PANOPTICON brennan data broker loophole
page 2 / 11
Over the past few years, lawmakers have sought to address the threat that third-party data poses to Americans’ privacy, proposing bills that would limit the collection of location and health information and rein in the government’s purchases of data from third parties. This report describes the major legal loopholes that necessitate such reforms and highlights two legislative proposals that would constrain the government’s ability to acquire large swaths of personal information without legal process. It discusses the proposals’ strengths and potential shortfalls and emphasizes important considerations for legislators when moving forward with these proposals or crafting future ones.
Part of
Artificial Intelligence and National Security
More on
-
Privacy Rights
The Data Broker Problem
Among the main purveyors in this surveillance capitalism ecosystem are data brokers — companies that collect, assemble, and analyze personal information to create detailed profiles of individuals, which they then sell. Although most of these companies are not household names, they serve an ever-growing demand; the industry pulled in more than $250 billion in 2022.
Data brokers collect information from various sources. They pay app developers to install code that siphons users’ data, including location information. They use cookies or other web trackers to capture online activity. They scrape information from public-facing sites, including social media platforms, often in violation of those platforms’ terms of service. They also collect information from public records and purchase data from a wide range of companies that collect and maintain personal information, including app developers, internet service providers, car manufacturers, advertisers, utility companies, supermarkets, and other data brokers.
Data brokers and their clients claim that some or all of the data is “anonymized,” but it can often be reidentified when combined with other information. The data can be highly sensitive, and brokers sometimes use algorithmic tools to make additional inferences and predictions about individuals, lumping them into categories on the basis of where they live, their health, their ethnicity or religion, their political affiliation, or their expected levels of spending. Through such means, these companies gather “thousands of attributes each for billions of people,” analyze and repackage that data, and then sell it to buyers.
Myriad entities buy this information. For example, financial institutions and insurance firms use data for identity verification and risk assessments. Advertising companies use data to offer more relevant and targeted advertisements. More troublingly, data brokers have sold personal information to predatory loan companies, stalkers, and scammers, as well as to political consultants (like Cambridge Analytica in 2016) that can use data to send voters disinformation and attempt to skew electoral outcomes. Data brokers also sell data to foreign actors whose uses of the information are not constrained by U.S. law. And — as highlighted by news reports, civil society organizations, and a recently declassified report commissioned by the Office of the Director of National Intelligence — law enforcement and other government agencies (including state and local law enforcement, the FBI, the IRS, the Drug Enforcement Administration, the Department of Defense, and the Department of Homeland Security) have secretly been paying data brokers to access vast databases of personal information, including geolocation data, without any warrant, court order, or even subpoena.
The Legal Loopholes
Typically, the Fourth Amendment and various federal statutes require government agencies to comply with legal process to obtain personal data on Americans. Yet over the past few decades, government agencies have taken advantage of statutory loopholes and a stalled Fourth Amendment doctrine to access personal information without legal process.
Constitutional Protections: The Fourth Amendment’s Warrant Requirement Post-Carpenter
The Fourth Amendment requires the government to obtain a warrant to access information in which individuals have a “reasonable expectation of privacy.” For decades, however, Fourth Amendment protections were constrained by the third-party doctrine, which holds that people lose any expectation of privacy in information that they voluntarily disclose to others.
In today’s world, where much of our information is stored online and accessible to the third parties that facilitate our digital transactions, the third-party doctrine has proven untenable. Nearly every American carries a cell phone that tracks their every move and stores their most private personal data. Internet service providers store our search and browsing histories, and our documents — once locked away in safes or desk drawers — are hosted by cloud service providers. Often, we disclose information unwittingly: simply using our devices generates metadata, like the location and IP address of a device used to search for or post content, which can then be collected and stored by third parties.