Stanford
University
  • Stanford Home
  • Maps & Directions
  • Search Stanford
  • Emergency Info
  • Terms of Use
  • Privacy
  • Copyright
  • Trademarks
  • Non-Discrimination
  • Accessibility
© Stanford University.  Stanford, California 94305.
Companies That Buy and Sell Your Data Are Not Following California’s Strict Privacy Laws | Stanford HAI
Navigate
  • About
  • Events
  • AI Glossary
  • Careers
  • Search
Participate
  • Get Involved
  • Support HAI
  • Contact Us
Skip to content
  • About

    • About
    • People
    • Get Involved with HAI
    • Support HAI
    • Subscribe to Email
  • Research

    • Research
    • Fellowship Programs
    • Grants
    • Student Affinity Groups
    • Centers & Labs
    • Research Publications
    • Research Partners
  • Education

    • Education
    • Executive and Professional Education
    • Government and Policymakers
    • K-12
    • Stanford Students
  • Policy

    • Policy
    • Policy Publications
    • Policymaker Education
    • Student Opportunities
  • AI Index

    • AI Index
    • AI Index Report
    • Global Vibrancy Tool
    • People
  • News
  • Events
  • Industry
  • Centers & Labs

Stay Up To Date

Get the latest news, advances in research, policy work, and education program updates from HAI in your inbox weekly.

Sign Up For Latest News

news

Companies That Buy and Sell Your Data Are Not Following California’s Strict Privacy Laws

Date
August 11, 2026
Topics
Privacy, Safety, Security
Government, Public Administration
Illustration of people trying to delete document files in the trash

A new Stanford study shows data brokers are making it difficult for consumers to submit privacy requests and failing to report how many privacy requests they receive.

It’s no secret that businesses collect personal information as users scroll and click through websites and mobile apps. But a booming ecosystem of third-party data brokers that buy and sell massive amounts of customer data remains invisible to most consumers. 

To make that ecosystem more transparent, California passed the first law regulating data broker practices: the 2023 Delete Act. Under the act, any business collecting data from at least 10 million California consumers must register with the state and give consumers the right to delete their data, correct personal information, and learn what personal information the business is selling.

The problem? Most data brokers are ignoring those rules. 

Joint research from Stanford RegLab and Stanford HAI looked at compliance with California’s strict privacy laws and found that only 9% of these companies are fully complying with the law. 

“This is a surprisingly low compliance rate,” says Stanford HAI Privacy and Data Policy Fellow Jennifer King. “It’s possible data brokers are still working out how to report on the required metrics, but they’ve been on notice for more than three years and this step is now mandatory.”

Allowing consumers to manage their own personal data matters for many reasons. When brokers sell your data, it can impact what ads you see, what pricing businesses offer you, and whether you get hired for a job or qualify for a loan. Inaccurate information spreads quickly through the ecosystem and persists long after it’s detected. 

“Companies use personal data to create a 360-degree profile and make predictions about you, but often that data is incorrect,” King says. “People need to have some control over the entire coursing river of their data, especially as AI developers build more automated systems that are unsupervised by humans.”

Today, it’s unclear to what extent data brokers influence the development of AI because of a lack of transparency with how frontier models are built. However, the 2026 Data Broker Registry now requires brokers to disclose whether they have sold data to generative AI developers. So far, more than 30 companies have disclosed this information. “California has been a leader in mandating broker transparency on paper. In principle, that should allow us to better understand the role of data brokers in the AI ecosystem, but in practice, our research shows that disclosures are far from complete,” says RegLab Director Daniel E. Ho.

Strong on Paper, Weak in Practice

By July 1, 2025, data brokers had to publicly report how many consumer requests they received in the past two years for the following categories:

  1. To delete one’s data

  2. To correct personal information

  3. To know what personal information is being collected by a business

  4. To know what personal information is being sold/shared by a business

  5. To request the business not sell or share your data

  6. To limit the use and disclosure of sensitive personal information

They also needed to share the mean and median number of days to fulfill each request type, and a breakdown of the number of requests they complied with and denied. 

But when King, Ho, and coauthors Anna-Maria Gueorguieva, PhD candidate at the University of Washington and RegLab 2025 Summer Graduate Student Fellow, and Apoorva Panidapu, RegLab undergraduate research assistant, manually reviewed privacy policies for all 522 self-registered data brokers in 2025, they found only 9% fully complied by reporting on the full set of transparency requirements and 45% did not submit any rights request metrics at all to the California Privacy Protection Agency. 

