Stanford
University
  • Stanford Home
  • Maps & Directions
  • Search Stanford
  • Emergency Info
  • Terms of Use
  • Privacy
  • Copyright
  • Trademarks
  • Non-Discrimination
  • Accessibility
© Stanford University.  Stanford, California 94305.
Companies That Buy and Sell Your Data Are Not Following California’s Strict Privacy Laws | Stanford HAI
Skip to content
  • About

    • About
    • People
    • Get Involved with HAI
    • Support HAI
    • Subscribe to Email
  • Research

    • Research
    • Research Programs
    • Grants
    • Marlowe (opens in new tab)
    • Student Affinity Groups
    • Centers & Labs
    • Research Publications
    • Research Partners
  • Education

    • Education
    • Executive and Professional Education
    • Government and Policymakers
    • K-12
    • Stanford Students
  • Policy

    • Policy
    • Policy Publications
    • Policymaker Education
    • Student Opportunities
  • AI Index

    • AI Index
    • AI Index Report
    • Global Vibrancy Tool
    • People
  • News
  • Events
  • Industry
  • Centers & Labs
Navigate
  • About
  • Events
  • AI Glossary
  • Careers
  • Search
Participate
  • Get Involved
  • Support HAI
  • Contact Us

Stay Up To Date

Get the latest news, advances in research, policy work, and education program updates from HAI in your inbox weekly.

Sign Up For Latest News

news

Companies That Buy and Sell Your Data Are Not Following California’s Strict Privacy Laws

Date
August 11, 2026
Topics
Privacy, Safety, Security
Government, Public Administration
Illustration of people trying to delete document files in the trash

A new Stanford study shows data brokers are making it difficult for consumers to submit privacy requests and failing to report how many privacy requests they receive.

It’s no secret that businesses collect personal information as users scroll and click through websites and mobile apps. But a booming ecosystem of third-party data brokers that buy and sell massive amounts of customer data remains invisible to most consumers. 

To make that ecosystem more transparent, California passed a law expanding data broker regulation: the 2023 Delete Act, which built on the state's 2019 data broker registration law. Under the act, any business that knowingly collects and sells the personal information of consumers with whom it has no direct relationship must register with the state and give consumers the right to delete their data, correct personal information, and learn what personal information the business is selling.

The problem? Most data brokers are ignoring those rules. 

Joint research from Stanford RegLab and Stanford HAI looked at compliance with California’s strict privacy laws and found that only 9% of these companies are fully complying with the law. 

“This is a surprisingly low compliance rate,” says Stanford HAI Privacy and Data Policy Fellow Jennifer King. “It’s possible data brokers are still working out how to report on the required metrics, but they’ve been on notice for more than three years and this step is now mandatory.”

Allowing consumers to manage their own personal data matters for many reasons. When brokers sell your data, it can impact what ads you see, what pricing businesses offer you, and whether you get hired for a job or qualify for a loan. Inaccurate information spreads quickly through the ecosystem and persists long after it’s detected. 

“Companies use personal data to create a 360-degree profile and make predictions about you, but often that data is incorrect,” King says. “People need to have some control over the entire coursing river of their data, especially as AI developers build more automated systems that are unsupervised by humans.”

Today, it’s unclear to what extent data brokers influence the development of AI because of a lack of transparency with how frontier models are built. However, the 2026 Data Broker Registry now requires brokers to disclose whether they have sold data to generative AI developers. So far, more than 30 companies have disclosed this information. “California has been a leader in mandating broker transparency on paper. In principle, that should allow us to better understand the role of data brokers in the AI ecosystem, but in practice, our research shows that disclosures are far from complete,” says RegLab Director Daniel E. Ho.

Strong on Paper, Weak in Practice

By July 1, 2025, data brokers had to publicly report how many consumer requests they received in the prior calendar year for the following categories:

  1. To delete one’s data

  2. To correct personal information

  3. To know what personal information is being collected by a business

  4. To know what personal information is being sold/shared by a business

  5. To request the business not sell or share your data

  6. To limit the use and disclosure of sensitive personal information

They also needed to share the mean and median number of days to fulfill each request type, and a breakdown of the number of requests they complied with and denied. 

