Regulating Data Brokers in the Age of AI: A California Case Study
Abstract
Key Takeaways
- Data brokers are third parties that buy and sell consumers’ data without their specific knowledge or consent. In so doing, they expose consumers and the public to potential risks such as data breaches, political violence, and national security threats. Despite these risks, few states regulate this opaque ecosystem.
- Widely lauded as the most comprehensive state consumer privacy statute, the California Consumer Privacy Act (CCPA) and the Delete Act require data brokers to allow consumers to exercise their privacy rights (e.g., by deleting their data or opting out of data collection) and mandate that brokers disclose the number of requests they receive each year.
- We assess data broker compliance with the CCPA and the Delete Act, finding that many brokers obstruct consumers from properly exercising their requests and ignore disclosure requirements, leaving consumers to navigate a complex system with no direct remedy for harm.
- Data brokers and generative AI developers operate in the same data ecosystem, with brokers selling consumer data to AI companies, making it imperative that data privacy protections extend to generative AI development.
Executive Summary
Technology, social media, and AI mediate our daily lives, raising urgent concerns about how businesses collect, share, and sell our data. This collection process is largely invisible, occurring in our background use of apps, websites, and devices, without meaningful notice. The scale of this data collection is staggering: Billions of data points are generated and distributed each day. Data brokers — third-party companies that collect and exchange consumer data with whom they do not have first-party relationships — are key players in this opaque data-sharing ecosystem. The data that brokers make available for a price can include personal addresses, phone numbers, credit history, as well as predictive profiles assessing an individual’s purchasing habits, insurance risk, and much more. All of this data can be used in ways that have harmful downstream effects for consumers, yet the broker ecosystem remains largely opaque.
In our paper “Privacy Without Remedy: An Assessment of Data Broker Compliance with California Privacy Law,” we assess data broker compliance with the California Consumer Privacy Act and the Delete Act. California is widely seen to be at the frontier of comprehensive consumer privacy law, and these two acts are the first in the nation to require data brokers to: register with the state, allow consumers to exercise their data privacy rights, and publicly post the annual number of requests they receive from California consumers. We find that a majority of brokers ignore mandated disclosure requirements and add friction to rights request processes, making it challenging for consumers to exercise their rights.
These findings also matter in the context of generative AI development as novel datasets become ever more valuable for training AI systems. As the 2026 California data broker registry demonstrates, 32 brokers currently sell data to generative AI developers. To ensure that consumers can actively exercise their data privacy rights and that regulators and researchers can adequately monitor and assess data laws, policymakers should consider implementing similar data broker registration laws across the nation. Such legislation best serves consumers and researchers if it includes automated privacy rights request processes, standardized reporting practices, and the ability for consumers to pursue a private right of action.