Data Brokers and Personal Privacy
Data brokers are companies that collect, aggregate, and sell personal information about individuals, sourced from public records, commercial data sources, and online traces.[^c10] In 2026, people search sites and data brokers continue to draw from these sources to create detailed profiles that include names, addresses, phone numbers, email addresses, and other personal details.[^c10] These companies range from digital advertising firms and location intelligence providers to people search websites and social media management platforms.[^c3]
California's DROP Platform
The regulatory landscape for data brokers in the United States remains fragmented. As of 2026, twenty states have comprehensive privacy laws on the books, with new laws in Indiana, Kentucky, and Rhode Island taking effect on January 1, 2026.[^c7] California has the most extensive data broker regulations: the state's data broker registry includes approximately 580 firms, a record high,[^c25] and laws such as SB 361 and [[California Delete Act (SB 362)|SB 362 (the Delete Act)]] require brokers to register annually, disclose detailed information about the data they collect, and process deletion requests through [[California Privacy Protection Agency|CalPrivacy]]'s Delete Request and Opt-Out Platform (DROP).[^c3][^c4][^c14] The Delete Act uses an intentionally broad definition of "data broker" that covers any business that collects and sells personal information about California residents without a direct relationship to those individuals, including traditional data vendors and also retailers, loyalty program operators, lead generation firms, and business intelligence providers who sell or enrich data acquired from third parties.[^c15]
DROP, which launched on January 1, 2026, saw immediate adoption. More than 300,000 California residents had signed up within five months, and by June 2026 the Data Broker Registry reached a record 581 registered brokers.[^c24][^c25] Beginning August 1, 2026, data brokers must access DROP at least once every 45 days and process verified deletion requests,[^c4] with fines of $200 per request per day and no statutory cap. DROP remains the only universal deletion mechanism in the United States. Despite these requirements, close to 150 of approximately 570 registered data brokers in California reported receiving zero deletion requests in 2024, and another 130 firms received fewer than 100 requests,[^c3] though the DROP platform is designed to centralize and streamline the process.
CalPrivacy has complemented its enforcement work with a consumer awareness campaign backed by a nearly $8 million budget.[^c3] An investigation by The Markup and CalMatters found that 35 data brokers were using "no-index" code on their opt-out web pages to prevent them from appearing in Google search results, creating a technical barrier to consumers exercising their deletion rights.[^c5] After the investigation and a subsequent Senate inquiry, most brokers removed the code; as of mid-2026, only eight of the original 35 still hide their deletion pages.[^c5]
State Data Broker Registries Expand
Beyond California, state-level data broker regulation saw significant expansion in 2026. Connecticut passed Senate Bill 4 in May 2026, signed by Governor Ned Lamont on May 27, becoming the fifth state to enact comprehensive legislation to regulate data brokers, joining California, Texas, [[Vermont Data Broker Registry|Vermont]], and Oregon.[^c19] The Connecticut law requires data brokers to register with the Department of Consumer Protection by January 1, 2027, pay a $2,500 annual fee, and submit to a centralized consumer deletion mechanism by 2028. Connecticut also became the second state after California to mandate a centralized consumer deletion mechanism.
Texas expanded its data broker definition via Senate Bill 2121, effective September 1, 2025, removing the "principal source of revenue" qualifier to cover any business that "collects, processes, or transfers personal data that the business entity did not collect directly from the individual," broadening the range of entities required to register.[^c31] Vermont Governor Phil Scott signed Act 138 (H.211) on June 16, 2026, substantially strengthening the state's data broker law.[^c55] The Act raises the annual registration fee from $100 to $900, requires a $20,000 surety bond, introduces a new consumer deletion right with 30-day processing requirements, adds purchaser credentialing procedures, expands breach notification obligations, and orders a feasibility study for a centralized deletion mechanism.[^c55] The four active state registries vary significantly in fees, penalties, and scope; a comparative analysis found that Oregon had the highest proportional registration gap at an estimated 63 percent of active entities failing to register.[^c56] For a detailed comparison, see [[State Data Broker Registry Comparison]].
In June 2026, Massachusetts lawmakers voted unanimously to pass the Consumer Data Privacy Act, granting residents new rights over accessing and deleting their data and banning the sale of precise geolocation data, biometrics, and markers of religion, immigration status, and sexual orientation without explicit consent.[^c26] The Massachusetts law also establishes a data broker registry and requires the creation of an accessible deletion mechanism for consumers by 2027, positioning the state among the leaders in data broker regulation.[^c34] Following separate House and Senate versions, the bill entered a conference committee for reconciliation.
