Privacy's Peril: Unmasking the Unregulated Underground Market of Data Brokers and the Suggested Framework

Rabia Bajwa,Farah Tasnur Meem
2024-10-07
Abstract:The internet is a common place for businesses to collect and store as much client data as possible and computer storage capacity has increased exponentially due to this trend. Businesses utilize this data to enhance customer satisfaction, generate revenue, boost sales, and increase profile. However, the emerging sector of data brokers is plagued with legal challenges. In part I, we will look at what a data broker is, how it collects information, the data industry, and some of the difficulties it encounters. In Part II, we will look at potential options for regulating data brokers. All options are provided in light of the EU General Data Protection Regulation (GDPR). In Part III, we shall present our analysis and findings.
Cryptography and Security
What problem does this paper attempt to address?
The main problems that this paper attempts to solve are the privacy and regulatory issues in the Data Broker industry. Specifically, the paper explores the following key issues: 1. **Legal Gaps in the Data Broker Industry**: - Data broker companies lack an effective legal regulatory framework in the process of collecting, purchasing, licensing, and sharing users' personal data. This has led to the risk of user data abuse and privacy leakage. 2. **Consumer Privacy and Security Issues**: - Although the data broker industry has brought economic benefits, there are serious consumer privacy and security issues in its operation process. For example, frequent collection and distribution of inaccurate or false information may cause consumers to suffer adverse effects, such as lower credit scores, higher product prices, or welfare rejections. - The risk of identity theft has also increased due to the ineffectiveness of the risk mitigation strategies in the data broker industry. Fraudsters can use false information to impersonate real customers, resulting in innocent customers being misclassified as fraudsters. 3. **Accuracy Issues in Data Classification and Decision - making**: - Data broker companies classify people by collecting and analyzing personal data, and these classifications may be based on inaccurate or misinterpreted data. This practice is widely used in important areas such as insurance premium determination and student loan repayment ability assessment, but it often leads to wrong conclusions and affects individuals' real - life decisions. 4. **Insufficient Transparency and Control for Consumers**: - Consumers lack sufficient transparency and control over the use of their personal data. Due to the lack of strict laws and regulations, it is difficult for consumers to verify the accuracy of data, and even without their knowledge, their personal data is used for key decisions, such as premium calculation by health insurance companies. 5. **Risks of Social and Economic Manipulation**: - The current data broker system lacks sufficient protection measures to prevent malicious actors from using the purchased data to manipulate politics, economy, or society. For example, Facebook cooperates with data broker companies. Although it is not a data broker company itself, it sells advertisements to accounts related to Russia, and these accounts are known to spread false information and incite conflicts. ### Goals of the Paper To address the above - mentioned problems, the paper sets the following goals: 1. **Analyze the Impact of Data Processing Practices in the Data Broker Industry**: - By studying the history of data leakage events, analyzing the impact of inaccurate data collection and distribution on consumers, investigating identity theft cases related to data broker mistakes, and evaluating the actual impact of data classification techniques. 2. **Discuss the Main Data Privacy and Protection Laws**: - Research existing data privacy and governance frameworks worldwide, such as GDPR, PIPEDA, FCRA, GLBA, HIPAA, COPPA, etc., to understand how they regulate the processing of users' personally identifiable information (PII). 3. **Propose a Data Privacy Protection Framework**: - Based on the analysis of existing laws and practices, propose a conceptual framework aimed at strengthening data protection and privacy management in the data broker industry, ensuring stricter control and more accurate data collection and distribution. Through these goals, the paper hopes to provide valuable insights for policymakers, enterprises, and the public to improve privacy protection and compliance in the data broker industry.