You've never heard of most of them, you never agreed to anything with them, and they know an astonishing amount about you. They're called data brokers, and the scale of what they hold is genuinely hard to believe until you see the numbers the companies themselves gave Congress.
What they actually have
One major broker, Acxiom, told a Senate committee it holds data on approximately 700 million consumers worldwide and maintains over 3,000 "propensities" for nearly every U.S. consumer — 3,000 predicted traits about you. Another gave Congress a list of about 75,000 individual data elements it collects. The Federal Trade Commission, studying nine brokers, found one holding 700 billion data elements and another adding 3 billion new data points every month.
And it's not just your zip code and your car. The categories they sort and sell are intimate and predatory. The FTC documented brokers selling segments built around health conditions — depression, diabetes, ADHD, cancer — and around financial vulnerability, with segment names like "Rural and Barely Making It" and "Credit Crunched: City Families." A Duke University study in 2023 found data brokers openly selling mental-health data — lists of people with depression and anxiety — for about $275 per 5,000 records. Another Duke study found brokers selling data on U.S. military service members for as little as 12 cents a record.
Read that again: your diagnosis, your debts, and your service record, packaged and sold for pennies, by companies you've never heard of, to buyers you'll never know.
This isn't hypothetical — the harm is on the record
The FTC has spent the last two years proving how dangerous the location piece is. It has taken action against broker after broker for selling precise phone-location data that can track you to a clinic, a church, a shelter, or a lawyer's office: Kochava (data from 61 million devices), X-Mode/Outlogic (the first-ever ban on selling sensitive location data), InMarket, Gravy Analytics (processing 17 billion location signals from a billion devices daily), and Mobilewalla. Automakers were caught quietly funneling drivers' second-by-second behavior into this economy until reporting shamed them into stopping.
And then the nightmare scenario happened: in January 2025, Gravy Analytics itself was breached, spilling millions of location records into the open. The data broker who tracks everyone got tracked. That's the thing about a giant honeypot of everyone's movements and secrets — it's a target, and eventually someone takes it.
Washington tried, then quit
Here's the pattern this series keeps finding. In December 2024 the Consumer Financial Protection Bureau proposed a real rule to bring data brokers under the fair-credit laws — to treat the sale of your sensitive data with the same rules that govern a credit report. In May 2025, the Bureau withdrew it, saying rulemaking was "not necessary or appropriate at this time."
So once again, the federal protection was proposed and then abandoned. Which leaves the states — and here, California is a decade ahead of everyone, including us.
California built the button Minnesota forgot
California did the thing that actually helps an ordinary person. Its 2018 law created a public registry of data brokers — you can't opt out of companies you can't even find, so first the state made them register and be listed. Then its Delete Act built DROP: a single, one-stop deletion mechanism. As of 2026 it's live — a Californian can go to one website, make one request, and be deleted from every registered data broker at once, instead of hunting down and petitioning hundreds of companies individually. Vermont pioneered the registry idea in 2018; Texas and Oregon have their own registries, and Texas's attorney general has been aggressively enforcing, suing Allstate and its data arm in what it called the first enforcement action any state ever brought under a comprehensive privacy law.
Now Minnesota. Our new consumer data privacy law, in effect since July 2025, gives you a right to delete your data and to opt out of its sale. That's good. But it built neither of the two things that make those rights usable at scale: there's no data-broker registry, so Minnesotans have no public list of who these companies even are, and there's no one-stop deletion — you'd have to find and petition each broker one at a time, hundreds of them, with no map. A delete right you can only exercise company-by-company against companies you can't identify is a right on paper. It's the fine-print problem again: the protection exists, but the path to using it doesn't.
And there's a national-security angle even skeptics should hear
This isn't only a privacy problem — it's a foreign-leverage problem, which connects to the "protect Minnesota from foreign interference" theme in this series. Because this data is for sale to anyone, foreign governments can simply buy it — the movements of military personnel, the health conditions of officials, the financial vulnerabilities of ordinary Americans. Congress recognized this in 2024, passing a law banning brokers from selling Americans' sensitive data to China, Russia, Iran, and North Korea, and the executive branch added rules restricting bulk data transfers to adversaries. If you worry about foreign adversaries knowing too much about Americans, the data-broker economy is how they find out — legally, for pennies.
