The Data Broker Economy: The Consumer File Outside the Law

The Data Broker Economy: The Consumer File Outside the Law | HL Hunt
Institutional Outlook

The Data Broker Economy: The Consumer File Outside the Law

The Fair Credit Reporting Act was passed in 1970 in response to a data surveillance industry Congress found alarming — companies compiling files on tens of millions of Americans covering their employment, income, bill-paying, marital status, and, in the language of the era, their "habits, character and morals." The statute imposed accuracy duties, access rights, and use limits on that industry. Fifty-five years later, a far larger trade in comparable information operates substantially outside that perimeter, selling demographic, financial, health, location, and behavioral data to essentially anyone who pays. This report examines how that happened, why the boundary is so contested, and what it means that the country's most consequential consumer files come in both a regulated and an unregulated edition.

By the HL Hunt Research Desk · 25 min read · Updated July 2026

The core thesis

This desk has spent considerable effort on the file that lenders read — its accuracy, its dispute mechanics, the specialty agencies that gate housing and banking, and the identity infrastructure underneath all of it. Our thesis here is that this analysis has been examining the regulated fraction of a much larger system, and that the unregulated remainder is where the consumer protections a reader might assume exist mostly don't.

The structural insight is that the FCRA regulates a purpose, not a dataset. The statute attaches obligations to information assembled for use in decisions about credit, employment, insurance, and housing — which means the identical data, sold for marketing, identity verification, risk scoring outside those categories, or general commercial use, can travel without accuracy duties, without consumer access, without dispute rights, and without the permissible purpose limits that govern a credit report. That is not a loophole in the ordinary sense; it's the boundary the statute draws. But it produces a result that would surprise most people: a company can hold two files on you, one you're legally entitled to see and correct, and one you may not even be able to learn exists.

The second half of the thesis concerns consequences. Because credit decisions are the most scrutinized use of consumer data, the analytical attention has followed them — but the data flowing outside the perimeter affects outcomes too, through pricing, targeting, verification, and increasingly through the risk models that feed decisions adjacent to credit. And because the unregulated side has no accuracy obligation, errors there are not merely uncorrected but uncorrectable, since there's no dispute right to exercise. The error equilibrium our specialty reporting analysis identified — where nobody reads a file, so nobody disputes it, so errors persist structurally — reaches its purest form here, where there is often no file to read at all.

The FCRA regulates a purpose, not a dataset. Sell the same information for a different reason and the accuracy duties, access rights, and dispute mechanisms simply don't attach.

What the industry actually is

"Data broker" covers a range of businesses with meaningfully different characteristics, which is part of why regulating the category has proven difficult.

TypeWhat they sellRegulatory position
Consumer reporting agenciesCredit reports and scores for lending, employment, insurance, tenancyClearly FCRA-covered; also subject to financial privacy rules
Specialty reporting agenciesTenant, account, employment, insurance, and medical screeningFCRA-covered, with far less public scrutiny
People-search companiesAddresses, phone numbers, relatives, property recordsGenerally claim non-FCRA status while disclaiming permissible-purpose uses
Marketing data compilersDemographic, behavioral, purchase, and inferred-interest segmentsTypically outside the FCRA; subject to state privacy law where it applies
Location and mobile data firmsDevice-derived movement patterns and place visitationLargely outside the FCRA; the subject of most recent enforcement attention
Identity and verification providersData supporting identity proofing and fraud screeningMixed — some uses fall inside the perimeter, many don't

Two observations from that table. First, the same corporate group frequently occupies several rows. Major consumer reporting agencies also sell employment and income verification, marketing data, analytics, and identity products — some regulated as consumer reports, some not, from the same underlying infrastructure. Second, the boundary runs through products rather than companies, which is what makes both compliance and enforcement complicated: the question is never simply "is this firm a CRA," but "is this specific product, sold for this specific use, a consumer report."

The FCRA perimeter and how it's drawn

The statutory architecture rests on two definitions. A consumer report is, broadly, information bearing on a consumer's creditworthiness, character, general reputation, or personal characteristics that is used or expected to be used in establishing eligibility for credit, insurance, employment, or certain other purposes. A consumer reporting agency is an entity that regularly assembles such information for the purpose of furnishing consumer reports to third parties.

