The dark web has exposed the Social Security numbers of millions of Americans due to numerous data breaches over the past few years. These numbers are now available for purchase by anyone with a credit card, including cyber criminals. The misuse of such information can lead to severe consequences. Criminals can open credit cards, file fake tax returns, and steal refunds, government benefits, and medical aid in the victims’ names.
Addressing the Breach in California
In California, many people are proactively trying to address this issue. They are utilizing their rights under the Delete Act to request data brokers in the state to delete personal information such as locations, finances, health, and personal data.
Understanding California’s Delete Act
This legislation, also identified as SB 362, enhances privacy rights. It allows Californians to demand the removal of their personal data from numerous registered data brokers through a centralized platform known as the Delete Request and Opt-out Platform (DROP). The information eligible for deletion includes:
- Social Security numbers
- Precise geolocation
- Browsing history
- Email addresses
- Phone numbers
- Personal interests
- Health-related information
- Shopping habits
Some data will not be deleted, including information provided directly to a business, exempted data, and publicly available data.
Requests for data deletion also obligate brokers to register with the California Privacy Protection Agency (CPPA). They must comply with these requests by deleting and refraining from selling individuals’ future data. Penalties for non-compliance include a $200 daily fine per person whose data remains undeleted.
Californians Take Action
As reported by the Mercury News, by July 1, 332,292 Californians had signed up for data deletion. Among the nearly 600 data brokers on CalPrivacy’s registry, a significant number deal with sensitive personal data:
- 110 sell precise location data
- Over 40 sell identity data
- Nearly 70 sell gender identity information
- Seven sell reproductive health data
- Six sell union membership information
Additionally, 18 brokers sell information about minors. Minors can request deletion via DROP or have their parents make the request. Meanwhile, approximately 50 brokers sell data to federal and state governments, police agencies, foreign entities, and developers of artificial intelligence.
The Need for Greater Participation
Despite these efforts, less than 1 percent of Californians have signed up for data deletion. Tom Kemp, Executive Director of CalPrivacy, emphasized the risks of unregulated data broker activities. He encourages more people to request data deletions, citing potential reductions in targeted advertising, scams, and fraudulent activities.
Those interested in reducing their digital footprint and enhancing personal privacy can apply for deletion through DROP by August 1.
Privacy Initiatives Across the U.S.
The U.S. lacks a comprehensive federal law governing data brokers or restricting the sale of personal information. Instead, privacy regulation varies by state. As of April, 20 states, including California, have enacted comprehensive privacy laws.
Some states, like Connecticut and New Jersey, are taking steps to follow California’s model. Connecticut’s new law, effective October 1, will establish a system by July 1, 2028, allowing consumers to request data deletion from all registered data brokers. Similarly, New Jersey has passed legislation requiring data brokers to delete personal information upon request.
Although states like Oregon, Texas, and Vermont require broker registration, they have not adopted a system like California’s DROP. Efforts to protect personal information are underway, encouraging states to consider standardized data protection mechanisms.
