There's a whole other blog post waiting to be written about the intersection between GDPR/CCPA threats and spam.
The first is that they lied about who they were (and lied by omission about the purpose of the email). The ethics of deceiving someone for research are complicated, but should go through an IRB evaluation. Since they avoided the IRB by claiming it was a study about process, they should have avoided the ethics issues from lying in the survey.
They should have been up-front and honest about who they were, and why they were asking the question.
If their research truly requires deceiving the participant (and, I’m not at all convinced that it does), then it needed to be rigorously evaluated by the IRB, which almost certainly should and should have rejected it.
Second, their research makes a demand for a response “without undue delay”, rather than a request. That is also unethical, as it’s misrepresenting the law and implying a response within 45 days is required by law. It is not.
Many of the involuntary subject participants are not subject to the cited provision of the law. As such, demanding a response within the time frame and citing that provision of the law is misleading. Also, the law makes no requirement for a business to respond to such a query within 45 days. The legislative text is here (https://casetext.com/statute/california-codes/california-civ...) and the only 45 day window that exists is for responding to an actual CCPA request, which this query explicitly disclaimed from being. So even if this was a business required to comply with CCPA, they are not required to respond to this query. So, they lied (by implication) to claim that provision of the law approach lied to the business, and lied (explicitly) by claiming the law created a duty to respond to the email within a 45 day period, which it does not.