The IT Law Wiki
Advertisement

Definitions[]

Data brokers (also called information brokers, information resellers, data aggregators, and information solutions providers)

[are] companies that collect information, including personal information about consumers, from a wide variety of sources for the purpose of reselling such information to their customers, which include both private-sector businesses and government agencies.[1]
collect personal information from public and private records and sell this information to public and private sector entities for many purposes, from marketing to law enforcement and homeland security purposes.[2]
collect, repackage, and sell information that is either available in the public domain, or they illicitly aggregate data that was collected for another purpose from that for which it is ultimately used.[3]
offer several types of products to customers that include retailers, advertisers, private individuals, nonprofit organizations, and law enforcement and other government agencies.[4]

Overview[]

"Two types of businesses exist in this industry: (1) 'individual reference services providers' (IRSPs), which sell 'profiles' and other reports containing confidential personal information about individuals; and (2) 'marketing list brokers,' which sell lists of names, mailing addresses or electronic mail addresses of individuals, grouped by characteristics, conditions, circumstances, traits, preferences or mode of living."[5]

These entities may provide their services to a variety of prospective buyers, either to specific business clients or to the general public through the Internet.

More prominent or large information resellers such as consumer reporting agencies and entities like LexisNexis provide information to their customers for various purposes, such as building consumer credit reports, verifying an individual's identity, differentiating records, marketing their products, and preventing financial fraud. These large information resellers limit their services to businesses and government entities that establish accounts with them and have a legitimate purpose for obtaining an individual's personal information. For example, law firms and collection agencies may request information on an individual's bank accounts and real estate holdings for use in civil proceedings, such as a divorce.

Information resellers that offer their services through the Internet (Internet resellers) will generally advertise their services to the general public for a fee. Resellers, whether well-known or Internet-based, collect information from three sources: public records, publicly available information, and nonpublic information.

Reseller

Information resellers provide information to their customers for various purposes, such as building consumer credit reports, verifying an individual's identity, differentiating records, marketing their products, and preventing financial fraud. The aggregation of the general public's personal information, such as SSNs, in large corporate databases and the increased availability of information via the Internet may provide unscrupulous individuals a means to acquire SSNs and use them for illegal purposes.

Applicable federal and state laws[]

Although federal laws do not specifically regulate the information reseller industry as a whole, they provide safeguards for personal information under certain specific circumstances, such as when financial or health information is involved, or for such activities as pre-employment background checks. As shown in Table 1, these laws either restrict the circumstances under which entities such as information resellers are allowed to disclose personal information or restrict the parties with whom they are allowed to share information.

Infobroker

Information resellers are also affected by various state laws. For example, California state law requires businesses to notify consumers about security breaches that could directly affect them.

References[]

See also[]

Advertisement