July 31, 2026

CIPL Launches Policy Series on Data Brokers in the United States

CIPL is pleased to announce the publication of a new policy series examining the role of data brokers in the United States. The three-paper series explores the evolving data broker landscape and proposes solutions that recognize the breadth of the industry, the benefits of proportionate, risk-based regulation, and the importance of robust accountability mechanisms.

Paper 1: Understanding Data Brokers: Definitions, Regulations, and Enforcement in the United States

Data brokers have become key players in the modern digital economy and society, operating at the intersection of commerce, privacy, and technology. Despite their ubiquity and impact, data brokers remain poorly understood by policymakers, disparately regulated by existing legal frameworks, and largely invisible to the individuals whose information fuels their operations.

The first paper in the series examines how data brokers are defined and regulated at both the federal and state levels. It explains how this fragmented legal landscape leaves consumers with inconsistent protections while creating complexity for regulated entities.

Paper 2: Data Brokers and Proportionate Regulation: Balancing Commercial Value, Consumer Protection, and Civil Rights

The data broker industry defies simplistic characterization. Its complexity demands regulatory approaches that differentiate among practices and use cases. Policymakers should refrain from imposing uniform restrictions that eliminate beneficial activities and from creating categorical bans that drive harmful practices underground. Treating data brokers identically through blanket regulation risks eliminating benefits without adequately addressing harms.

The second paper in the series proposes the adoption of a proportionate, risk-based regulatory framework to protect consumers from harms while preserving legitimate commercial activities.

Paper 3: Data Stewardship and Accountability: Operationalizing Responsible Data Broker Practices

Laws and regulations establish what organizations must do. Accountability gives them the means to do it. This distinction—between legal obligation and operational reality—represents the critical gap in privacy protection that prescriptive rules alone cannot bridge.

The third paper in the series explores how data brokers can operationalize regulatory obligations through data stewardship, accountability structures, and governance practices.