Data Broker Laws in the US New Privacy Rights Consumers Should Know

Data Broker Laws in the U.S.: New Privacy Rights Consumers Should Know

Data has become one of the most valuable commercial assets in the United States. Companies collect information about what people buy, where they travel, what websites they visit, what devices they use, and what products or services they may be interested in. Much of that information does not remain with the company that originally collected it. It can move through advertising networks, analytics companies, data brokers, technology providers, and other third parties.

That increasingly complex data ecosystem has pushed privacy law toward a new question: What rights should consumers have over personal information held by companies they may have never heard of?

Data broker laws are becoming an important part of the answer.

In 2026, U.S. privacy regulation is placing greater emphasis on consumer deletion rights, opt-out mechanisms, sensitive information, precise location data, and the transfer of personal information. California has taken a particularly significant step by launching its Delete Request and Opt-out Platform, commonly known as DROP. The platform allows eligible California residents to send a single request to more than 600 registered data brokers.

At the federal level, the Federal Trade Commission is also increasing scrutiny of data brokers. The agency has warned companies about obligations involving sensitive information and foreign adversaries and has taken action involving the sale and disclosure of precise location data.

For consumers and businesses, these developments signal a broader transformation in U.S. privacy law.

What Is a Data Broker?

A data broker is generally a company that collects personal information from various sources and provides that information to other businesses or organizations.

Unlike a retailer, bank, social media platform, or other company with which a consumer may have a direct relationship, a data broker may obtain information about an individual without ever interacting directly with that person.

A broker might compile information from public records, websites, mobile applications, commercial databases, advertising networks, surveys, purchase information, or other sources.

The resulting profile can contain numerous categories of information.

A consumer’s name and address may appear alongside age, household information, purchase interests, property records, online activity, approximate location information, or other characteristics. When multiple datasets are combined, the resulting profile can be considerably more detailed than any single source of information.

That is one reason lawmakers and regulators are paying closer attention to the data broker industry.

Consumers may understand that a website collects information when they create an account. They may not realize that information can later become part of a much larger commercial data ecosystem.

Legal Journal has previously examined this issue in How Data Broker Laws Are Changing Consumer Privacy Rights, which provides additional background on the development of U.S. data broker regulation.

Why Are Data Broker Laws Becoming More Important?

Traditional privacy rules often focused on the relationship between a consumer and the business that directly collected information.

That model becomes more complicated when personal information is transferred to companies outside that relationship.

Imagine that a consumer provides information to an online retailer. The retailer may use the information for a transaction, customer service, advertising, analytics, or other legitimate business purposes. Some information may subsequently be shared with service providers or other companies.

The consumer may then have little visibility into what happens next.

Data broker regulation attempts to address this problem by placing obligations on companies that obtain, combine, analyze, sell, or otherwise process information outside the original consumer relationship.

The policy goal is increasingly focused on giving individuals more practical control over personal information.

Depending on the applicable state or federal law, that control can include rights to access information, request deletion, correct certain information, opt out of sales or sharing, or limit certain uses of sensitive personal information.

However, there is no single comprehensive data broker privacy law that gives every American identical rights.

The United States continues to rely on a combination of federal laws and state privacy laws.

California’s Data Broker Rules Are Changing the Privacy Landscape

California has emerged as one of the most important states in U.S. data privacy regulation.

The state’s Delete Act created the framework for DROP, the Delete Request and Opt-out Platform. California launched the consumer-facing system in January 2026. Under the program, California residents can submit a single request intended for registered data brokers rather than contacting each company separately.

This is significant because identifying every company that possesses a person’s information can be difficult.

Without a centralized system, a consumer may have to search for individual data brokers, determine whether each company holds information about them, locate a privacy request form, verify their identity, submit a request, and repeat the process.

California’s approach attempts to reduce that burden.

As of August 1, 2026, data brokers are required to begin accessing DROP and processing qualifying deletion requests. The California Privacy Protection Agency states that brokers must access the system at least once every 45 days.

The system is therefore not simply a website where consumers submit a request. It creates an ongoing regulatory process for registered data brokers.

What Is the California DROP System?

DROP stands for Delete Request and Opt-out Platform.

