Companies That Buy and Sell Your Data Are Not Following California’s Strict Privacy Laws | Stanford HAI
Stanford
University
  • Stanford Home
  • Maps & Directions
  • Search Stanford
  • Emergency Info
  • Terms of Use
  • Privacy
  • Copyright
  • Trademarks
  • Non-Discrimination
  • Accessibility
© Stanford University.  Stanford, California 94305.
Navigate
  • About
  • Events
  • AI Glossary
  • Careers
  • Search
Participate
  • Get Involved
  • Support HAI
  • Contact Us

Stay Up To Date

Get the latest news, advances in research, policy work, and education program updates from HAI in your inbox weekly.

Sign Up For Latest News

Skip to content
  • About

    • About
    • People
    • Get Involved with HAI
    • Support HAI
    • Subscribe to Email
  • Research

    • Research
    • Research Programs
    • Grants
    • Marlowe (opens in new tab)
    • Student Affinity Groups
    • Centers & Labs
    • Research Publications
    • Research Partners
  • Education

    • Education
    • Executive and Professional Education
    • Government and Policymakers
    • K-12
    • Stanford Students
  • Policy

    • Policy
    • Policy Publications
    • Policymaker Education
    • Student Opportunities
  • AI Index

    • AI Index
    • AI Index Report
    • Global Vibrancy Tool
    • People
  • News
  • Events
  • Industry
  • Centers & Labs
news

Companies That Buy and Sell Your Data Are Not Following California’s Strict Privacy Laws

Date
August 11, 2026
Topics
Privacy, Safety, Security
Government, Public Administration
Illustration of people trying to delete document files in the trash

A new Stanford study shows data brokers are making it difficult for consumers to submit privacy requests and failing to report how many privacy requests they receive.

It’s no secret that businesses collect personal information as users scroll and click through websites and mobile apps. But a booming ecosystem of third-party data brokers that buy and sell massive amounts of customer data remains invisible to most consumers. 

To make that ecosystem more transparent, California passed a law expanding data broker regulation: the 2023 Delete Act, which built on the state's 2019 data broker registration law. Under the act, any business that knowingly collects and sells the personal information of consumers with whom it has no direct relationship must register with the state and give consumers the right to delete their data, correct personal information, and learn what personal information the business is selling.

The problem? Most data brokers are ignoring those rules. 

Joint research from Stanford RegLab and Stanford HAI looked at compliance with California’s strict privacy laws and found that only 9% of these companies are fully complying with the law. 

“This is a surprisingly low compliance rate,” says Stanford HAI Privacy and Data Policy Fellow Jennifer King. “It’s possible data brokers are still working out how to report on the required metrics, but they’ve been on notice for more than three years and this step is now mandatory.”

Allowing consumers to manage their own personal data matters for many reasons. When brokers sell your data, it can impact what ads you see, what pricing businesses offer you, and whether you get hired for a job or qualify for a loan. Inaccurate information spreads quickly through the ecosystem and persists long after it’s detected. 

“Companies use personal data to create a 360-degree profile and make predictions about you, but often that data is incorrect,” King says. “People need to have some control over the entire coursing river of their data, especially as AI developers build more automated systems that are unsupervised by humans.”

Today, it’s unclear to what extent data brokers influence the development of AI because of a lack of transparency with how frontier models are built. However, the 2026 Data Broker Registry now requires brokers to disclose whether they have sold data to generative AI developers. So far, more than 30 companies have disclosed this information. “California has been a leader in mandating broker transparency on paper. In principle, that should allow us to better understand the role of data brokers in the AI ecosystem, but in practice, our research shows that disclosures are far from complete,” says RegLab Director Daniel E. Ho.

Strong on Paper, Weak in Practice

By July 1, 2025, data brokers had to publicly report how many consumer requests they received in the prior calendar year for the following categories:

  1. To delete one’s data

  2. To correct personal information

  3. To know what personal information is being collected by a business

  4. To know what personal information is being sold/shared by a business

  5. To request the business not sell or share your data

  6. To limit the use and disclosure of sensitive personal information

They also needed to share the mean and median number of days to fulfill each request type, and a breakdown of the number of requests they complied with and denied. 

