PrivacySignal
News

CDT Issue Brief: The Data Broker Loophole

- Center for Democracy and Technology · · International · Privacy Law

The Center for Democracy and Technology has published an issue brief focused on what it calls the data broker loophole, a gap that allows data brokers to collect and sell personal information outside the reach of stronger privacy protections that apply to other industries.

Why this matters: Data brokers sit in a strange legal space. A hospital cannot sell your medical records. Your bank cannot sell your financial details. But a data broker can buy information derived from both, package it, and sell it to almost anyone. That gap is not an accident. It is a structural feature of how U.S. privacy law developed. CDT naming it a loophole is a framing choice with policy weight. If enough people treat it that way, it becomes harder for lawmakers to keep ignoring it.

Who should care: General readers · Privacy officers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

News
The Guardian — Tech · · International

Amazon to launch Ring ‘neighbourhood watch’ app in UK amid US privacy fears

Doorbell firm aims to replace WhatsApp or Facebook groups with platform where people can post about safety or lost pets Amazon’s doorbell camera maker Ring is to launch its Neighbours community app in the UK in an attempt to supplant neighbourhood WhatsApp or Facebook groups. The service is intended as a modern equivalent of a community message board, where neighbours can post about safety, community matters or lost pets. Continue reading...

Who should care: General readers · Privacy officers · Policy

News
Inside Privacy (Covington) · · International

Kenya Issues New Cross-Border Data Transfer Guidance: Familiar Concepts, but Important Local Differences

On September 8, 2026, Kenya’s Office of the Data Protection Commissioner (“ODPC”) published new Guidance Notes for Cross-border Data Transfers (“Guidance”), providing organizations with more detailed guidance on the application of Kenya’s rules governing transfers of personal data outside the country. The Guidance arrives at an interesting time for Kenya’s data protection framework. Kenya and... Continue Reading…

Who should care: Lawyers · Compliance · General readers · Privacy officers · Policy

#regulation#privacy Read original →