The California Privacy Protection Agency created the platform to allow California residents to submit a centralized request concerning personal information maintained by registered data brokers.

According to the state, consumers can use DROP to send one request to more than 600 registered data brokers.

The system is designed to support both deletion and opting out of the sale or sharing of personal information maintained by covered data brokers.

Consumers must establish that they are California residents. The state uses its California Identity Gateway for eligibility verification.

The system is particularly notable because it changes the starting point for exercising a privacy right.

Instead of asking consumers to determine which data brokers possess their information, the state provides a centralized mechanism that reaches participating registered brokers.

That could make privacy rights substantially easier to use.

When Did Data Brokers Have to Start Processing DROP Requests?

California consumers could begin submitting DROP requests in January 2026.

The major compliance date for data brokers arrived on August 1, 2026.

Beginning on that date, covered data brokers must access DROP and process consumer deletion requests according to the requirements of California law. The California Privacy Protection Agency states that data brokers must access the system at least once every 45 calendar days.

Consumers should also understand that submitting a request does not necessarily mean every record disappears immediately.

The California system explains that status updates can take up to 90 days to appear, depending on the data broker’s processing procedures.

This distinction is important.

A privacy request begins a legal and administrative process. It is not necessarily an instant deletion mechanism.

What Information Can Data Brokers Have?

Data brokers can potentially possess many different types of personal information.

Basic information can include names, addresses, telephone numbers, email addresses, age, and household characteristics.

More detailed datasets can contain information concerning purchases, browsing activity, advertising identifiers, device information, location, property, financial characteristics, or other consumer attributes.

Some categories are considerably more sensitive than others.

The FTC has identified sensitive information under the Protecting Americans’ Data from Foreign Adversaries Act of 2024, or PADFAA, including health, financial, genetic, biometric, geolocation, and sexual behavior information. The law also covers certain account credentials and government-issued identifiers.

The distinction matters because sensitive information can create greater risks when it is sold, transferred, or disclosed.

For example, precise location information may reveal that a person repeatedly visits a healthcare facility, place of worship, workplace, or other sensitive location.

That type of information can potentially reveal intimate details about a person’s life even when the data does not explicitly state what the person was doing.

Precise Location Data Is Receiving Greater Legal Scrutiny

Location data has become one of the most important issues in modern privacy law.

Smartphones, connected vehicles, mobile applications, advertising technologies, and other devices can generate large amounts of location information.

Some location data is necessary for legitimate services. Navigation applications need location information to provide directions. Weather applications may need location information to provide local forecasts. Transportation applications may need it to connect passengers and drivers.

The legal concern arises when location information is collected or transferred for purposes that consumers did not reasonably expect.

In May 2026, the FTC announced a proposed settlement involving data broker Kochava and its subsidiary concerning sensitive location data. The FTC said the companies would be prohibited from selling, sharing, or disclosing sensitive location data without affirmative express consumer consent under the covered circumstances.

The case is an important example of how regulators are approaching location information.

The proposed requirements included a sensitive location data program, supplier assessments, mechanisms for consumers to withdraw consent, and a data retention schedule.

The case demonstrates that privacy compliance can involve more than simply publishing a privacy policy.

Businesses handling location data may need to understand where the information came from, what permissions accompanied it, where it goes, and how long it remains in the company’s systems.

Federal Law Also Restricts Certain Data Transfers

Data broker regulation has increasingly become connected to national security.

The Protecting Americans’ Data from Foreign Adversaries Act of 2024 makes it unlawful for data brokers to make certain personally identifiable sensitive data about U.S. individuals available to designated foreign adversary countries or entities controlled by those countries.

The FTC identifies China, Russia, Iran, and North Korea among the foreign adversaries covered by the law. Sensitive categories include health, financial, genetic, biometric, geolocation, sexual behavior information, account credentials, and certain government-issued identifiers.

The law illustrates an important development in American privacy policy.

Personal information is increasingly viewed not only as a consumer protection issue but also as a national security issue.

Large-scale databases can provide valuable information about individuals and populations. That creates concerns when sensitive American information can be accessed by entities associated with foreign adversaries.

