
Share
As data brokers continue to operate with little oversight, California’s privacy laws are struggling to protect consumers. Here’s why this matters and what needs to change.
In an age where technology permeates every aspect of our lives, the collection and sale of personal data have become a lucrative business. Data brokers-companies that gather and sell consumer information without explicit consent-are at the heart of this opaque ecosystem. These brokers collect vast amounts of data from various sources, including social media, online activities, and public records, often leading to significant privacy risks. In California, the state with some of the most stringent privacy laws, these risks are being scrutinized more closely than ever.
The California Consumer Privacy Act (CCPA) and the Delete Act were designed to give consumers control over their data by allowing them to request its deletion or opt out of collection. However, a recent assessment reveals that many data brokers are not complying with these regulations, leaving consumers vulnerable and without effective recourse.
Data brokers operate in a shadowy world where transparency is rare. They collect information such as personal addresses, phone numbers, credit histories, and even predictive profiles that assess purchasing habits and insurance risks. This data can be used for targeted advertising, but it also poses serious threats. Data breaches can expose sensitive information, leading to identity theft and financial fraud. The misuse of this data can exacerbate social issues like political violence and national security threats.
The CCPA, enacted in 2018, was hailed as a landmark piece of legislation for consumer privacy. It grants California residents the right to know what personal information is being collected, request its deletion, and opt out of its sale. The Delete Act, passed in 2021, further strengthens these protections by requiring data brokers to disclose the number of requests they receive each year.
Despite these legal safeguards, many data brokers are failing to meet their obligations under the CCPA and the Delete Act. A study conducted by Stanford University's Human-Centered Artificial Intelligence (HAI) program found that several brokers obstruct consumer requests for data deletion or opt-out, often through convoluted processes or outright non-compliance. This leaves consumers navigating a complex system with no clear path to remedy any harm caused by data misuse.
The implications of this non-compliance are far-reaching. As generative AI systems become more advanced, the demand for large datasets grows. Data brokers play a crucial role in supplying these datasets, which can then be used to train AI models. If these datasets contain biased or inaccurate information, the resulting AI systems may perpetuate harmful practices. For example, an AI tool trained on biased data could unfairly deny loan applications or job opportunities based on race, gender, or other protected characteristics.

The relationship between data brokers and AI developers is symbiotic. Data brokers collect and sell consumer data to AI companies, which then use this data to train their models. This interconnectedness means that any weaknesses in data privacy protections can have ripple effects throughout the tech industry. For instance, a recent lawsuit against OpenAI, the company behind ChatGPT, highlights the potential legal and ethical issues surrounding the use of personal data in AI development.
The lawsuit alleges that OpenAI used vast amounts of private data to train its AI models without proper consent, raising questions about the ethics and legality of such practices. This case underscores the need for more robust regulations that not only address the collection and sale of data but also ensure that this data is used ethically in AI development.
California’s efforts to regulate data brokers are a step in the right direction, but they fall short of providing comprehensive protection. The CCPA and the Delete Act are essential tools, but their effectiveness is undermined by non-compliance and the lack of enforcement mechanisms. To truly protect consumers, policymakers must consider stricter penalties for non-compliant brokers and provide clearer guidelines on how to exercise privacy rights.
The regulation of data brokers is not just a technical issue; it has profound implications for individual privacy and societal well-being. As AI systems become more integrated into our daily lives, the quality and integrity of the data they use will directly affect their outcomes. Ensuring that this data is collected ethically and used responsibly is crucial for building trust in technology and protecting vulnerable populations.
California’s experience serves as a cautionary tale for other states and countries considering similar regulations. While it is important to balance innovation with privacy, the current landscape shows that more must be done to safeguard consumer rights. By addressing the gaps in existing laws and holding data brokers accountable, we can create a more transparent and equitable data ecosystem.
In an era where personal data is increasingly valuable, the need for robust privacy protections has never been more urgent. It is time for policymakers to take decisive action to ensure that the benefits of AI are not overshadowed by the risks it poses to individual freedoms and societal health.
Tags
Original Sources
Regulating Data Brokers in the Age of AI: A California Case Study | Stanford HAI
↗ https://hai.stanford.edu/policy/regulating-data-brokers-in-the-age-of-ai-a-california-case-study
About the author
Amara's entry point into AI was an epidemiology role at a London research hospital, where she spent five years studying how digital health tools reached — or conspicuously failed to reach — underserved communities. Watching early algorithmic systems in healthcare quietly entrench existing inequalities, she redirected her career toward the systemic consequences of AI at scale. She covers AI through an unflinching lens: who benefits, who bears the cost, and what evidence actually says versus what the press release claims. Her writing is calm and precise, but she doesn't mistake balance for neutrality.
More from The Steward →This Week's Edition
17 August 2026
113 articles
Related Articles

FDA Panel Rejects Duchenne Muscular Dystrophy Drug, FTC Sues Hims & Hers for Data Sharing
Policy & Regulation · 3 min

FTC Sues Hims & Hers Over Privacy Breaches and Misleading Practices
Policy & Regulation · 4 min

HRSA Revises Controversial 340B Rebate Model Pilot Program Despite Provider Opposition
Policy & Regulation · 3 min
Related Articles

FDA Panel Rejects Duchenne Muscular Dystrophy Drug, FTC Sues Hims & Hers for Data Sharing
Policy & Regulation · 3 min

FTC Sues Hims & Hers Over Privacy Breaches and Misleading Practices
Policy & Regulation · 4 min

HRSA Revises Controversial 340B Rebate Model Pilot Program Despite Provider Opposition
Policy & Regulation · 3 min
More Stories
© 2026 Cedar & Bloom. All rights reserved.