On June 30, 2026, New Jersey Governor Mikie Sherrill signed A5328, making New Jersey the seventh state to enact a data broker registry law.[^c61] The law creates a tiered annual registration fee reaching $1.5 million for the largest firms, bans the sale of sensitive data with penalties of $50,000 per record, and covers not only traditional data brokers but also "data collectors" — entities with direct consumer relationships who sell data to brokers.[^c61] The New Jersey law established the most expensive registration fee structure in the country. However, following industry outcry about the record-setting fees and confusion about the law's scope, the New Jersey Division of Consumer Affairs announced in July 2026 that enforcement of the registry and fee requirements would be delayed until June 2027, though the sensitive data sale ban remains in effect.[^c66] See [[New Jersey Data Broker Registry]] for a detailed treatment.
Oregon enacted Senate Bill 1587, effective June 5, 2026, prohibiting state and local government bodies from disclosing personally identifiable information to data brokers unless the broker attests the data will not be used for federal immigration enforcement.
States are also shifting from notice-and-choice frameworks toward categorical prohibitions on certain categories of data sales.[^c27] Virginia (effective July 1, 2026) and Connecticut (effective October 1, 2026) enacted bans on the sale of precise geolocation data, joining similar prohibitions in Maryland and Oregon. Analysts have noted that failure to register as a data broker is increasingly an independent enforcement hook, with regulators not required to show consumer harm to initiate investigations.
AI and Market Transformation
The rapid expansion of artificial intelligence has fundamentally reshaped the data brokerage industry by 2026. AI training runs consume personal records from brokers at rates that doubled in the last two years, and data contracts that once focused on advertising now designate model training rights as their primary clause.[^c54] Pricing has shifted from per-impression to per-million-token fees, rewarding denser, cleaner datasets, while regulators in the United States and Europe now require data origin logs covering at least three prior sales. The convergence of AI demand and regulatory pressure is driving market concentration as smaller brokers exit due to compliance costs. For a detailed analysis, see [[AI and Data Brokerage]].
Enforcement Activity in 2026
The first half of 2026 saw a significant escalation in enforcement activity across multiple jurisdictions. California regulators issued more than $4.22 million in penalties in the first quarter alone, including a $2.75 million settlement with Disney and a $1.1 million fine against PlayOn Sports.[^c20] General Motors agreed to pay $12.75 million in May 2026 — the largest civil penalty ever under the California Consumer Privacy Act — for selling driving data of hundreds of thousands of Californians to data brokers without adequate consent.[^c21] The Federal Trade Commission also finalized a consent order against GM and OnStar in January 2026, barring the automaker from sharing geolocation and driving behavior data with consumer reporting agencies for five years in the agency's first enforcement action regarding connected vehicle data.[^c17] In May 2026, the FTC reached a settlement with location data broker Kochava, resolving litigation dating to August 2022 and permanently banning the company from selling sensitive location data without affirmative express consent. The FTC finalized the order on July 1, 2026. The FTC also sent warning letters to 13 data brokers in February 2026 regarding compliance with the Protecting Americans' Data from Foreign Adversaries Act (PADFAA), which prohibits selling sensitive personal data of Americans to foreign adversaries including China, Russia, Iran, and North Korea.[^c18] California's Data Broker Enforcement Strike Force fined Rickenbacher Data LLC $45,000 for failing to register and for selling health-condition-targeted lists of millions of individuals including those with Alzheimer's disease. In a separate action, the CPPA reached a settlement requiring Background Alert to shut down its operations through 2028 for failing to register as a data broker under the Delete Act — the most significant US precedent for an operational shutdown of a data broker for regulatory non-compliance.[^c62]
In May 2026, the Electronic Privacy Information Center (EPIC) published an audit documenting that 38 major data-collecting companies, including people-search brokers Spokeo, Whitepages, and National Public Data, used manipulative design to block consumers from exercising opt-out rights.[^c59] EPIC documented at least eight categories of obstruction, including buried opt-out links, fake forms, and paid subscription requirements before data removal.[^c59] People-search brokers provided no opt-out of data sales, offering only URL-by-URL listing removal, while companies such as Palantir and SoundThinking offered no opt-out for data sale at all.[^c60] Google, Meta, and OpenAI did not clearly link opt-out forms from their homepages or privacy policies. A separate academic study submitted to arXiv in July 2026 found that a significant fraction of California-registered data brokers failed to respond to CCPA opt-out and deletion requests, with some requiring intrusive identity verification explicitly disallowed by the CCPA.[^c65]
