How Data Broker Laws Are Changing Consumer Privacy Rights

How Data Broker Laws Are Changing Consumer Privacy Rights

Data brokers operate largely behind the scenes of the digital economy. These companies collect, organize, analyze, and sometimes sell information about consumers, often without having a direct relationship with the people whose information appears in their databases. The information may include shopping habits, contact details, online activity, location information, financial characteristics, and other personal data.

For years, consumers had limited practical control over this ecosystem. That situation is changing.

A growing combination of state privacy laws, specialized data broker rules, federal restrictions, and regulatory enforcement is giving Americans stronger ways to understand how their information is used, request deletion, opt out of certain disclosures, and challenge the handling of particularly sensitive information.

California’s new Delete Request and Opt-out Platform, commonly known as DROP, represents one of the most significant developments. California consumers can submit a single request aimed at registered data brokers rather than contacting brokers individually. Registered brokers became required to begin processing qualifying DROP deletion requests on August 1, 2026, at least once every 45 days.

At the federal level, regulators are also focusing closely on sensitive data. In February 2026, the Federal Trade Commission reminded data brokers about obligations under the Protecting Americans’ Data from Foreign Adversaries Act of 2024. The law restricts data brokers from providing certain sensitive data about Americans to designated foreign adversaries or entities controlled by them.

Together, these developments show a shift in U.S. privacy law. Regulation increasingly focuses not only on companies that collect information directly from customers but also on businesses that obtain personal information indirectly and build products around it.

What Is a Data Broker?

A data broker generally collects personal information about individuals with whom the company does not have a direct consumer relationship and then uses, licenses, analyzes, shares, or sells that information for commercial purposes.

The business model is different from a traditional retailer.

A consumer knowingly gives an online store information when creating an account or making a purchase. A data broker, by contrast, may obtain information from numerous external sources and combine those records into a detailed profile.

Those sources may include public records, mobile applications, websites, advertising networks, surveys, commercial databases, purchase information, and other providers.

The resulting profile can potentially reveal far more than any single source.

For example, separate data points about a person’s approximate age, purchases, interests, location history, property, household composition, or online activity can become more revealing when combined.

This aggregation is one reason data broker regulation has attracted significant attention from legislators and regulators.

Consumers may understand that a specific application or retailer collects data. They may have much less awareness that information can move into an ecosystem of businesses they have never heard of.

That information can then influence advertising, marketing, fraud prevention, research, identity verification, analytics, and other commercial activities.

The central privacy concern is therefore not merely that information exists. It is that consumers may have little visibility into where it travels and what happens after it leaves the business with which they originally interacted.

Data Broker Laws Are Moving Privacy Toward Consumer Control

Modern U.S. privacy laws increasingly try to give individuals greater control over personal information.

Depending on the applicable law, consumers may have rights involving access, deletion, correction, portability, and opting out of certain sales, sharing arrangements, or targeted advertising practices.

Data broker laws add another dimension.

Instead of regulating only the original business that collected information, these laws can impose obligations on downstream companies that acquire information about people they do not directly serve.

This approach addresses a major weakness of older privacy models.

A consumer can change privacy settings on an application and still have personal information circulating through databases that received the information earlier or obtained similar data elsewhere.

Data broker rules increasingly try to reach those downstream databases.

California’s DROP system illustrates how the regulatory approach is evolving. The official California platform allows qualifying residents to request deletion of personal information from registered data brokers through a centralized process. The platform also facilitates an opt-out from the sale or sharing of information maintained by those brokers.

That is a meaningful change in how privacy rights can function in practice.

California’s Delete Act Changes the Deletion Process

California has become an important testing ground for data broker regulation.

Before centralized deletion, consumers seeking to remove information from multiple brokers could face the burden of finding individual businesses, locating privacy request pages, completing different forms, verifying identities, and repeating the process many times.

The California Delete Act created a more centralized approach.

