Your Data, Their Disregard: How California Data Brokers Are Failing to Protect Your Privacy Rights
The California Consumer Privacy act (CCPA) promised you control over your personal information. But a recent study reveals a troubling reality: many data brokers are simply ignoring your rights. Researchers at the University of California, Irvine, found that 43% of registered data brokers in California failed to respond to requests for data access.This isn’t just a technical glitch; it’s a blatant disregard for the law adn your basic privacy.
What Does This Mean For You?
Data brokers collect and sell information about you – everything from your shopping habits to your location data. The CCPA grants you the right to know what information they hold about you, and to request its deletion. However, this right is meaningless if companies refuse to even acknowledge your requests.
Hear’s a breakdown of the problem:
Widespread Non-Compliance: over four in ten companies are actively ignoring legal obligations.
Difficult Process: Filing a data request is already time-consuming and complex.
Lack of Accountability: Companies are betting they won’t face consequences for ignoring the law.
This isn’t just frustrating; it’s a violation of your rights under the CCPA.
What You Can Do: Taking Action Against Data Broker Non-Compliance
If a data broker ignores your request, you have options. Don’t let them get away with it.
- File a Complaint with the California Privacy Protection Agency (CPPA): https://cppa.ca.gov/webapplications/complaint
- File a Complaint with the California attorney General’s Office: https://oag.ca.gov/contact/consumer-complaint-against-business-or-company
Reporting these violations is crucial. It sends a message that non-compliance will not be tolerated.
Why Are They ignoring You? The Cost of Doing business
Regrettably, the current system allows many companies to operate with impunity. They frequently enough calculate that the risk of getting caught – and the potential penalties – are lower than the cost of complying with data requests. This is a direct result of weakening the CCPA during its legislative phase.
originally, the CCPA included a private right of action, allowing individuals to sue companies for privacy violations. however,corporate lobbying successfully removed this crucial provision. Without the threat of individual lawsuits, the incentive for compliance diminishes substantially.
The Fight for Stronger Privacy Laws
At the Electronic Frontier Foundation (EFF), we believe that strong privacy laws require real teeth. We are actively advocating for:
A Private Right of Action: Empowering individuals to sue companies for violating their privacy. This creates a powerful deterrent.
Meaningful Penalties: Ensuring that fines and other consequences are considerable enough to discourage non-compliance.
Robust enforcement: Urging the CPPA and the Attorney General’s Office to actively investigate and prosecute violations.
We’ve seen the impact of strong enforcement in other areas, like biometric privacy. A recent settlement in Illinois demonstrates that companies will pay attention when faced with notable financial risk. (See: