You've probably heard data broker lobbyists claim their operations are too complex to regulate and any restrictions will fail under constitutional scrutiny. The Radaris case, where a New Jersey court transferred 14 domains from a data broker violating Daniel's Law, debunks these myths.
The industry's tactics aren't sophisticated, just persistent obstruction disguised as complexity. Here's what your team needs to know.
Myth 1: Data Brokers Operate in Legal Gray Areas
Reality: Data brokers often violate clear statutes, betting on non-enforcement.
Daniel's Law requires data brokers to remove information about New Jersey law enforcement officials, judges, or government employees upon request, with a $1,000 penalty per violation. When Atlas Data Privacy Corp sued Radaris in February 2024 for ignoring these requests, the issue wasn't ambiguous, it was whether Radaris would defend itself.
Radaris delayed until the last moment to contest a default judgment, claiming Atlas sued the wrong entities. This isn't a gray area; it's a delay tactic.
Your compliance framework should reflect this. When assessing vendor relationships, don't accept excuses like "we operate internationally" for non-compliance. If a vendor can't show compliance with specific laws, document the gap and escalate the risk.
Myth 2: Shell Companies Make Data Brokers Untouchable
Reality: Complex corporate structures create paperwork, not immunity.
Radaris cycled through entities in various countries. An investigator found a newly claimed managing entity didn't exist. Despite constant changes in terms of service, the court transferred the domains. Why? Because evidence showed multiple entities operated from the same addresses and shared resources.
When conducting due diligence, examine operational reality, not just legal registration. Ask who administers the infrastructure, where support tickets go, and who handles transactions. If a vendor can't answer, you're facing an accountability gap that could become your problem.
Myth 3: Constitutional Challenges Will Kill State Privacy Laws
Reality: Legal challenges create uncertainty, not inevitability.
Many data brokers moved lawsuits to federal court, arguing Daniel's Law violates the First Amendment. While a federal court ruled West Virginia's version unconstitutional, the U.S. Court of Appeals for the Third Circuit hasn't ruled on New Jersey's statute yet.
Despite ongoing litigation, 14 states have passed laws similar to Daniel's Law. This isn't the behavior of legislatures convinced these statutes are doomed.
Your job isn't to predict court outcomes. It's to document compliance under current law. If you operate in states with similar protections, implement removal processes now. Waiting for legal certainty exposes you during litigation.
Myth 4: Federal Legislation Will Solve the Data Broker Problem
Reality: Federal bills face opposition, and state exemptions will persist.
Tech companies, social media platforms, and AI firms oppose federal privacy legislation, claiming it threatens competitiveness. This isn't temporary, it's a structural barrier.
Even if Congress passes privacy legislation, expect carveouts. State laws often exempt "public" records like voting registries and court documents. People-search sites will argue they're exempt from federal restrictions.
Your data inventory should classify information by source and legal basis. Document exemptions under state statutes. When federal legislation arrives, map existing classifications to new requirements quickly.
Myth 5: Age Verification Requirements Protect Drivers License Data
Reality: No federal law limits how verification vendors use or retain data.
A breach at IDScan.net exposed drivers license information for over 153 million Americans, leading to identity theft. This happened because states required document scanning without mandating data protection.
If your organization collects identity documents, your retention schedule and access controls are crucial. Define a Time-to-Live (TTL) for document images and implement Secure Deletion procedures. Restrict access to personnel with a documented need.
Don't assume collecting data for regulatory compliance allows indefinite retention.
What to Do Instead
Stop treating data broker relationships as low-risk. If you purchase enrichment data or identity verification services, ask your vendor:
- Which entities operate the infrastructure?
- Where is data processed, and under which legal entity's control?
- What removal mechanisms exist for deletion requests?
- Has the vendor faced litigation for non-compliance?
Document the answers. If a vendor can't provide specifics or frequently changes structure, escalate that risk.
For data you control, implement removal workflows independent of federal legislation. If you operate in states with Daniel's Law equivalents, build opt-out mechanisms now. If not, consider implementing them anyway. The Radaris case shows "waiting for legal clarity" isn't a viable defense.
The data broker industry isn't winning because it's ungovernable. It's winning because compliance teams accept complexity as an excuse for inaction. The Radaris domains were transferred because one plaintiff refused that excuse. Your organization can make the same choice.



