can contain facts you volunteered, records acquired from other sources, device identifiers, inferred interests, household links, marketing segments, and internal labels you never saw.
That is why a data access request can be useful.
It turns an invisible profile into something inspectable.
Access can reveal the difference between supplied and inferred data
California’s current privacy guidance describes a consumer’s right to know what personal information covered businesses have collected and how they use and share it. See CalPrivacy’s CCPA FAQ.
Depending on the applicable law, company, and request, an access response may include categories or specific pieces of personal information, sources, purposes, or disclosures.
The most interesting comparison is often between what the person remembers supplying and what the company has assembled.
For example:
- Volunteered: name, shipping address, email.
- Observed: pages viewed, purchases, devices used.
- Acquired: demographic or commercial attributes from another source.
- Inferred: likely interests, household status, audience segment, predicted preference.
Those categories have different evidentiary meanings.
An inference is not automatically a fact merely because it appears in a company database.
The response can expose errors too
A profile might contain an outdated address, a device belonging to another household member, a purchase made as a gift, or an interest category inferred from one accidental click.
Without access, those errors can remain invisible while still influencing advertising, personalization, or other systems.
This connects directly to the data-broker problem. The Federal Trade Commission’s 2014 data broker report documented how brokers combine information from many sources into composite profiles and derive additional classifications from those records.
Access provides one way to inspect the result instead of merely guessing what the system knows.
An access response is not necessarily the whole backend
There are important limits.
Legal rights vary by jurisdiction. Exceptions can apply. Security-sensitive material may be withheld. A company may describe categories rather than expose every internal model. Data held by a separate company may require a separate request.
And a response from one organization does not reconstruct every copy that has already moved through the advertising or broker ecosystem.
So an access request should not be treated as a magical database dump.
It is evidence about a specific organization’s records and obligations at a specific time.
That is still valuable.
The Surveillance Economy is difficult to evaluate when every profile is hypothetical.
Access rights can turn at least part of the hypothesis into a document.
