It’s Time to Regulate Big Data: An Argument for Privacy in the Information Age

By Margaret Peterman, NCL Summer Communications Intern

How comfortable are you with someone seeing your purchase history? What about who you voted for? Your health data? Browsing history? Location?
If any of those questions made you anxious, it may be disturbing to realize that just about anyone can access your personal information—including minimally regulated data brokers who sell your information to private corporations and government agencies.
Data brokers are organizations that collect and sell consumers’ personal information to third-party groups—major brokers include LexisNexis, Experian, Acxiom, and Oracle—for use in marketing, political campaigns, and even government investigations. These organizations gather all kinds of data, from contact and demographic information to precise geolocation data and browsing history.
As a result of mass data collection, data brokers and online platforms have unprecedented levels of control over what consumers see and purchase online. Thousands of the online ads Americans see daily are shaped by complex data profiles built from consumers’ social media pages, browsing and click history, location data, and demographics. Even consumers’ most personal and private behaviors are being shaped by data collection. In 2022, Pray.com came under fire for sharing users’ personal prayers with third-party sources and advertising agencies, ensuring that even prayer is not excluded from a consumer’s data profile.
Consumers’ data is even used to shape access to certain programs or even price health insurance policies. In 2019, the Department of Housing and Urban Development sued Facebook for violating the Fair Housing Act by determining which users could see housing-related ads based on their race, religion, and nationality. In 2013, the Federal Trade Commission sued Equifax for selling consumer credit scores and mortgage information to companies advertising potentially predatory and fraudulent loan services. Insurance and actuarial companies use consumer data to create health risk profiles—inferred from what consumers wear, when they pay their bills, and what they post on social media, not actual health data.
AI has further complicated data privacy concerns. A growing number of Americans are relying on AI for daily use, and nearly three-quarters of businesses have adopted some form of AI technology in the workplace. But AI has not been a champion of data privacy. Users’ chats are funneled into models to train chatbots further. Countless musicians, programmers, authors, and news outlets have sued AI companies for using copyrighted work without consent. Generative AI chatbots like Anthropic’s Claude, OpenAI’s ChatGPT, and X’s Grok have all published user chats including personally identifiable information (PII) like phone numbers, emails, and healthcare data.
So why should we care about data privacy? After all, in an increasingly digitized society, it’s hard to fathom a world where we have control over our own data.
Data privacy is closely tied to protecting consumers’ rights. Advertising agencies represent a significant portion of data brokers’ clients, making up nearly 40% of the market share. When consumers see ads tailored to their personal preferences, they are far more likely to buy the advertised products or services. As targeted ads grow more specific to a consumer’s data profile, consumers are slowly deprived of their right to make independent choices in the marketplace.
Data privacy is also part of the larger debate over individual privacy in a post-9/11 world. Even with guarantees against domestic surveillance outlined in the Foreign Intelligence Surveillance Act and the Electronic Communications Privacy Act, “data broker loopholes” allow federal and state government agencies to purchase bulk data from brokers and social media sites for immigration enforcement, criminal investigations, and surveillance of protestors.
In the past few years, several state governments have passed laws attempting to rein in consumer data collection. Regulations like California’s Delete Act are promising on paper, but it remains to be seen how effective these laws will be in practice. A recent Stanford study found that only 9% of eligible data brokers were in compliance with California’s data privacy legislation nearly three years after its adoption. Hundreds of brokers have failed to register with state consumer protection agencies, violating multiple state laws and making it difficult to understand the role data brokers play in consumers’ lives.
It is now clear that the U.S. needs a national privacy guarantee. For too long, government, healthcare, and advertising organizations have utilized Americans’ data to build personalized, error-prone, and invasive data profiles at the expense of consumers. Without meaningful federal oversight, data brokers run roughshod over consumers’ rights. Congress and state governments need to prioritize consumers’ privacy rights and pass legislation that protects consumers from, and makes them aware of, predatory data-collection practices.