Through DROP, California residents can submit a deletion request intended for registered data brokers using one state platform. California explains that consumers can provide identifying information to improve the likelihood that brokers can match their records to the request.

The system became available to consumers in January 2026. Registered data brokers became responsible for beginning to process qualifying DROP requests on August 1, 2026. They must process deletion requests through the platform at least once every 45 days.

This development transforms deletion from a potentially fragmented process into something closer to a centralized privacy control.

The approach may also influence future privacy policy outside California. Legislators in other jurisdictions can observe whether centralized deletion reduces friction and increases consumer participation.

What Information Can Data Brokers Hold

What Information Can Data Brokers Hold?

The phrase “personal information” can cover a wide range of data depending on the law involved.

Basic identifiers can include names, addresses, email addresses, telephone numbers, dates of birth, and similar information.

Other information can be far more sensitive.

The Federal Trade Commission states that personally identifiable sensitive data covered by the Protecting Americans’ Data from Foreign Adversaries Act includes categories such as health, financial, genetic, biometric, geolocation, and sexual behavior information. It can also include account credentials and government-issued identifiers.

Location information has received particular scrutiny because repeated location points can reveal patterns about people’s lives.

A location dataset may indicate that a device repeatedly appears near a workplace, residence, healthcare facility, place of worship, school, or other sensitive location.

The FTC’s 2026 Kochava matter illustrates the regulatory concern. The agency alleged that precise location information could reveal consumer movements, including visits to healthcare facilities and places of worship. Under the proposed settlement announced in May 2026, Kochava and its subsidiary faced restrictions on selling or sharing sensitive location data without affirmative express consumer consent in covered circumstances.

That enforcement action demonstrates why privacy regulation increasingly distinguishes ordinary information from sensitive information.

Knowing someone’s general interests is one thing. Having access to a detailed history of physical movements can create substantially different risks.

Precise Location Data Is Becoming a Major Privacy Issue

Smartphones and connected devices have made location information commercially valuable.

Applications may collect location data for navigation, weather services, advertising, analytics, transportation, retail services, or other functions.

The privacy issue can become more complicated when data moves beyond the service that originally collected it.

The FTC has repeatedly focused on the commercial handling of precise location information. In the 2026 Kochava settlement announcement, the agency stated that the proposed order would restrict the selling, licensing, transferring, sharing, or disclosure of sensitive location data without affirmative express consent under the covered circumstances.

The proposed requirements also included a sensitive location data program, supplier assessments, consumer withdrawal mechanisms, and data retention measures.

For consumers, this trend could mean stronger expectations around meaningful consent.

A person accepting location access for one application feature may not expect the same information to become available for unrelated downstream purposes.

Privacy regulators increasingly examine that distinction.

Federal Law Is Targeting Transfers to Foreign Adversaries

Data broker regulation is not only a traditional consumer privacy issue. National security has become part of the discussion.

The Protecting Americans’ Data from Foreign Adversaries Act of 2024 restricts data brokers from making certain sensitive information about Americans available to designated foreign adversaries.

In February 2026, the FTC sent warning letters to 13 data brokers concerning compliance with the law. The agency explained that the covered foreign adversaries include China, Russia, Iran, and North Korea, along with entities controlled by those countries.

The FTC also emphasized that the law reaches categories including health, financial, genetic, biometric, geolocation, sexual behavior, account credentials, and government identification information.

This creates a different kind of privacy framework.

Traditional privacy laws often focus on what businesses tell consumers, whether people can opt out, and how companies respond to deletion requests.

Federal restrictions involving foreign adversaries focus more directly on where sensitive American data can go.

The two approaches increasingly overlap.

A database containing detailed personal profiles can raise consumer protection concerns domestically while also creating national security concerns if sensitive information becomes accessible to certain foreign entities.

Consumers can review the Federal Trade Commission’s privacy and security resources for information about federal privacy enforcement and business responsibilities.