Both definitions turn on purpose and expected use. That produces the industry's central defensive position: a company selling identical data for a use outside the enumerated categories argues it is not furnishing consumer reports, and therefore is not a consumer reporting agency, and therefore owes none of the statute's duties — no accuracy obligation, no consumer file disclosure, no dispute investigation, no adverse action linkage, and no permissible purpose restriction on who may buy.

Regulators have characterized this as widespread evasion, with one description capturing the frustration precisely: too many companies that walk and quack like consumer reporting agencies claim on their websites that they are not FCRA-covered and provide consumers none of the rights they would otherwise hold. The industry's counter is that it is following the statute as written, and that expanding the definition by interpretation would sweep in ordinary commercial data use Congress never contemplated. Both positions are coherent, which is why the question has stayed unresolved for decades rather than being settled by obvious argument.

The arbitrage: same data, two regimes

The practical consequence is a set of asymmetries that would be difficult to defend if designed deliberately.

  • Accuracy. A credit bureau must follow reasonable procedures to assure maximum possible accuracy. A marketing data compiler holding an inference that you have a particular health condition, income level, or financial vulnerability generally has no comparable obligation — and the inference may be wrong.
  • Access. You can obtain your credit file, and under the specialty agency framework you can obtain those files too. There is often no equivalent right to see what an unregulated broker holds, which means you cannot evaluate accuracy even in principle.
  • Dispute. The FCRA's investigation and correction machinery — the process our dispute analysis examines at length — has no counterpart outside the perimeter. An error is permanent by default.
  • Permissible purpose. A consumer report may only be furnished for enumerated purposes. Data sold outside the perimeter can generally go to whoever pays, which is the mechanism behind the safety concerns that prompted several states to protect judges and law enforcement officers after violent incidents traced to purchased address information.
  • Adverse action. When a consumer report contributes to a denial, you're entitled to notice and the reasons. When unregulated data contributes to a price, an offer you never received, or a verification failure, there is typically no notice at all — the invisible decline problem our fraud detection analysis identifies, arriving through a different door.

The arbitrage is not merely theoretical. Where the same underlying data can be sold under either regime depending on the stated purpose, there is a structural incentive to characterize products as falling outside — and the consumer, who cannot see the transaction, has no way to know which regime governed the information used about them.

Two files, one person
A company can hold information about you that's regulated when sold for lending and unregulated when sold for anything else — with accuracy duties, access rights, and dispute mechanisms attaching to one version and not the other.

The federal rule that wasn't

In December 2024, the Consumer Financial Protection Bureau proposed a rule amending Regulation V — which implements the FCRA — to clarify that data brokers selling certain sensitive consumer information qualify as consumer reporting agencies. The proposal would have imposed accuracy requirements, consumer access rights, and safeguards against misuse; limited the sale of identifiers such as Social Security and phone numbers; restricted the sharing of financial information including income to essential purposes; and required affirmative consumer authorization for certain sales. The Bureau described the proposal as grounded in extensive market monitoring that revealed consumer protections being flouted at scale, and framed it partly as a national security matter, noting that adversaries seeking data on Americans often need not hack anything when brokers will sell it.

The rule was not finalized. The Bureau subsequently concluded that the rulemaking was not necessary or appropriate at that time, citing inconsistencies with its interpretation of the statute, and withdrew it. Whatever one's view of the merits, the practical outcome is clear: there remains no comprehensive federal framework governing data brokers, and the FCRA perimeter remains where the statute and case law leave it.

The episode is instructive beyond its subject. It demonstrates that the boundary is an interpretive question rather than a settled one — the same statutory text supported a proposal to extend coverage and a decision that extension was inappropriate, within about a year. For anyone building products that touch consumer data, that instability is itself a planning fact: the perimeter can move, and a business model that depends on sitting just outside it carries a regulatory risk that a business model comfortably inside does not. That's the same "own the compliance rather than rent proximity to it" logic our licensing analysis applies to money movement.