What we can do
Build the registry. The first step is a public list. Minnesota should require data brokers operating here to register with the state, as Vermont, California, Texas, and Oregon do. You can't delete yourself from companies you can't find, and the registry is cheap to run — the fees the brokers pay cover it.
Build the one-button delete. Follow California's Delete Act and DROP: one request, on one state website, that deletes a Minnesotan from every registered broker at once. This is the single most powerful consumer-privacy tool any state has built, and it turns Minnesota's existing delete right from a theoretical maze into a button an actual person can press.
Enforce it — and let people enforce it too. As the privacy-law article in this series documented, Minnesota's data law is enforceable only by the Attorney General, with no visible enforcement yet. Texas is suing brokers; Minnesota should too. And a private right of action would let a Minnesotan whose sensitive data was sold do something about it directly.
And close the foreign-data door at the state level where you can. Support and mirror the federal restrictions on selling Americans' sensitive data to adversary governments, and make it a Minnesota enforcement priority.
There are companies profiting off the fact that you're depressed, or diabetic, or barely making rent — and selling it for twelve cents to whoever asks, including people who don't wish you well. Minnesota gave you the right to make them delete you. Now let's give you the button to actually do it.
First the facts. Then the fix.
Sources
Scale and categories: U.S. Senate Committee on Commerce, "A Review of the Data Broker Industry" (Dec. 18, 2013) — Acxiom's approximately 700 million consumers and over 3,000 propensities per U.S. consumer, and a broker's roughly 75,000 data elements; FTC, "Data Brokers: A Call for Transparency and Accountability" (2014) — a broker holding 700 billion data elements and 1.4 billion consumer transactions, another adding 3 billion data points monthly, and the health and financial-vulnerability segments including "Rural and Barely Making It." Sensitive-data sales: Duke University (Joanne Kim, Feb. 2023) on brokers selling mental-health data (11 of 37 brokers; about $275 per 5,000 records); Duke University (Justin Sherman, Nov. 2023) on brokers selling U.S. military-personnel data for as little as $0.12 per record. FTC enforcement: FTC v. Kochava (Aug. 2022, 61 million devices); X-Mode/Outlogic (Jan. 9, 2024, first sensitive-location ban) and InMarket (Jan. 18, 2024); Gravy Analytics/Venntel (Dec. 3, 2024, 17 billion signals from a billion devices daily) and Mobilewalla (Dec. 3, 2024); the GM/LexisNexis driving-data episode (stopped March 2024); the Gravy Analytics breach (January 2025). CFPB: the FCRA data-broker rule proposed December 2024 and withdrawn May 15, 2025 ("legislative rulemaking is not necessary or appropriate at this time"). State registries and deletion: Vermont (2018, first-in-nation); California AB 1202 and the Delete Act (SB 362) creating the DROP one-stop deletion mechanism (consumer access January 1, 2026; broker processing August 1, 2026; 543 brokers registered); Texas (ch. 509, effective September 1, 2023) and Texas v. Allstate/Arity (Jan. 13, 2025, described as the first state enforcement under a comprehensive privacy law); Oregon (HB 2052). Minnesota's gap: Minn. Stat. §§ 325M.10–.21, effective July 31, 2025, providing delete (§ 325M.14, subd. 1(d)) and opt-out (subd. 1(f)) rights but no data-broker registry and no one-stop deletion, verified against raw text at revisor.mn.gov. National security: Executive Order 14117 (Feb. 28, 2024) and the resulting Data Security Program rule; the Protecting Americans' Data from Foreign Adversaries Act (Pub. L. 118-50, Apr. 24, 2024), barring brokers from transferring Americans' sensitive data to China, Russia, Iran, and North Korea.
Exact current registration-fee amounts and live registered-broker counts for California, Vermont, Texas, and Oregon were flagged for verification; statutory fees and penalties are stated as enacted. Corrections: campaign@madgettformn.com.