In February 2026, the FTC sent warning letters to 13 data brokers reminding them about their obligations under PADFAA. The agency warned that violations can lead to enforcement action and potential civil penalties.

What Are Consumer Deletion Rights?

Deletion rights allow eligible consumers to ask a business to remove personal information maintained about them.

The exact scope of deletion rights depends on the applicable law.

Some information may be exempt from deletion requirements because businesses need to retain it for legal, security, contractual, accounting, or other recognized purposes.

Consumers should therefore avoid assuming that a deletion request automatically removes every record connected to their identity from every database.

Nevertheless, deletion rights represent a significant change in the relationship between individuals and organizations that hold personal information.

Instead of treating personal information as something a company can retain indefinitely simply because it has been collected, privacy laws increasingly give consumers a mechanism to exercise control over that information.

California’s DROP system takes this concept further by allowing one request to reach many registered data brokers.

Deletion and Opt-Out Are Not the Same Thing

Consumers should understand the difference between deleting information and opting out.

A deletion request generally seeks to have qualifying information removed.

An opt-out request can prevent or limit certain future uses, sales, or sharing practices.

These rights can work together.

For example, a consumer may want a data broker to delete existing personal information while also preventing certain future sales or sharing.

California’s DROP system is designed to address both deletion and opt-out rights for covered data brokers.

This distinction is becoming increasingly important as privacy regulation moves toward ongoing consumer control.

Do All Americans Have the Same Data Broker Rights?

No.

This is one of the most important limitations consumers should understand.

The United States does not currently have one comprehensive privacy law that gives every resident exactly the same data broker rights.

California has developed particularly strong mechanisms, including DROP.

Other states have adopted comprehensive privacy laws or specialized privacy statutes that can provide different rights and obligations.

Some states specifically regulate data brokers, while others approach the issue through broader consumer privacy laws, biometric privacy laws, consumer protection laws, or cybersecurity requirements.

The result is a patchwork system.

A California resident may have access to a particular deletion mechanism that is not available to a resident of another state.

Similarly, a business may have different compliance responsibilities depending on where its customers live and what type of information it processes.

For national companies, this can create substantial compliance complexity.

Texas Takes a Different Approach

Texas provides an example of a state-specific data broker framework.

The Texas Data Broker Act applies to certain businesses whose principal source of revenue comes from collecting, processing, or transferring personal data that they did not collect directly from the individual.

The Texas Attorney General explains that covered businesses must register with the Texas Secretary of State, disclose that they are data brokers, maintain comprehensive information security safeguards, and meet other requirements.

The Texas framework is different from California’s centralized consumer deletion system.

This illustrates why consumers and businesses need to look at the law applicable to the particular state and activity rather than assuming that one privacy rule applies nationwide.

Why Businesses Should Care About Data Broker Laws

Why Businesses Should Care About Data Broker Laws

Data broker regulation is not limited to data brokers themselves.

Many businesses purchase, license, receive, analyze, or otherwise use information obtained from third parties.

An advertising company might use audience data.

A retailer might use demographic information.

A financial business might use identity information.

A technology company might use third-party information for analytics.

An AI company could potentially use large datasets for training, personalization, testing, or automated decision-making.

These relationships create legal questions about data provenance and consumer rights.

Businesses should know where information came from, whether the supplier had appropriate rights to provide it, whether sensitive data is included, and what obligations apply if a consumer requests deletion or opts out.

Data contracts are becoming increasingly important because privacy responsibilities can extend through multiple layers of a data supply chain.

Data Broker Laws and Artificial Intelligence

Artificial intelligence adds another layer to the privacy debate.

AI systems can analyze enormous amounts of information and identify relationships or patterns that might not be obvious to a human reviewer.

A collection of seemingly ordinary data points can become much more revealing when analyzed together.

For example, information about shopping behavior, location patterns, device usage, demographics, and online activity could potentially be used to create predictions about an individual.

That does not mean every AI use of consumer data is unlawful.

It does mean that companies using third-party data for AI applications should carefully consider privacy obligations.

Businesses should also consider whether information used to train, test, or operate AI systems is subject to deletion or opt-out requests.

This issue is likely to become increasingly important as companies integrate AI into advertising, fraud detection, personalization, hiring, financial services, healthcare, and other industries.

