Stanford CIS

Regulating Data Brokers in the Age of AI: A California Case Study

By Jen King on

Technology, social media, and AI mediate our daily lives, raising urgent concerns about how businesses collect, share, and sell our data. This collection process is largely invisible, occurring in our background use of apps, websites, and devices, without meaningful notice. The scale of this data collection is staggering: Billions of data points are generated and distributed each day. Data brokers — third-party companies that collect and exchange consumer data with whom they do not have first-party relationships — are key players in this opaque data-sharing ecosystem. The data that brokers make available for a price can include personal addresses, phone numbers, credit history, as well as predictive profiles assessing an individual’s purchasing habits, insurance risk, and much more. All of this data can be used in ways that have harmful downstream effects for consumers, yet the broker ecosystem remains largely opaque. 

In our paper “Privacy Without Remedy: An Assessment of Data Broker Compliance with California Privacy Law,” we assess data broker compliance with the California Consumer Privacy Act and the Delete Act. California is widely seen to be at the frontier of comprehensive consumer privacy law, and these two acts are the first in the nation to require data brokers to: register with the state, allow consumers to exercise their data privacy rights, and publicly post the annual number of requests they receive from California consumers. We find that a majority of brokers ignore mandated disclosure requirements and add friction to rights request processes, making it challenging for consumers to exercise their rights. 

These findings also matter in the context of generative AI development as novel datasets become ever more valuable for training AI systems. As the 2026 California data broker registry demonstrates, 32 brokers currently sell data to generative AI developers. To ensure that consumers can actively exercise their data privacy rights and that regulators and researchers can adequately monitor and assess data laws, policymakers should consider implementing similar data broker registration laws across the nation. Such legislation best serves consumers and researchers if it includes automated privacy rights request processes, standardized reporting practices, and the ability for consumers to pursue a private right of action. 

Authors:
Anna-Maria Gueorguieva
Jennifer King
Apoorva Panidapu
Daniel E. Ho

Download paper at HAI.