19 August 2026
The data broker industry has been operating in the shadows for decades, quietly buying, selling, and aggregating personal information about nearly every adult in the United States and increasingly around the world. Most people have no idea how deeply their digital footprint has been commodified. That is about to change, and not because companies suddenly developed a conscience.
The next few years will bring a perfect storm of regulatory pressure, technological shifts, and changing consumer expectations that will fundamentally reshape how data brokers operate. If you are a business leader, a privacy professional, or just someone who cares about where your personal information ends up, you need to understand what is coming. The days of opaque data trading are numbered, but what replaces them will not necessarily be better unless we pay attention.

The largest brokers like Acxiom, Experian, and Oracle Data Cloud maintain profiles on hundreds of millions of individuals. These profiles can contain thousands of data points, from basic demographics to extremely sensitive attributes like health conditions, political affiliations, sexual orientation, or financial distress. Some of this data is collected with consent, but a great deal of it is scraped, inferred, or purchased from third parties without the individual ever knowing.
The industry has essentially operated without meaningful federal oversight in the United States. The Fair Credit Reporting Act regulates data used for credit, employment, and insurance decisions, but most broker activity falls outside that scope. The California Consumer Privacy Act and similar state laws have forced some transparency, but they are fragmented and often poorly enforced. This regulatory vacuum has allowed a market worth tens of billions of dollars to grow with almost no accountability.
The second force is consumer awareness. High-profile data breaches, the Cambridge Analytica scandal, and a steady stream of investigative journalism have made the public far more suspicious of how their data is used. A 2023 survey from the Pew Research Center found that a majority of Americans believe they have little control over how companies use their personal information. That skepticism is translating into political pressure, and politicians are responding.
The third force is technology. The rise of on-device processing, differential privacy, federated learning, and homomorphic encryption is making it possible to derive value from data without actually collecting and storing raw personal information. This is a direct threat to the traditional broker business model, which depends on hoarding data. The brokers that survive will be the ones that figure out how to provide insights without owning the underlying data.

California has already amended its privacy law with the California Privacy Rights Act, which gives consumers the right to delete their data, correct inaccuracies, and limit the use of sensitive personal information. Colorado, Connecticut, Utah, and Virginia have passed their own comprehensive laws, and more states are following. The problem is that these laws have different definitions, different exemptions, and different enforcement mechanisms. A broker operating nationally must comply with all of them simultaneously, which is expensive and technically demanding.
The Federal Trade Commission is not waiting for Congress. It has brought enforcement actions against brokers like Kaye, which sold location data that could be used to track people into sensitive locations like abortion clinics and places of worship. The FTC is also considering a rule that would require brokers to register with the agency, disclose their data collection practices, and provide consumers with a clear way to opt out. If that rule goes into effect, it will be the first federal regulation specifically aimed at the industry.
Internationally, the picture is even more complex. The European Union's General Data Protection Regulation already imposes strict obligations on data brokers, and the upcoming Data Governance Act and Data Act will add more layers. The United Kingdom is charting its own course with a post-Brexit data protection framework that is more business-friendly but still requires meaningful consumer protections. Companies that operate globally will need to navigate a maze of requirements that sometimes conflict with each other.
These registries will not just be bureaucratic formalities. They will become the first place consumers, journalists, and regulators look to understand who is collecting data and how. This will create enormous reputational risk for brokers that have built their business on secrecy. The smart brokers are already preparing for this by cleaning up their data practices and being more transparent about what they do.
The registry data will also enable new forms of analysis. Researchers will be able to map the flow of data between brokers and their clients, revealing the hidden connections between companies that consumers would never suspect. This transparency will likely lead to public pressure on companies that buy data from disreputable brokers, creating a "clean data supply chain" movement similar to what happened in the coffee and chocolate industries.
The first reason is cost. Data breaches and regulatory fines are making raw data ownership increasingly expensive. The average cost of a data breach is now over four million dollars, and that figure does not include the reputational damage or the cost of litigation. Brokers are sitting on massive databases that are tempting targets for hackers, and they are finding it harder to get cyber insurance at reasonable rates.
The second reason is accuracy. The data that brokers collect is often stale, incomplete, or just wrong. A study from the University of Pennsylvania found that commercial data brokers had error rates of up to 30 percent on some attributes. As consumers become more aware of their rights, they are correcting or deleting their data, which makes the remaining data less reliable. The value proposition of "we have data on everyone" is becoming "we have inaccurate data on fewer people."
The third reason is the emergence of alternative models. Instead of selling raw data, brokers will increasingly sell insights, predictions, and analytics. They will use the data they have to train machine learning models, then sell access to those models rather than the underlying data. This is already happening in the credit scoring and fraud detection industries, where companies like FICO and Zest AI provide scoring models without exposing the data that powers them.
Differential privacy works by adding carefully calibrated noise to data queries, making it impossible to identify any individual while still getting accurate aggregate results. Apple and Google use this technique to collect usage statistics from their users, and it is now practical enough for broader commercial use. A data broker could use differential privacy to sell insights about consumer behavior without ever revealing who those consumers are.
Federated learning takes a different approach. Instead of bringing data to a central server, the model is sent to the data. A broker could deploy a machine learning model to a client's device or server, train it on the client's data locally, and then only receive the updated model parameters. This means the client never has to share their raw data, and the broker never has to store it.