The Meaning of Consumer Consent Is Becoming More Important

One of the central questions in modern data privacy law is what counts as meaningful consent.

A company may claim that a consumer agreed to certain data practices through an application permission, privacy policy, account setting, or contractual term.

Regulators may examine whether that consent actually covered the later use or disclosure.

The FTC’s Kochava case demonstrates this distinction. The agency alleged that consumers were unaware of certain location-data sharing and lacked a meaningful way to avoid the resulting privacy concerns.

The proposed settlement placed affirmative express consent at the center of future covered disclosures involving sensitive location information.

This trend can affect the entire data supply chain.

Businesses purchasing datasets may increasingly need to understand where the information originated and what permissions accompanied it.

Data brokers may need stronger information from suppliers concerning consumer consent.

Application developers may face closer scrutiny over disclosures explaining what happens to data after collection.

Advertisers and analytics companies may need to evaluate whether their downstream uses fit within the original permissions.

Privacy compliance therefore increasingly extends beyond posting a privacy policy.

 

Consumers Are Gaining Stronger Deletion Rights

Consumers Are Gaining Stronger Deletion Rights

Deletion rights represent one of the clearest changes in modern U.S. privacy law.

The concept sounds straightforward. A consumer asks a business to erase personal information.

In practice, deletion can become complicated because information may exist across numerous systems, backups, service providers, contractors, analytics platforms, and outside data brokers.

Data broker laws attempt to address at least part of this problem by expanding deletion beyond companies with direct consumer relationships.

California’s DROP program specifically states that participating consumers can request deletion of non-exempt personal information maintained by registered data brokers in covered circumstances.

Some information remains outside the reach of a particular deletion request because statutory exemptions can apply.

Privacy rights therefore should not be interpreted as a guarantee that every reference to an individual disappears from every database.

Still, centralized deletion represents a substantial shift.

Consumers previously faced a discovery problem before they could even exercise a right. They needed to know which broker held the data.

A centralized system reduces that obstacle by allowing one request to reach registered brokers covered by the system.

Opt-Out Rights Are Becoming Easier to Exercise

Deletion and opting out are related but different.

Deletion concerns removing information that a company already maintains.

Opt-out rights can affect certain future uses, sales, or sharing of personal information.

Modern privacy laws increasingly try to give consumers both types of control.

California’s DROP platform is designed not only to facilitate deletion but also to support opting out of the sale or sharing of personal information maintained by registered data brokers.

That distinction matters because a one-time deletion may have limited value if the same company can immediately obtain the information again and resume selling it.

Effective consumer privacy therefore increasingly involves ongoing control rather than a single transaction.

This concept could shape future state legislation.

Instead of requiring individuals to repeatedly discover brokers and submit separate requests, lawmakers may look toward systems that maintain consumer preferences across the data ecosystem.

Data Broker Registration Is Increasing Transparency

Another regulatory approach involves data broker registries.

Registration laws require certain brokers to identify themselves to regulators and provide specified information about their business practices.

This can improve transparency because consumers previously had few practical ways to identify companies holding information about them.

The existence of a registry can also give regulators a clearer picture of the industry.

Registration does not necessarily prevent data collection or data sales by itself. Its value lies partly in identifying businesses that operate within the market and creating a regulatory point of contact.

California’s centralized deletion system builds upon that concept.

A deletion system covering registered brokers becomes more workable when the state already has a formal registry showing which companies fall into the regulated category.

The combination of registration and centralized consumer rights may become an important model in U.S. privacy regulation.

Businesses That Are Not Data Brokers May Still Be Affected

Data broker regulation does not concern only companies traditionally described as brokers.

Other businesses interact with the data broker ecosystem.

A retailer may purchase demographic information.

An advertiser may license audience segments.

A fraud prevention company may use identity data.

An application developer may provide information to analytics or advertising vendors.

A financial company may buy information used for verification or risk analysis.

