For 30 years, Ben Isaacson has been a leading privacy professional and trusted counsel. During the "Internet 1.0" era, he was instrumental in launching the first self-regulatory guidelines for email marketing, addressable TV, and mobile marketing. Ben was one of the first privacy professionals to get certified as a CIPP/US with the IAPP in 2005.

In this episode…

Data broker laws are pulling a once-hidden industry into the light. For years, consumers generally had no idea which companies were compiling and selling their personal information, what those companies were doing with it, or how to opt out. States are responding with data broker laws that require brokers to register and disclose information about their businesses and data-selling practices. Seven states now have these laws on the books, with some providing consumers with a centralized mechanism to request deletion of their data or to opt out of its sale. So, how can companies that purchase or license data from brokers manage the downstream risks that come with using it?  

Companies buying or licensing data from data brokers need to know where that data comes from, how it's used, and what their third-party contracts permit. Legal and privacy teams should work with marketing and sales to identify which adtech vendors they buy or license data from and scrutinize their licensing relationships. They also need to map how purchased data flows through the business and ensure their privacy notices disclose its use. California's Delete Act makes this downstream visibility especially important because it requires data brokers to apply deletion requests before that data is used. Companies also need to consider whether their activities qualify them as data brokers, particularly because New Jersey's data broker law extends registration requirements to data collectors, potentially affecting businesses that fall outside the traditional data broker definition. Companies should seek a legal opinion to determine where they stand based on the nature of their business and its commercial terms. 

In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels speak with Ben Isaacson, Principal at In-House Privacy, about the rise of data broker laws and what they mean for companies that buy, license, or sell personal information. Ben discusses the evolution of these laws and how data broker definitions and legal requirements vary across states. He highlights what companies can do to mitigate risk when using data purchased from brokers and provides tips on how companies can determine whether they are considered data brokers under these laws. Ben also shares his perspective on how California's Delete Act could influence future state and federal regulation. 

Podden och tillhörande omslagsbild på den här sidan tillhör Jodi and Justin Daniels. Innehållet i podden är skapat av Jodi and Justin Daniels och inte av, eller tillsammans med, Poddtoppen.