But when King, Ho, and coauthors Anna-Maria Gueorguieva, PhD candidate at the University of Washington and RegLab 2025 Summer Graduate Student Fellow, and Apoorva Panidapu, RegLab undergraduate research assistant, manually reviewed privacy policies for all 522 self-registered data brokers in 2025, they found only 9% fully complied by reporting on the full set of transparency requirements and 45% did not submit any rights request metrics at all to the California Privacy Protection Agency. 

Moreover, the study found 64% of data brokers added friction to rights request processes, using confusing website designs, multiple forms, or excessive verification steps to make it more difficult for consumers to submit requests. Such “dark patterns” are expressly prohibited by the law.

The team identified several possible reasons for noncompliance: The system relies on data brokers to self-register, penalties are inconsistent, and the agency that enforces the rules is under-resourced.

A One-Stop Shop for Dropping Data

The Delete Act also authorized a new technical platform, the Delete Request and Opt-out Platform (DROP), that will allow California residents to submit data-deletion and opt-out-of-sale requests to all registered data brokers with a single request. Now live as of August 1, every 45 days data brokers must delete all personal information related to consumers who opt out, including behavioral, financial, health, location, and relationship data, as well as any inferences drawn about individuals from their data. 

The platform holds promise, but its effectiveness will depend on how effectively consumer rights organizations publicize the new mechanism, King says. As it stands today, the platform has over a half-million consumer registrations, due in part to a publicity campaign by CalPrivacy to build consumer awareness.

Another phase of the legislation kicks in by 2028, when data brokers will have to undergo third-party audits every three years to assess their compliance with the Delete Act. King adds that this is when the stakes will go up. 

“California is leading the way in consumer privacy laws, but our findings paint a troubling picture of how these protections have been implemented,” she says. “Without clear reporting requirements and consistent financial consequences, businesses simply won’t do it.” 

Read the related Stanford HAI policy paper, Regulating Data Brokers in the Age of AI: A California Case Study

Read the May 2026 study, Privacy Without Remedy: An Assessment of Data Broker Compliance with California Privacy Law.

Share
Link copied to clipboard!
Contributor(s)
Nikki Goth Itoi

Related News

AI Legal Review Says Millions Live Under Discriminatory Local Laws
Andrew Myers
Sep 08, 2026
News
piles of outdated laws with AI highlighted discriminatory ones

Building an AI pipeline to comb through millions of local statutes, researchers at Stanford Law School turn a spotlight on unsavory laws still on the books in communities across the country.

News
piles of outdated laws with AI highlighted discriminatory ones

AI Legal Review Says Millions Live Under Discriminatory Local Laws

Andrew Myers
Government, Public AdministrationLaw Enforcement and JusticeRegulation, Policy, GovernanceSep 08

Building an AI pipeline to comb through millions of local statutes, researchers at Stanford Law School turn a spotlight on unsavory laws still on the books in communities across the country.

Your Boss, Tech Companies And Police Can Read Your Chatbot Conversations
Washington Post
Aug 31, 2026
Media Mention

HAI Policy Fellow Jennifer King discusses privacy issues with AI chatbots, saying, “Unless you are having a chat with a service that has a temporary chat or, basically, an incognito version ... [and] you’re also having it within a browser that’s not tracking you, the answer is no. You can’t be sure that it’ll be totally private."

Media Mention
Your browser does not support the video tag.

Your Boss, Tech Companies And Police Can Read Your Chatbot Conversations

Washington Post
Privacy, Safety, SecurityAug 31

HAI Policy Fellow Jennifer King discusses privacy issues with AI chatbots, saying, “Unless you are having a chat with a service that has a temporary chat or, basically, an incognito version ... [and] you’re also having it within a browser that’s not tracking you, the answer is no. You can’t be sure that it’ll be totally private."

California's Data And Privacy Laws Aren't Being Followed
Marketplace
Aug 25, 2026
Media Mention

The state's Delete Act was supposed to give Californians a one-stop-shop to request their online information be deleted. But only a minority of registered data brokers are abiding by those laws, says Jennifer King, privacy and data policy fellow at the Stanford University Institute for Human-Centered AI.

Media Mention
Your browser does not support the video tag.

California's Data And Privacy Laws Aren't Being Followed

Marketplace
Privacy, Safety, SecurityRegulation, Policy, GovernanceAug 25

The state's Delete Act was supposed to give Californians a one-stop-shop to request their online information be deleted. But only a minority of registered data brokers are abiding by those laws, says Jennifer King, privacy and data policy fellow at the Stanford University Institute for Human-Centered AI.