Legal Journal’s coverage of [AI Copyright After Thaler: Why Human Authorship Still Matters in 2026] demonstrates how rapidly AI-related legal issues are developing. The privacy implications of AI represent another major area where businesses need to monitor evolving U.S. law.

What Should Consumers Do to Protect Their Information?

Consumers can take several practical steps to reduce unnecessary exposure of personal information.

The first is to understand what information applications and websites collect.

Privacy settings should be reviewed periodically rather than treated as a one-time decision.

Consumers should also pay particular attention to location permissions, advertising identifiers, contact access, and other permissions that may provide applications with information beyond what is necessary for their primary function.

People should also be cautious when providing sensitive information to unfamiliar companies.

A business requesting a Social Security number, precise location information, financial information, or other sensitive data should have a legitimate reason for collecting it.

Consumers may also want to investigate whether their state provides privacy rights that allow them to request access, deletion, correction, or opt-out from certain data practices.

California residents have a particularly direct option through DROP.

The official California platform allows eligible residents to submit a centralized request to registered data brokers.

How California Consumers Can Use DROP

California residents who want to exercise their data broker rights can access the official DROP system operated by the California Privacy Protection Agency.

The process begins with eligibility verification.

Consumers then provide information that can help data brokers identify their records. The state explains that providing additional identifiers can increase the likelihood of matching information held by brokers.

Consumers should also understand the timing.

Data brokers began processing DROP requests on August 1, 2026, and must access the system at least every 45 days. Status information can take additional time to appear for consumers.

Consumers can use the official [California DROP platform] to submit a request and monitor the status of their deletion requests.

What Happens After a Consumer Requests Deletion?

A deletion request generally requires the business to determine whether it maintains information that matches the consumer’s request.

California’s DROP system uses hashed identifiers to facilitate matching while limiting the exposure of the raw information provided by consumers. The California Privacy Protection Agency explains that data brokers download consumer deletion lists and match those identifiers against their records.

Once a covered match is identified, the broker must follow the applicable deletion requirements.

There can still be exceptions.

Certain information may be exempt from deletion under applicable law, and not every data broker will necessarily possess information about every consumer.

This is why consumers should view privacy rights as an ongoing process rather than expecting a single request to eliminate every piece of information connected to their identity.

Data Minimization Is Becoming More Important for Businesses

One of the strongest privacy practices businesses can adopt is data minimization.

If a company does not need a particular category of information, there may be little reason to collect it.

If information is no longer needed, retaining it indefinitely can create unnecessary legal and security risks.

A business holding large quantities of sensitive data may face greater exposure if the information is stolen, improperly disclosed, transferred to another company, or used for purposes that consumers did not expect.

Data minimization can therefore serve both privacy and cybersecurity objectives.

Companies should consider whether they have appropriate retention periods, access controls, vendor agreements, deletion procedures, and data inventories.

The FTC’s Kochava settlement illustrates the growing importance of retention controls. The proposed order included a data retention schedule requiring deletion of covered information according to established timeframes.

Privacy Policies Alone May Not Be Enough

Privacy Policies Alone May Not Be Enough

For years, privacy compliance often focused heavily on disclosures.

Companies published privacy policies explaining what information they collected and how it might be used.

Privacy policies remain important, but modern privacy regulation increasingly focuses on what companies actually do.

A company may have a detailed privacy policy but still face regulatory scrutiny if its actual data practices are inconsistent with consumer expectations or applicable law.

The growing importance of deletion mechanisms, opt-out tools, consent requirements, data retention policies, and vendor controls reflects this shift.

Businesses should therefore treat privacy as an operational function rather than simply a legal document.

What the Future of Data Broker Regulation May Look Like

The U.S. data broker industry is entering a period of significant legal change.

California’s DROP program provides a major test of whether centralized privacy rights can make consumer control more practical.

The state’s experience may influence future legislation in other states.

If consumers successfully use centralized deletion mechanisms, other jurisdictions may consider similar systems.

Federal regulators are also likely to continue focusing on sensitive information.

The FTC’s actions involving precise location data and its enforcement efforts under PADFAA demonstrate that regulators are looking beyond traditional privacy disclosures and examining how sensitive information moves through commercial networks.