Secure multi-party computation is the most complex of the three, but it offers the strongest guarantees. It allows multiple parties to jointly compute a function on their combined data without any party seeing the other's inputs. This is particularly useful for fraud detection and risk assessment, where multiple financial institutions might want to identify suspicious patterns without revealing their customer lists.
These technologies are not hypothetical. They are being deployed in production systems today, and their cost and complexity are dropping rapidly. Within the next five years, they will be standard tools for any data broker that wants to stay relevant. The brokers that invest in PETs will be able to offer clients powerful insights with much lower privacy risk. The brokers that do not will find themselves locked out of the most lucrative markets.
This will likely take the form of granular, purpose-based consent. Instead of a blanket agreement to "share data with partners," consumers will be asked to opt in to specific uses like personalized advertising, credit scoring, or health research. They will also be given the ability to withdraw consent at any time, and brokers will be required to honor that withdrawal within a reasonable timeframe.
The challenge for brokers is that meaningful consent will dramatically reduce the amount of data they can collect. Most people, when given a real choice, will decline to share their data for advertising purposes. This is not speculation. Studies of the European Union's cookie consent rules have shown that only about 10 to 20 percent of users accept all cookies when given a clear choice.
Brokers will need to find ways to create value for consumers in exchange for their data. This is already happening in some sectors. Insurance companies offer usage-based policies that reward drivers for sharing their driving data. Retailers offer loyalty programs with genuine discounts in exchange for purchase history. The brokers that thrive will be the ones that help their clients create these value exchanges, rather than simply vacuuming up data in the background.
The combination of cookie deprecation, stricter consent rules, and new privacy laws will make the old model of audience targeting nearly impossible. Advertisers will have to rely on contextual targeting, which places ads based on the content of the page rather than the identity of the user. This is less precise but much more privacy-friendly, and it is already seeing a resurgence.
Data brokers will pivot to providing the technology and the data for contextual targeting. They will analyze web pages in real time to understand their meaning and sentiment, then match ads to that context. This requires a very different set of skills and data assets than traditional audience targeting, and not all brokers will make the transition successfully.
There will also be a shift toward first-party data. Companies that have direct relationships with their customers, like retailers, banks, and media companies, will increasingly use their own data for marketing and advertising. This is more reliable and more compliant than buying third-party data. Brokers will position themselves as consultants and technology providers that help these companies maximize the value of their first-party data, rather than as sellers of third-party data.
This new archetype will have several defining characteristics. It will maintain a public registry of its data sources, collection practices, and clients. It will use privacy-enhancing technologies to minimize the risk of re-identification. It will conduct regular privacy impact assessments and publish the results. It will offer consumers a single dashboard where they can see every piece of data the broker holds on them and request deletion with one click.
This might sound like a fantasy, but it is already starting to happen. Companies like Jumbo Privacy and DeleteMe are building consumer-facing tools that help people manage their data across multiple brokers. Some traditional brokers are starting to offer these features proactively, recognizing that transparency is becoming a competitive advantage rather than a threat.
The privacy-forward broker will not be cheaper or faster than the old model. It will be more expensive, because it is doing more work. But it will be trusted, and in a world where trust is increasingly scarce, that is worth a premium.
The first risk is regulatory capture. The data broker industry has deep pockets and a history of lobbying against meaningful reform. It is entirely possible that the federal privacy law that eventually passes will be so full of exemptions and carve-outs that it does more harm than good. The state laws are a counterbalance, but they are inconsistent and underfunded.
The second risk is the commodification of privacy. As PETs become more common, there is a danger that companies will use them as a fig leaf to avoid real accountability. They will say, "We use differential privacy, so we are safe," when in fact their implementation is flawed and their data practices are still opaque. Regulators will need to develop technical expertise to audit these claims, and that is not happening fast enough.
The third risk is the consolidation of power. The data broker industry is already highly concentrated, and the cost of complying with new regulations will push smaller players out of the market. This could lead to a situation where a few giant companies control even more data and have even more influence over our digital lives. The near future might not be a more private world, but a more monopolized one.
The fourth risk is the rise of the "shadow data" market. As legitimate brokers come under pressure, some of their business will move offshore or into unregulated channels. There will always be companies willing to sell sensitive data to anyone who pays, and they will not care about consent or transparency. The challenge for regulators will be to crack down on these shadow markets without driving more activity underground.
If you are a consumer, the near future is a time to be proactive. Exercise your rights under the laws that already exist. Send deletion requests to the major brokers. Use the opt-out mechanisms that are already available. The more people do this, the more pressure it puts on the industry to change. Do not wait for a federal law to save you, because it might not come, and even if it does, it might not be strong enough.
If you are a policymaker, the near future is a time to be bold. The public is on your side, and the technology exists to make real change possible. Do not settle for a law that merely requires disclosure and consent. Require data minimization, meaning brokers should only collect what they actually need. Require algorithmic transparency, so that consumers can understand why they are being targeted or scored. And fund enforcement, because a law without enforcement is just a suggestion.
The brokers that survive will be the ones that embrace the change rather than fighting it. They will build trust with consumers, invest in privacy-enhancing technologies, and find ways to create value without violating basic rights. The brokers that do not will face extinction, and the world will not mourn their passing.
We are moving toward a future where data is still valuable, but its collection and use will be constrained by law, technology, and public opinion. That future is not a distant dream. It is being built right now, and everyone has a role to play in shaping it. The question is not whether the data broker industry will change, but whether we will be ready for the change when it comes.
all images in this post were generated using AI tools
Category:
Digital PrivacyAuthor:
Adeline Taylor