Regulating Data Brokers in the Age of AI: A California Case Study

This brief assesses data broker compliance with California privacy laws and calls for more stringent consumer protections.
Key Takeaways
Data brokers are third parties that buy and sell consumers’ data without their specific knowledge or consent. In so doing, they expose consumers and the public to potential risks such as data breaches, political violence, and national security threats. Despite these risks, few states regulate this opaque ecosystem.
Widely lauded as the most comprehensive state consumer privacy statute, the California Consumer Privacy Act (CCPA) and the Delete Act require data brokers to allow consumers to exercise their privacy rights (e.g., by deleting their data or opting out of data collection) and mandate that brokers disclose the number of requests they receive each year.
We assess data broker compliance with the CCPA and the Delete Act, finding that many brokers obstruct consumers from properly exercising their requests and ignore disclosure requirements, leaving consumers to navigate a complex system with no direct remedy for harm.
Data brokers and generative AI developers operate in the same data ecosystem, with brokers selling consumer data to AI companies, making it imperative that data privacy protections extend to generative AI development.
Executive Summary
Technology, social media, and AI mediate our daily lives, raising urgent concerns about how businesses collect, share, and sell our data. This collection process is largely invisible, occurring in our background use of apps, websites, and devices, without meaningful notice. The scale of this data collection is staggering: Billions of data points are generated and distributed each day. Data brokers — third-party companies that collect and exchange consumer data with whom they do not have first-party relationships — are key players in this opaque data-sharing ecosystem. The data that brokers make available for a price can include personal addresses, phone numbers, credit history, as well as predictive profiles assessing an individual’s purchasing habits, insurance risk, and much more. All of this data can be used in ways that have harmful downstream effects for consumers, yet the broker ecosystem remains largely opaque.
In our paper “Privacy Without Remedy: An Assessment of Data Broker Compliance with California Privacy Law,” we assess data broker compliance with the California Consumer Privacy Act and the Delete Act. California is widely seen to be at the frontier of comprehensive consumer privacy law, and these two acts are the first in the nation to require data brokers to: register with the state, allow consumers to exercise their data privacy rights, and publicly post the annual number of requests they receive from California consumers. We find that a majority of brokers ignore mandated disclosure requirements and add friction to rights request processes, making it challenging for consumers to exercise their rights.
These findings also matter in the context of generative AI development as novel datasets become ever more valuable for training AI systems. As the 2026 California data broker registry demonstrates, 32 brokers currently sell data to generative AI developers. To ensure that consumers can actively exercise their data privacy rights and that regulators and researchers can adequately monitor and assess data laws, policymakers should consider implementing similar data broker registration laws across the nation. Such legislation best serves consumers and researchers if it includes automated privacy rights request processes, standardized reporting practices, and the ability for consumers to pursue a private right of action.
Introduction
Most U.S. consumers are generally aware that their data is collected by the businesses they interact with directly. Fewer are knowledgeable about the wide-reaching third-party data collection ecosystem that exists alongside the websites and apps they visit regularly. Data brokers are the third-party companies that collect and sell the data of consumers with whom they do not have a first-party relationship. Some have over 10,000 different data types on offer for purchase by other businesses, individuals, and governments. Along with concrete behavioral data collected about consumers, brokers also make and sell inferences about future behavior — such as whether a consumer is likely to buy a product, take up a hobby, or need a specific service.
Many use cases for this data can be beneficial or benign, such as public health research, fraud detection, and identity verification. However, broker data has also been used in instances of political violence and to identify military personnel. For example, in 2020, a disgruntled lawyer used publicly available data available online to target District Judge Esther Salas and fatally shoot her son outside their New Jersey home. Broker data is also used to shape financial decisions that can have allocative harms. In 2024, General Motors was found to be selling their customers’ driving data without explicit consent to data brokers, who in turn used the data to create risk scoring products for auto insurance companies. The sales were discovered after many GM auto owners experienced rate increases, were dropped from their insurance policies, or were unable to find new auto insurance.
Such threats have fueled calls to regulate data brokers for over a decade, yet only four states currently do so. Under the California Consumer Privacy Act (CCPA) of 2018, data brokers must allow consumers to exercise their privacy rights to have their data deleted, corrected, and not sold to others. In addition, brokers must disclose what personal information is being collected, sold, or shared, and to limit the use and disclosure of sensitive personal information when requested by consumers. California’s 2023 Delete Act requires brokers to publicly post the number of requests they receive from consumers in the prior calendar year. The goal of this requirement is to increase accountability by crowdsourcing compliance through the direct disclosure of information to the public. However, to date no other researchers have studied brokers’ compliance with either of these laws.
Several data brokers also sell data to companies building generative AI, information that is newly disclosed in the 2026 California broker registry. Little is known regarding how generative AI developers might use broker-purchased data, and there are no transparency requirements that mandate any detailed disclosure.