Artificial intelligence will likely make this issue even more important.

As businesses use AI to analyze larger datasets, the consequences of collecting and combining personal information may increase.

The legal question may therefore shift from simply asking, “What data does this company have?” to asking, “What can this company infer, predict, or determine from the data it has?”

That distinction could become central to future U.S. privacy law.

Frequently Asked Questions About U.S. Data Broker Laws

What is a data broker?

A data broker is generally a company that collects personal information from various sources and provides that information to third parties for commercial or other purposes. The exact legal definition varies by jurisdiction.

Can I make a data broker delete my information?

Potentially. Your rights depend on the state where you live and the law that applies to the data broker. California residents have access to the DROP system, which provides a centralized mechanism for requesting deletion from registered data brokers.

What is California DROP?

DROP stands for Delete Request and Opt-out Platform. It allows eligible California residents to submit one request to more than 600 registered data brokers concerning deletion and certain opt-out rights.

When did California data brokers have to start processing DROP requests?

Covered data brokers began processing DROP requests on August 1, 2026. They must access the system at least once every 45 days.

Does the United States have one national data broker privacy law?

No. U.S. data broker regulation consists of federal laws and a growing collection of state privacy and data broker laws. Consumer rights can therefore vary significantly by state.

Does federal law restrict data brokers from selling sensitive information?

Yes, in certain circumstances. PADFAA prohibits data brokers from making certain personally identifiable sensitive data about Americans available to designated foreign adversaries or entities controlled by them.

Why is location data so important?

Precise location information can reveal detailed patterns about a person’s movements and may expose visits to sensitive locations. The FTC’s 2026 action involving Kochava demonstrates the regulatory attention being given to sensitive location data.

Can businesses outside the data broker industry be affected?

Yes. Companies that purchase, license, receive, analyze, or share information obtained from data brokers may need to evaluate privacy, contractual, security, and consumer-rights obligations.

Final Thoughts

Data broker laws are becoming one of the most important parts of the evolving U.S. privacy landscape.

For consumers, the biggest development is the growing ability to exercise meaningful control over information held by companies with which they may never have had a direct relationship.

California’s DROP platform represents a particularly important development because it allows eligible residents to submit a centralized request to hundreds of registered data brokers.

At the federal level, PADFAA places restrictions on certain transfers of sensitive American information to foreign adversaries, while the FTC’s enforcement activity demonstrates increasing scrutiny of sensitive location data and other privacy practices.

For businesses, the message is equally important.

Privacy compliance can no longer be limited to maintaining a privacy policy. Companies increasingly need to understand their data supply chains, vendor relationships, consent practices, retention policies, deletion procedures, and security controls.

As artificial intelligence and data-driven technologies continue to expand, personal information will become even more valuable—and potentially more sensitive.

The future of U.S. privacy law is likely to involve greater transparency, stronger consumer control, more regulation of sensitive information, and increasingly sophisticated rules governing how personal data moves through the economy.

For consumers and businesses alike, understanding data broker laws is becoming an essential part of navigating the modern digital economy.

Important legal disclaimer: This article is intended for general educational and informational purposes and does not constitute legal advice. Privacy rights and obligations can vary based on state law, the type of information involved, the parties handling the information, and other circumstances. Consumers and businesses with specific legal questions should consult a qualified attorney.

Share

RECENT ARTICLES

Software Patents and Generative AI: What Developers and Companies Need to Know

Software Patents and Generative AI: What Developers and Companies Need…

Software Patents and Generative AI: What Developers and Companies Need to Know Generative artificial intelligence is changing the way…

Data Broker Laws in the U.S.: New Privacy Rights Consumers Should Know

Data Broker Laws in the U.S.: New Privacy Rights Consumers…

Data Broker Laws in the U.S.: New Privacy Rights Consumers Should Know Data has become one of the most…

Domain Name Disputes and Cybersquatting: How Brands Can Fight Impersonation Sites

Domain Name Disputes and Cybersquatting: How Brands Can Fight Impersonation…

Domain Name Disputes and Cybersquatting: How Brands Can Fight Impersonation Sites A domain name can become one of a…

Scroll to Top