The state patchwork

With federal action stalled, states have become the operative regulators. Four — California, Vermont, Texas, and Oregon — have enacted data broker registry laws. The common architecture requires third-party data brokers, meaning companies selling personal data they did not collect directly from their own customers, to register with a state agency, to honor consumer requests to delete data or stop collecting and selling it, and to meet data security requirements.

California has moved furthest, including through legislation signed in October 2025 continuing to build out its framework, and has pursued a mechanism intended to let a consumer make a single deletion request that registered brokers must honor — a meaningful design choice, since the alternative is submitting individual requests to hundreds of companies. Oregon's approach intersects with its broader privacy statute in a way that lets consumers request a list of specific third parties that received their data. New York has considered legislation targeting the sale of information about service members.

Two limitations are worth stating honestly. Registration is not regulation of substance — knowing which companies participate is a precondition for oversight, not oversight itself, and registry laws impose comparatively light obligations relative to the FCRA. And state coverage is geographic, so the protections available to a consumer depend on where they live, producing exactly the kind of variation our garnishment analysis documents in a different context: identical circumstances, different outcomes, determined by state lines.

The exemption problem in privacy laws

Here is the wrinkle that makes the overall picture worse rather than better, and it's genuinely counterintuitive.

Every general state privacy law enacted to date — nineteen as of a recent count — includes exemptions for data or entities regulated by the FCRA and by financial privacy law. The logic is reasonable on its face: avoid duplicative regulation of information already governed by federal statute. The effect in practice is a gap. Because the federal statutes cover some activities of these companies and not others, and state privacy laws then exempt the companies or the data categories, information can end up covered by neither: outside the FCRA because it wasn't furnished for an enumerated purpose, and outside the state privacy law because it falls within an exemption written for federally regulated data.

Advocates analyzing this have recommended narrowing exemptions from entity-level to activity-level, so that a company regulated for one product doesn't obtain blanket exemption for all its others. Whether that's the right fix is a policy question; the structural observation is not: overlapping regimes with mismatched boundaries can produce less coverage than either would alone, and this is one of the clearest live examples in American consumer protection.

The harms, ranked by evidence

Not all concerns about this industry are equally supported, and distinguishing them matters for anyone forming a view.

  1. Safety and physical risk — strongest evidence. Purchased address and location information has been connected to stalking and to violent incidents, which is what prompted multiple states to enact targeted protections for judges, law enforcement, and other officials. This harm is concrete, documented, and the least contested.
  2. Fraud targeting — well supported. Detailed profiles including age, financial circumstances, and vulnerability indicators are precisely what enables the targeted schemes our elder exploitation analysis documents. A scammer with a list of likely-vulnerable individuals is operating at a different efficiency than one dialing randomly.
  3. Identity fraud enablement — well supported. The weak-identifier problem our identity report describes is worsened when the identifiers and the biographical details supporting them are purchasable, which is directly relevant to the synthetic identity construction process.
  4. National security exposure — raised prominently by regulators. The concern that adversary states can purchase rather than steal detailed data on Americans, including service members and officials.
  5. Differential pricing and targeting — real but harder to quantify. Data-driven segmentation affects what offers people see and what prices they're shown, and the line between legitimate marketing and exclusionary practice is genuinely difficult to draw from outside.
  6. Inference accuracy — under-examined. Because there's no accuracy obligation, the reliability of broker inferences about health, income, and behavior is largely unmeasured, which is itself the finding: nobody is required to check.

What consumers can actually do

The honest framing is that individual action reduces exposure meaningfully without solving the problem, and anyone claiming otherwise is selling something.

