FPF Releases New Issue Brief on U.S. “Data Broker” Regulatory Landscape
Data brokers have been the subject of intense scrutiny in recent years, including through critical media coverage, public hearings, private lawsuits, regulatory enforcement actions, and new state and federal regulatory frameworks. Despite all this public attention, there is little consensus as to who is a “data broker,” what risks and benefits are associated with data brokerage, and how the evolving privacy regulatory landscape affects this industry.
The data broker industry is diverse, and the risks posed to individuals vary depending on data use cases, sensitivity, and companies’ practices. Data brokerage also enables services widely regarded as beneficial, such as combating fraud and other illegal activities as well as enabling access to financial services. It also supports personalized marketing, toward which consumers and other stakeholders have a range of views.
To help make sense of this rapidly evolving regulatory space, FPF is releasing a new issue brief, The Boundaries of Data Brokerage: An Overview of the U.S. Regulatory Landscape. This issue brief provides an overview of the emerging regulatory landscape—focusing on recently enacted state and federal laws that specifically regulate the data broker industry—as well as key considerations for policymakers and industry actors.
Key takeaways from the issue brief—
- Inconsistent Scope: New U.S. data broker laws define a data broker as either a business that sells personal data that the business did not collect directly from the consumer or sells the data of a consumer with whom the business does not have a direct relationship. Both approaches attempt to exclude the sale of data that was collected in a first-party interaction but differ in their formulation.
- Requirements Include Registration, Security, and Targeted Prohibitions: Data brokers are typically required to register with the state annually. Some of these laws include additional obligations such as maintaining adequate security or targeted prohibitions such as bans on fraudulent acquisition of personal data.
- Accessible Deletion Mechanisms Are Paradigm-Changing: Exercising deletion or opt-out rights on a company-by-company basis can be difficult and time-consuming for consumers. California’s new accessible deletion mechanism, soon to be replicated in Connecticut, changes this calculus for consumers by enabling deletion requests en masse. Nevertheless, these tools may pose a risk to consumers in-and-of themselves if not implemented securely.
- Existing Consumer Protection Law Remains Relevant: As states experiment with data broker registries and Congress focuses on limiting the flow of sensitive data to foreign adversaries and countries of concern, longstanding consumer protection laws like the FTC Act remain an avenue for enforcement actions against data brokers.
The issue brief concludes with ongoing policy considerations that may prove valuable for future legislative efforts as well as industry practices. For policymakers, key questions include the appropriate scope of new regulations (both in terms of the types of data and entities who should be regulated), whether new frameworks should broadly define “data brokerage” or focus on specific harmful use cases, and how existing legal and technical protections can be better enforced or inform future regulatory frameworks. For industry, they include the extent to which organizations should adopt voluntary practices for transparency and data stewardship in order to deepen customer and public trust.