Each relationship creates privacy questions about where information originated, whether the supplier had appropriate rights to provide it, whether sensitive categories are involved, and whether consumer deletion or opt-out requests need to flow through the relationship.

Businesses increasingly need to understand their data supply chain in the same way they understand other supply chains.

Legal Journal has previously discussed privacy as one of the major legal challenges arising from new technologies in its overview of AI and the law. The same concern becomes even more significant as AI systems depend on large datasets for analytics, personalization, prediction, and automated decision-making.

Artificial Intelligence Could Increase the Value of Brokered Data

AI adds another dimension to the privacy debate.

Large datasets become more valuable when automated systems can rapidly identify patterns and generate predictions.

Individual data points that appear harmless in isolation can contribute to detailed profiles when analyzed together.

For example, an AI system might combine purchase behavior, device information, general location patterns, household characteristics, and web activity to predict consumer interests.

This does not mean every use of such information violates privacy law.

It does mean that the potential impact of collecting large amounts of personal information has changed.

AI systems can process information at a scale that human analysts cannot easily match.

As a result, privacy debates increasingly focus not only on the information companies possess but also on what those companies can infer from it.

Businesses using AI and third-party datasets may therefore need to evaluate both data privacy requirements and the legal risks associated with automated decision-making.

 

Privacy Rights Still Differ Across the United States

Privacy Rights Still Differ Across the United States

One challenge for consumers is that privacy protections remain heavily influenced by state law.

A person living in one state may have rights that differ from those of someone living elsewhere.

California has developed one of the most prominent data broker frameworks, including its state-operated DROP system.

At the federal level, laws such as PADFAA address narrower categories and specific risks rather than creating one comprehensive nationwide data broker deletion system. The FTC’s February 2026 enforcement warning demonstrates that federal oversight can nevertheless affect data brokers handling sensitive American information.

This patchwork creates challenges for national businesses.

Companies may need to determine which privacy law applies to a consumer, which rights that person has, what deadlines apply, and which data falls within an exemption.

Large data brokers operating nationwide may therefore design broader privacy programs rather than building entirely separate systems for every jurisdiction.

That business response could indirectly expand privacy practices even for consumers living outside states with the strongest laws.

What Can Consumers Do About Data Broker Information?

Consumers increasingly have legal tools for reducing the circulation of personal information, although available rights depend on residence and applicable law.

People can examine state privacy agency resources to determine which access, deletion, correction, and opt-out rights apply.

California residents can use the official Delete Request and Opt-out Platform to submit qualifying requests to registered data brokers. The platform requires residency verification and allows consumers to provide information that can help brokers match the request to relevant records.

Consumers can also review privacy settings on devices and applications, particularly settings involving location, advertising identifiers, and unnecessary permissions.

However, individual action has limits.

The data broker ecosystem is complex precisely because people may not know every company holding information about them.

That is why centralized systems represent such an important policy shift. Privacy rights become more useful when consumers can exercise them without first conducting extensive investigations into the data market.

What Data Brokers Need to Consider in 2026

The regulatory environment increasingly asks data brokers to look beyond basic privacy notices.

Companies may need to assess registration requirements, deletion mechanisms, opt-out procedures, sensitive data restrictions, consumer verification, supplier relationships, retention schedules, and international data transfers.

Location data deserves particular attention given recent FTC activity.

The May 2026 Kochava announcement demonstrates that the agency continues to view the distribution of sensitive location information as a significant consumer privacy issue.

Federal restrictions involving foreign adversaries add another compliance layer. The FTC’s 2026 PADFAA letters specifically encouraged brokers to conduct comprehensive reviews of their practices.

Businesses purchasing information from brokers also have reasons to conduct due diligence.

Questions can include where the information originated, whether sensitive information appears in the dataset, what consumer permissions exist, and whether contractual terms address deletion requests.

Privacy compliance increasingly becomes a shared responsibility throughout the data supply chain.