Moreover, the study found 64% of data brokers added friction to rights request processes, using confusing website designs, multiple forms, or excessive verification steps to make it more difficult for consumers to submit requests. Such “dark patterns” are expressly prohibited by the law.

The team identified several possible reasons for noncompliance: The system relies on data brokers to self-register, penalties are inconsistent, and the agency that enforces the rules is under-resourced.

A One-Stop Shop for Dropping Data

The Delete Act also authorized a new technical platform, the Delete Request and Opt-out Platform (DROP), that will allow California residents to submit data-deletion and opt-out-of-sale requests to all registered data brokers with a single request. Now live as of August 1, every 45 days data brokers must delete all personal information related to consumers who opt out, including behavioral, financial, health, location, and relationship data, as well as any inferences drawn about individuals from their data. 

The platform holds promise, but its effectiveness will depend on how effectively consumer rights organizations publicize the new mechanism, King says.

Another phase of the legislation kicks in by 2028, when data brokers will have to undergo third-party audits every three years to assess their compliance with the Delete Act. King adds that this is when the stakes will go up. 

“California is leading the way in consumer privacy laws, but our findings paint a troubling picture of how these protections have been implemented,” she says. “Without clear reporting requirements and consistent financial consequences, businesses simply won’t do it.” 

Read the related Stanford HAI policy paper, Regulating Data Brokers in the Age of AI: A California Case Study

Read the May 2026 study, Privacy Without Remedy: An Assessment of Data Broker Compliance with California Privacy Law.

Share
Link copied to clipboard!
Contributor(s)
Nikki Goth Itoi

Related News

California's Data And Privacy Laws Aren't Being Followed
Marketplace
Aug 25, 2026
Media Mention

The state's Delete Act was supposed to give Californians a one-stop-shop to request their online information be deleted. But only a minority of registered data brokers are abiding by those laws, says Jennifer King, privacy and data policy fellow at the Stanford University Institute for Human-Centered AI.

Media Mention
Your browser does not support the video tag.

California's Data And Privacy Laws Aren't Being Followed

Marketplace
Privacy, Safety, SecurityRegulation, Policy, GovernanceAug 25

The state's Delete Act was supposed to give Californians a one-stop-shop to request their online information be deleted. But only a minority of registered data brokers are abiding by those laws, says Jennifer King, privacy and data policy fellow at the Stanford University Institute for Human-Centered AI.

Open-Weight Models Aren’t Enough. We Need Truly Open Source AI Models for Science and Society.
Shana Lynch
Aug 04, 2026
News
iceberg showing model weights at the tip and a lot of unknown and deep technology under the surface of the water

As Chinese AI closes the capability gap, Washington and Silicon Valley debate open-weight models. Stanford HAI's James Landay says it's the right conversation framed the wrong way.

News
iceberg showing model weights at the tip and a lot of unknown and deep technology under the surface of the water

Open-Weight Models Aren’t Enough. We Need Truly Open Source AI Models for Science and Society.

Shana Lynch
Privacy, Safety, SecurityInternational Affairs, International Security, International DevelopmentRegulation, Policy, GovernanceAug 04

As Chinese AI closes the capability gap, Washington and Silicon Valley debate open-weight models. Stanford HAI's James Landay says it's the right conversation framed the wrong way.

The Complexities of Governing Mental Health AI
Caroline Yee, Caroline Meinhardt, Michelle Mello, Jane Paik Kim
Jul 24, 2026
News
digital face mental health illustration

Policymakers, academics, healthcare providers, AI developers, and patient advocates convened by Stanford HAI identify critical gaps in how we regulate AI tools used for therapy and emotional support.

News
digital face mental health illustration

The Complexities of Governing Mental Health AI

Caroline Yee, Caroline Meinhardt, Michelle Mello, Jane Paik Kim
HealthcarePrivacy, Safety, SecurityGenerative AIRegulation, Policy, GovernanceJul 24

Policymakers, academics, healthcare providers, AI developers, and patient advocates convened by Stanford HAI identify critical gaps in how we regulate AI tools used for therapy and emotional support.