In a further development, plaintiffs' lawyers have begun leveraging the Department of Justice's Bulk Data Rule — which restricts the transfer of sensitive U.S. personal data to countries of concern — to advance claims under state and federal wiretap laws against data brokers and data services companies, adding private litigation risk to the existing regulatory enforcement landscape.[^c64]
National Security and the Data Broker Loophole
The national security implications of the data broker industry gained significant attention in 2026 after U.S. Central Command confirmed that commercially obtained location data was being exploited to target deployed military personnel. Two additional developments underscored the scope of the data broker loophole: ICE was revealed to have signed a nearly $10 million contract with data broker Thundercut Technology LLC for ITIN records of undocumented immigrants, potentially circumventing a court order barring direct access to IRS taxpayer data,[^c57] and the ATF canceled a contract with geolocation surveillance vendor Penlink after lawmakers revealed the agency had conducted over 340 warrantless searches using ad-tech location data.[^c58] For full treatment of the legal, national security, and international dimensions, see [[Data Broker Loophole]], [[Data Broker National Security Concerns]], and [[Fourth Amendment Is Not For Sale Act]].
Federal Legislation
At the federal level, the [[SECURE Data Act (H.R. 8413)]], introduced in April 2026, would create a single national privacy standard preempting state laws and establish a national data broker registry administered by the Federal Trade Commission.[^c8] The Electronic Privacy Information Center (EPIC) called the bill "worse than any privacy law we have evaluated," citing its weak data minimization standard, lack of universal opt-out signal requirements, absence of a private right of action, and broad preemption.[^c6] In June 2026, a House subcommittee held a hearing on the bill, with Ranking Member Frank Pallone criticizing its expansive preemption clause that would invalidate stronger state laws, including California's DROP platform, and describing the bill as one that "locks in the failed notice and consent status quo."[^c22] The bill lacks bipartisan support.
Ohio and State-Level Gaps
Ohio remains one of the most populous states without a comprehensive consumer privacy law, leaving its residents without a state-level right to request access to, deletion of, or control over the personal data that businesses collect about them.[^c9] The [[Ohio Resident Database]], a people search site that aggregates voter registration records, operates in this regulatory environment, drawing on Ohio's official voter registration database to publish registered party, voting history, home addresses, and other details.[^c1][^c2] Voter registration records are highly identifying: name and ZIP code alone uniquely identify 95.81 percent of Texas voters and 87.79 percent of North Carolina voters, illustrating how public records can be re-identified when aggregated by data brokers.[^c11] Ohio House Bill 807, introduced in April 2026, would close loopholes allowing state agencies to share or sell data to private data brokers and prevent automatic sharing of state-held data with federal immigration authorities without consent. The bill remains in committee as of June 2026. The Ohio Bureau of Motor Vehicles generated over $250 million over the past decade selling driver and vehicle personal information to data brokers, credit agencies, and insurance companies under exemptions in the federal Driver's Privacy Protection Act, precisely the practice HB 807 aims to restrict.
Consumer Opt-Out
For consumers seeking to remove their information from data brokers and people search sites, experts recommend using a dedicated email address, submitting opt-out requests on official pages, handling identity verification with redacted documents, and rechecking listings periodically, as many brokers refresh their data.[^c10] Consumers in states with comprehensive privacy laws have additional legal rights to deletion and opt-out that can compel data brokers to remove their information.[^c10] California's DROP platform provides the only universal deletion mechanism in the United States, allowing residents to submit a single deletion request to all registered data brokers, while Connecticut is developing a similar mechanism.
In May 2026, an investigation by Senator Maggie Hassan led data broker Findem to simplify its opt-out process after the company was found to have hidden its deletion pages from search results, demonstrating that congressional oversight can serve as an additional accountability mechanism beyond state regulation.[^c35] The Senate investigation also calculated that identity theft from four major data broker breaches cost U.S. consumers more than $20 billion, underscoring the financial harm associated with inadequate data protection practices in the data broker industry.[^c63]
At the state level, over 40 states have adopted AI-related laws in response to the rapid advancement of the technology,[^c16] while data brokers have expanded the use of AI to assemble and analyze consumer profiles at scale.