  • Exercise the rights you do have. Pull and review your credit reports and your specialty reports, where accuracy and dispute rights are real and enforceable — the process in our reading guide. This is the regulated fraction, and it's the fraction where effort produces durable results.
  • Use state deletion mechanisms if you're covered. If you live in a state with a registry law, the deletion request process is the most efficient tool available, particularly where a single request reaches registered brokers collectively.
  • Opt out of prescreened offers. A free federal mechanism that removes one significant data flow and reduces mail-based fraud exposure.
  • Freeze your credit permanently. It doesn't address broker data, but it closes the highest-consequence downstream use — new account fraud — per our freeze guide.
  • Reduce collection at the source. App permissions, particularly location; browser and device settings; and skepticism about loyalty programs and quizzes that trade data for small benefits.
  • Treat removal services realistically. Paid services that submit deletion requests on your behalf can save labor, but brokers frequently re-acquire data from upstream sources, so removal is a maintenance activity rather than a one-time fix — and the value depends heavily on how much of your exposure sits with companies that honor requests at all.
  • Consider the safety-specific programs that exist in many states for people at elevated risk, which are narrower but stronger than general opt-outs.

Scenarios and what we're watching

ScenarioShape of the worldSignposts
Base case — state-led patchworkRegistry laws spread state by state; obligations remain lighter than the FCRA; coverage depends on residence; federal boundary unchangedNew state registry statutes; deletion mechanism uptake; enforcement actions
Convergence case — the perimeter movesRulemaking or litigation extends consumer report treatment to more broker activity, bringing accuracy and access rights to data that currently has neitherRenewed federal rulemaking; court decisions on the CRA definition; industry repositioning
Divergence case — the gap widensExemptions in state privacy laws combine with a static federal perimeter to leave a growing share of inference-heavy data covered by nothing, as model-derived attributes replace collected factsExemption reform proposals; growth in inferred versus collected data; adverse decisions with no traceable source

What we're watching: whether state exemption structures get narrowed from entity-level to activity-level, which is the single change that would most reduce the coverage gap; the treatment of inferred attributes as distinct from collected ones, since a model output about your likely health or financial condition is not a fact anyone furnished and fits awkwardly into every existing framework; deletion mechanism effectiveness, which is measurable and currently unmeasured; and any renewed federal activity on the definitional question. The FCRA was written because Congress concluded that files compiled about people, sold to third parties, and used to make decisions about their lives required rules. That conclusion has not become less true. It has simply stopped covering most of the files.

Frequently asked questions

What is a data broker?

A company that collects, aggregates, infers from, and sells personal information about people it generally has no direct relationship with — spanning demographic, financial, health, location, and behavioral data. Credit bureaus are the regulated subset; much of the industry operates outside those rules.

Are data brokers regulated by the Fair Credit Reporting Act?

Some are. The FCRA attaches to information assembled for use in credit, employment, insurance, and housing decisions — so the same data sold for other purposes frequently falls outside, along with its accuracy, access, and dispute obligations.

What happened to the federal data broker rule?

Proposed in December 2024 to treat brokers selling sensitive data as consumer reporting agencies, it was not finalized — the Bureau later concluded the rulemaking wasn't necessary or appropriate. State law is now the primary vehicle.

Can I get my information removed from data brokers?

Partially. California, Vermont, Texas, and Oregon operate registry laws with deletion or opt-out rights; elsewhere it means individual requests. Brokers often re-acquire data, so removal is maintenance rather than a permanent fix.

Key takeaways

  • The FCRA regulates a purpose, not a dataset — identical information sold for a non-enumerated use carries no accuracy, access, or dispute obligations.
  • The boundary runs through products rather than companies, so the same corporate group can be regulated for one offering and unregulated for another.
  • A federal rule proposed in December 2024 to extend coverage was withdrawn, leaving no comprehensive federal framework and a movable, interpretive perimeter.
  • Four states operate registry laws with deletion rights, but registration is a precondition for oversight rather than oversight itself — and coverage depends on where you live.
  • Privacy law exemptions written to avoid duplicating federal rules can leave data covered by neither regime, producing less protection than either alone.
  • The best-evidenced harms are safety, fraud targeting, and identity enablement; individual action reduces exposure but cannot close a structural gap.

This report is for general information only and does not constitute legal advice. Regulatory positions, rulemakings, and state statutes in this area change frequently; verify current requirements and consumer rights for your jurisdiction before relying on any description here.