Stanford
University
  • Stanford Home
  • Maps & Directions
  • Search Stanford
  • Emergency Info
  • Terms of Use
  • Privacy
  • Copyright
  • Trademarks
  • Non-Discrimination
  • Accessibility
© Stanford University.  Stanford, California 94305.
Skip to content
  • About

    • About
    • People
    • Get Involved with HAI
    • Support HAI
    • Subscribe to Email
  • Research

    • Research
    • Fellowship Programs
    • Grants
    • Student Affinity Groups
    • Centers & Labs
    • Research Publications
    • Research Partners
  • Education

    • Education
    • Executive and Professional Education
    • Government and Policymakers
    • K-12
    • Stanford Students
  • Policy

    • Policy
    • Policy Publications
    • Policymaker Education
    • Student Opportunities
  • AI Index

    • AI Index
    • AI Index Report
    • Global Vibrancy Tool
    • People
  • News
  • Events
  • Industry
  • Centers & Labs

Stay Up To Date

Get the latest news, advances in research, policy work, and education program updates from HAI in your inbox weekly.

Sign Up For Latest News

Navigate
  • About
  • Events
  • AI Glossary
  • Careers
  • Search
Participate
  • Get Involved
  • Support HAI
  • Contact Us
Regulating Data Brokers in the Age of AI: A California Case Study | Stanford HAI
policyPolicy Brief

Regulating Data Brokers in the Age of AI: A California Case Study

Date
August 11, 2026
Topics
Privacy, Safety, Security
Regulation, Policy, Governance
Read Paper
abstract

This brief assesses data broker compliance with California privacy laws and calls for more stringent consumer protections.

In collaboration with

Key Takeaways

  • Data brokers are third parties that buy and sell consumers’ data without their specific knowledge or consent. In so doing, they expose consumers and the public to potential risks such as data breaches, political violence, and national security threats. Despite these risks, few states regulate this opaque ecosystem. 

  • Widely lauded as the most comprehensive state consumer privacy statute, the California Consumer Privacy Act (CCPA) and the Delete Act require data brokers to allow consumers to exercise their privacy rights (e.g., by deleting their data or opting out of data collection) and mandate that brokers disclose the number of requests they receive each year. 

  • We assess data broker compliance with the CCPA and the Delete Act, finding that many brokers obstruct consumers from properly exercising their requests and ignore disclosure requirements, leaving consumers to navigate a complex system with no direct remedy for harm.

  • Data brokers and generative AI developers operate in the same data ecosystem, with brokers selling consumer data to AI companies, making it imperative that data privacy protections extend to generative AI development.  

Executive Summary

Technology, social media, and AI mediate our daily lives, raising urgent concerns about how businesses collect, share, and sell our data. This collection process is largely invisible, occurring in our background use of apps, websites, and devices, without meaningful notice. The scale of this data collection is staggering: Billions of data points are generated and distributed each day. Data brokers — third-party companies that collect and exchange consumer data with whom they do not have first-party relationships — are key players in this opaque data-sharing ecosystem. The data that brokers make available for a price can include personal addresses, phone numbers, credit history, as well as predictive profiles assessing an individual’s purchasing habits, insurance risk, and much more. All of this data can be used in ways that have harmful downstream effects for consumers, yet the broker ecosystem remains largely opaque. 

In our paper “Privacy Without Remedy: An Assessment of Data Broker Compliance with California Privacy Law,” we assess data broker compliance with the California Consumer Privacy Act and the Delete Act. California is widely seen to be at the frontier of comprehensive consumer privacy law, and these two acts are the first in the nation to require data brokers to: register with the state, allow consumers to exercise their data privacy rights, and publicly post the annual number of requests they receive from California consumers. We find that a majority of brokers ignore mandated disclosure requirements and add friction to rights request processes, making it challenging for consumers to exercise their rights. 

These findings also matter in the context of generative AI development as novel datasets become ever more valuable for training AI systems. As the 2026 California data broker registry demonstrates, 32 brokers currently sell data to generative AI developers. To ensure that consumers can actively exercise their data privacy rights and that regulators and researchers can adequately monitor and assess data laws, policymakers should consider implementing similar data broker registration laws across the nation. Such legislation best serves consumers and researchers if it includes automated privacy rights request processes, standardized reporting practices, and the ability for consumers to pursue a private right of action. 

Introduction 

Most U.S. consumers are generally aware that their data is collected by the businesses they interact with directly. Fewer are knowledgeable about the wide-reaching third-party data collection ecosystem that exists alongside the websites and apps they visit regularly. Data brokers are the third-party companies that collect and sell the data of consumers with whom they do not have a first-party relationship. Some have over 10,000 different data types on offer for purchase by other businesses, individuals, and governments. Along with concrete behavioral data collected about consumers, brokers also make and sell inferences about future behavior — such as whether a consumer is likely to buy a product, take up a hobby, or need a specific service.