But when King, Ho, and coauthors Anna-Maria Gueorguieva, PhD candidate at the University of Washington and RegLab 2025 Summer Graduate Student Fellow, and Apoorva Panidapu, RegLab undergraduate research assistant, manually reviewed privacy policies for all 522 self-registered data brokers in 2025, they found only 9% fully complied by reporting on the full set of transparency requirements and 45% did not submit any rights request metrics at all to the California Privacy Protection Agency. 

Moreover, the study found 64% of data brokers added friction to rights request processes, using confusing website designs, multiple forms, or excessive verification steps to make it more difficult for consumers to submit requests. Such “dark patterns” are expressly prohibited by the law.

The team identified several possible reasons for noncompliance: The system relies on data brokers to self-register, penalties are inconsistent, and the agency that enforces the rules is under-resourced.

A One-Stop Shop for Dropping Data

The Delete Act also authorized a new technical platform, the Delete Request and Opt-out Platform (DROP), that will allow California residents to submit data-deletion and opt-out-of-sale requests to all registered data brokers with a single request. Now live as of August 1, every 45 days data brokers must delete all personal information related to consumers who opt out, including behavioral, financial, health, location, and relationship data, as well as any inferences drawn about individuals from their data. 

The platform holds promise, but its effectiveness will depend on how effectively consumer rights organizations publicize the new mechanism, King says. As it stands today, the platform has over a half-million consumer registrations, due in part to a publicity campaign by CalPrivacy to build consumer awareness.

Another phase of the legislation kicks in by 2028, when data brokers will have to undergo third-party audits every three years to assess their compliance with the Delete Act. King adds that this is when the stakes will go up. 

“California is leading the way in consumer privacy laws, but our findings paint a troubling picture of how these protections have been implemented,” she says. “Without clear reporting requirements and consistent financial consequences, businesses simply won’t do it.” 

Read the related Stanford HAI policy paper, Regulating Data Brokers in the Age of AI: A California Case Study

Read the May 2026 study, Privacy Without Remedy: An Assessment of Data Broker Compliance with California Privacy Law.

Share
Link copied to clipboard!
Contributor(s)
Nikki Goth Itoi

Related News

The Tests That Grade AI May Be Getting It Wrong
Andrew Myers
Sep 25, 2026
News

Benchmarks — the standardized tests that rank AI models on safety, bias, and reasoning — drive markets and shape regulation. New Stanford research finds they often don't measure what they claim to.

News

The Tests That Grade AI May Be Getting It Wrong

Andrew Myers
Generative AIPrivacy, Safety, SecurityFoundation ModelsSep 25

Benchmarks — the standardized tests that rank AI models on safety, bias, and reasoning — drive markets and shape regulation. New Stanford research finds they often don't measure what they claim to.

Can AI Be Slowed Down? Stanford HAI Experts Weigh the Risks, Rules and Race Ahead
Shana Lynch
Sep 22, 2026
News

In a new series called Prompt Response, Stanford’s Surya Ganguli, Diyi Yang and Rob Reich examined emergent agent behavior, recursive self-improvement, independent evaluation and whether a kill switch can make advanced AI safer.

News

Can AI Be Slowed Down? Stanford HAI Experts Weigh the Risks, Rules and Race Ahead

Shana Lynch
Privacy, Safety, SecurityRegulation, Policy, GovernanceGenerative AISep 22

In a new series called Prompt Response, Stanford’s Surya Ganguli, Diyi Yang and Rob Reich examined emergent agent behavior, recursive self-improvement, independent evaluation and whether a kill switch can make advanced AI safer.

AI Chatbots And Privacy: How To Keep Personal Info Secure
Good Morning America
Sep 21, 2026
Media Mention

HAI Policy Fellow Jennifer King advises caution surrounding one's person security when using AI, citing her research on AI privacy and insights on users’ tendency to disclose personal information to chatbots due to their conversational nature, the lack of transparency in how companies use chatbot conversations for training, and the evolving legal landscape around this data.

Media Mention
Your browser does not support the video tag.

AI Chatbots And Privacy: How To Keep Personal Info Secure

Good Morning America
Privacy, Safety, SecuritySep 21

HAI Policy Fellow Jennifer King advises caution surrounding one's person security when using AI, citing her research on AI privacy and insights on users’ tendency to disclose personal information to chatbots due to their conversational nature, the lack of transparency in how companies use chatbot conversations for training, and the evolving legal landscape around this data.