Data Minimization May Become More Important

A basic question is becoming more relevant as privacy regulation grows: does a company actually need all the information it collects?

Holding large amounts of information can create commercial value, but it can also create legal and security risks.

More information means more data that could become subject to a deletion request.

It can mean more information exposed in a security incident.

It can create greater complexity when a business needs to determine whether sensitive data has been transferred to another company or foreign entity.

For this reason, businesses increasingly have incentives to think about data minimization, retention, and purpose limitations as part of broader privacy governance.

The FTC’s proposed Kochava settlement included a requirement for a data retention schedule, illustrating regulators’ interest not only in the collection and sale of information but also in how long companies keep it.

Data Broker Regulation Could Influence the Broader Privacy Market

The impact of these laws may extend well beyond data brokers themselves.

Once consumers become accustomed to centralized privacy controls, they may expect similar options from other industries.

A person who can send one deletion instruction to many data brokers may become less tolerant of companies that require complicated forms and multiple verification steps.

Businesses may respond by simplifying privacy dashboards and preference centers.

Technology providers may develop new systems for transmitting deletion requests across vendors.

Companies may build stronger data inventories so they can locate consumer records more quickly.

Privacy compliance could therefore move away from isolated legal paperwork and toward operational infrastructure built directly into information systems.

California’s DROP program provides an important real-world test of that idea in 2026.

The Future of Consumer Privacy Rights

U.S. data broker regulation is moving toward a model that gives consumers more visibility and greater control over information circulating outside direct customer relationships.

Three trends stand out.

First, deletion rights are becoming easier to exercise. California’s DROP platform represents a major move toward centralized requests rather than broker-by-broker processes.

Second, regulators are placing greater emphasis on sensitive information, particularly precise location data. The FTC’s 2026 Kochava action reflects continuing concern about data capable of revealing visits to sensitive places.

Third, data broker regulation increasingly intersects with national security. PADFAA restricts certain transfers of sensitive American information to foreign adversaries, and the FTC emphasized those obligations in February 2026.

These developments do not create one uniform U.S. privacy system. Consumers still face different protections depending on their state, the type of information involved, and the company handling it.

The direction of regulation, however, is becoming clearer.

Privacy law increasingly recognizes that meaningful consumer control requires regulation beyond the website or application where information was first collected. Data can travel through complex networks of brokers, advertisers, analytics providers, technology vendors, and other companies.

Modern data broker laws attempt to follow that information further downstream.

For consumers, that shift can mean more practical deletion tools, greater transparency, stronger protection for sensitive data, and more control over whether personal information continues circulating through the commercial data economy.

For businesses, it means privacy compliance increasingly depends on understanding not only the information they collect directly but also the information they buy, obtain, share, analyze, and retain.

As data becomes more valuable to advertising, analytics, artificial intelligence, and automated decision systems, the legal rules governing that information are becoming more consequential.

Data broker laws are therefore doing more than regulating a specialized industry. They are helping redefine what consumer privacy rights mean in the United States.

This article provides general educational information about U.S. privacy law and does not constitute legal advice. Privacy rights and compliance obligations depend on the applicable jurisdiction, type of information, business activity, and current law.

Share

RECENT ARTICLES

How Data Broker Laws Are Changing Consumer Privacy Rights

How Data Broker Laws Are Changing Consumer Privacy Rights

How Data Broker Laws Are Changing Consumer Privacy Rights Data brokers operate largely behind the scenes of the digital…

Who Owns Software Created With Generative AI?

Who Owns Software Created With Generative AI?

Generative artificial intelligence is changing the way software gets built. Developers now use AI coding assistants to generate functions,…

Can U.S. Artists Copyright Works Made With Generative AI?

Can U.S. Artists Copyright Works Made With Generative AI?

Can U.S. Artists Copyright Works Made With Generative AI?   Generative artificial intelligence has made it possible for artists…

Scroll to Top