Many use cases for this data can be beneficial or benign, such as public health research, fraud detection, and identity verification. However, broker data has also been used in instances of political violence and to identify military personnel. For example, in 2020, a disgruntled lawyer used publicly available data available online to target District Judge Esther Salas and fatally shoot her son outside their New Jersey home. Broker data is also used to shape financial decisions that can have allocative harms. In 2024, General Motors was found to be selling their customers’ driving data without explicit consent to data brokers, who in turn used the data to create risk scoring products for auto insurance companies. The sales were discovered after many GM auto owners experienced rate increases, were dropped from their insurance policies, or were unable to find new auto insurance.

Such threats have fueled calls to regulate data brokers for over a decade, yet only four states currently do so. Under the California Consumer Privacy Act (CCPA) of 2018, data brokers must allow consumers to exercise their privacy rights to have their data deleted, corrected, and not sold to others. In addition, brokers must disclose what personal information is being collected, sold, or shared, and to limit the use and disclosure of sensitive personal information when requested by consumers. California’s 2023 Delete Act requires brokers to publicly post the number of requests they receive from consumers in the prior calendar year. The goal of this requirement is to increase accountability by crowdsourcing compliance through the direct disclosure of information to the public. However, to date no other researchers have studied brokers’ compliance with either of these laws.

Several data brokers also sell data to companies building generative AI, information that is newly disclosed in the 2026 California broker registry. Little is known regarding how generative AI developers might use broker-purchased data, and there are no transparency requirements that mandate any detailed disclosure. 

Read Paper
Share
Link copied to clipboard!
Authors
  • Anna-Maria Gueorguieva
    Anna-Maria Gueorguieva
  • Jennifer King
    Jennifer King
  • Apoorva Panidapu
    Apoorva Panidapu
  • Dan Ho headshot
    Daniel E. Ho
Related
  • Data Privacy and Foundation Models: Can We Have Both?
    Jennifer King, Tiffany Saade
    Quick ReadApr 08
    issue brief

    This brief examines the privacy risks foundation models pose to individuals and society, and governance mechanisms needed to address them.

Related Publications

Designing Loyalty: AI Agents and Conflicts of Interest
Ella Genasci Smith, Victor Y. Wu, Jennifer King
Quick ReadAug 25, 2026
Issue Brief

This brief examines the conflict-of-interest risks posed by AI agents and calls for imposing a duty of loyalty on developers and deployers.

Issue Brief

Designing Loyalty: AI Agents and Conflicts of Interest

Ella Genasci Smith, Victor Y. Wu, Jennifer King
Privacy, Safety, SecurityRegulation, Policy, GovernanceIndustry, InnovationQuick ReadAug 25

This brief examines the conflict-of-interest risks posed by AI agents and calls for imposing a duty of loyalty on developers and deployers.

The World Model and Spatial Intelligence Era: Governing AI Beyond Language
Daniel Zhang, Russell Wald, Ehsan Adeli, Elena Cryst, Daniel E. Ho, Caroline Meinhardt, Jiajun Wu, Amy Zegart, Fei-Fei Li
Quick ReadJul 27, 2026
Issue Brief

This brief highlights the emergence of world models and outlines a first-of-its-kind governance and policy agenda for the technology.

Issue Brief

The World Model and Spatial Intelligence Era: Governing AI Beyond Language

Daniel Zhang, Russell Wald, Ehsan Adeli, Elena Cryst, Daniel E. Ho, Caroline Meinhardt, Jiajun Wu, Amy Zegart, Fei-Fei Li
Foundation ModelsRegulation, Policy, GovernanceIndustry, InnovationSpatial IntelligenceQuick ReadJul 27

This brief highlights the emergence of world models and outlines a first-of-its-kind governance and policy agenda for the technology.

Operationalizing Real-Time Monitoring of Clinical AI
Zhongnan Fang, Lina Cheuy, Hye Sun Na, Akshay Chaudhari, David B. Larson
Quick ReadMay 14, 2026
Policy Brief

This brief demonstrates how real-time monitoring can address critical gaps in the oversight of radiological AI tools.

Policy Brief

Operationalizing Real-Time Monitoring of Clinical AI

Zhongnan Fang, Lina Cheuy, Hye Sun Na, Akshay Chaudhari, David B. Larson
HealthcareRegulation, Policy, GovernanceQuick ReadMay 14

This brief demonstrates how real-time monitoring can address critical gaps in the oversight of radiological AI tools.

Toward Responsible AI in Health Insurance Decision-Making
Michelle Mello, Artem Trotsyuk, Abdoul Jalil Djiberou Mahamadou, Danton Char
Quick ReadFeb 10, 2026
Policy Brief

This brief proposes governance mechanisms for the growing use of AI in health insurance utilization review.

Policy Brief

Toward Responsible AI in Health Insurance Decision-Making

Michelle Mello, Artem Trotsyuk, Abdoul Jalil Djiberou Mahamadou, Danton Char
HealthcareRegulation, Policy, GovernanceQuick ReadFeb 10

This brief proposes governance mechanisms for the growing use of AI in health insurance utilization review.