So far, over 300,000 Californians have demanded that data brokers erase information in a process slated to begin on August 1st.
What happened
On August 1st, California data brokers will be required to begin erasing information from their systems, as part of the Delete Act. The Delete Act works in tandem with the Delete Request and Opt-Out Platform (DROP), which is a state-run platform created by the Delete Act that will allow California residents to submit a single deletion request that will automatically require registered data brokers to delete the data it holds on the individual.
In the know
Data brokers have come into the limelight with the increased awareness of the pixel which has caused a slew of lawsuits in the healthcare sector. These pixels, often owned and operated by Google or Meta, are commonly found on websites, tracking data and then selling it to third parties. Data brokers work in a similar way; they are companies that collect personal information from public records, online activities, and purchase histories. Individuals who opt-into reward programs, email list servers, social media, and more are often agreeing to their data being sold to brokers.
In our ever-increasing world of AI, it’s become common for brokers to aggregate and compile profiles on individuals using AI tools. Data brokers go on to resell data for a myriad of purposes, like targeted ads, background checks, and can even be used by the government for surveillance purposes. According to PrivacyRights.org, some brokers have sold data on military personnel and protestors to foreign adversaries.
Read more:
- Atrium Health agrees to $1.8M settlement over Meta Pixel lawsuit
- Allina Health pays $12.5M over pixel tracking on patient portal
- Google, Flo Health, and Flurry to pay $59.5 million in pixel lawsuit
Going deeper
As of July 1st, 322,292 Californians have signed up to have their data deleted, according to Mercury News, but that still represents less than 1% of California’s population. Beginning August 1st, data brokers will have to start accessing the deletion requests. From there, they’ll have an additional 45 days to report what data they have purged to the California Agency, known as CalPrivacy, and the people who have signed up. Brokers will not be allowed to sell the data instead of deleting it.
According to CalPrivacy’s registry, there are nearly 600 data brokers operating in California. 110 sell people’s precise locations, 40 sell identity data that may include Social Security numbers, and 70 sell data on gender identity. Additionally, some brokers sell data related to reproductive health or union membership. Numerous brokers sell data to the state, police, foreign entities, or developers of generative AI. Eighteen of the brokers sell minors’ data. Minors will be eligible to sign-up for deletion or their parents can complete the process for them.
What was said
CalPrivacy director Tom Kemp encouraged people to take advantage of this option. On data brokers, he shared, “Our data is their product, and they don’t sell it back to us….They sell it to other people. We don’t have control or say over who buys it. It’s not healthy to have all our personal information sloshing around. For the bad guys, it’s cheaper and easier for them to use data brokers and buy lists of people.”
For California residents who choose to opt-in, Kemp says, “You will reduce your footprint out there, and you should see less targeted advertising based on your demographics, you will see less text scams and email spams, and you will see, potentially, less attempts to defraud you.”
The big picture
California continues to be the leader when it comes to data protection in the United States, but other states have begun developing and enacting comprehensive data privacy laws, including Colorado, Florida, and 18 others. Most laws generally give individuals the right to know how their data is being collected and used, but to varying extents. The US still ultimately has a patchwork of data protection laws, which can be confusing for individuals who move across states. As we see the results of CalPrivacy, which could include decreased spam calls and emails, and even potentially decreased risk of fraud, other states are likely to consider implementing their own version of the Delete Act.
FAQs
How are data brokers legal?
According to the National Cybersecurity Alliance, data brokers are legal in the US because there is no federal policy restricting them. In Europe, the General Data Protection Regulation (GDPR) now requires data brokers to obtain consumer consent, but no law in the US applies specifically to data brokers. Some states, including California, Colorado, and Vermont, have additional laws for data brokers.
What can people outside of California do to reduce data brokers’ access to their information?
People should generally limit what information they provide to online sites and receive their privacy settings on their phone or computer. Generally, if an individual doesn’t know what or why a piece of data is being collected, they should opt out if possible. Individuals can also visit data brokerage websites and submit an opt-out request to each one, although without any legal requirements, brokers may deny the requests.
