Key Takeaways
- Data brokers are third parties that buy and sell consumers’ data without their specific knowledge or consent. In so doing, they expose consumers and the public to potential risks such as data breaches, political violence, and national security threats. Despite these risks, few states regulate this opaque ecosystem.
- Widely lauded as the most comprehensive state consumer privacy statute, the California Consumer Privacy Act (CCPA) and the Delete Act require data brokers to allow consumers to exercise their privacy rights (e.g., by deleting their data or opting out of data collection) and mandate that brokers disclose the number of requests they receive each year.
- We assess data broker compliance with the CCPA and the Delete Act, finding that many brokers obstruct consumers from properly exercising their requests and ignore disclosure requirements, leaving consumers to navigate a complex system with no direct remedy for harm.
- Data brokers and generative AI developers operate in the same data ecosystem, with brokers selling consumer data to AI companies, making it imperative that data privacy protections extend to generative AI development.
Read the associated academic paper here.