NVDA 217.50 ▼0.02%GOOGL 343.80 ▼3.84%MSFT 503.81 ▼0.44%AMD 474.32 ▲1.01%INTC 97.71 ▲0.19%TSMC 422.06 ▲0.86%AMZN 272.27 ▼2.09%META 599.12 ▲0.71%AAPL 304.91 ▼1.09%PLTR 174.94 ▼0.17%
Markets at last close

Policy

Data brokers fall short of California privacy rules

·1 min read

Stanford RegLab and Stanford HAI found widespread noncompliance among data brokers subject to California’s 2023 Delete Act, the first state law regulating broker practices. The law applies to businesses collecting data from at least 10 million California consumers and gives residents rights to delete data, correct personal information, and learn what information is being sold.

Only 9% of self-registered brokers fully complied with transparency requirements, while 45% did not submit any rights request metrics to the California Privacy Protection Agency. Researchers manually reviewed privacy policies for all 522 self-registered data brokers in 2025 and found that 64% added friction to consumer requests through confusing designs, multiple forms, or excessive verification steps, practices described as prohibited dark patterns.

Data brokers were required by July 1, 2025 to report rights request activity from the past two years, including response times, approvals, and denials. The 2026 Data Broker Registry now requires disclosures on whether brokers have sold data to generative AI developers, and more than 30 companies have done so. California’s DROP platform went live on August 1, allowing residents to send deletion and opt-out requests to all registered brokers, which must delete covered personal information every 45 days. Third-party audits begin by 2028 and must occur every three years.

Originally reported by hai.stanford.eduRead the source →
Related coverage