- Regulated industries like finance and healthcare are exempt from most state privacy laws only for GLBA or HIPAA covered data, not for every data stream a client generates.
- “Publicly available information” is broadly exempt from broker rules, letting companies aggregate and resell combined public records with little consistent legal testing.
- An outdated 1986 law lets companies route restricted data through brokers, who then resell the same data to government buyers legally.
- Opt-out is not deletion. A Consumer Reports test found only 35 percent of removed profiles stayed removed after four months, since resales and public record updates keep repopulating broker sites.
- California’s DROP platform, live January 2026 with $200 daily penalties starting August, streamlines deletion requests but leaves every underlying exemption untouched.
A data broker does not need to hack anyone. It only needs a business model that predates the laws written to stop it. That is the uncomfortable starting point for anyone trying to understand data broker loopholes in 2026. The collection itself is rarely illegal. The law simply never finished defining what counts as collection, what counts as public, or who counts as a broker in the first place.
This gap is not an oversight. It is the product of decades of sector-specific rules bolted onto a market that grew faster than any single regulator could track. For an MSP or IT reseller managing security for a client base, that gap is not academic. A client’s data can technically clear every audit on the books and still surface on a broker site next quarter, and the client will ask why the monitoring stack did not catch it.
Why the Gaps Exist by Design

Privacy law in the United States grew one industry at a time. Congress passed the Fair Credit Reporting Act for credit bureaus, the Gramm-Leach-Bliley Act for banks, and HIPAA for health providers. None of them were written with today’s data broker market in mind, because that market barely existed at the time.
As of July 2025, 19 states now have general consumer privacy laws on the books. Every one of them carries exemptions for data or entities already covered by FCRA or GLBA. The intent was to avoid duplicate regulation. The result is a set of data broker loopholes that let the exact companies the laws target opt out of coverage, simply by pointing to a different statute.
More than 4,000 active data brokers currently operate in the United States. Most consumers have no idea which ones hold their records, because no single law obligates every broker to say so.
Loophole 1: The Regulated-Industry Exemption
Here is the mechanic behind the first and largest gap. If a company can argue its data falls under FCRA, GLBA, or HIPAA, most state privacy laws stop applying, even when the company is functioning exactly like a broker in every other respect.
New Jersey closed part of this gap in June 2026, but the exemption structure still stands. GLBA-covered institutions, insurers, and secondary market entities remain exempt at the entity level, and FCRA, GLBA, and HIPAA data stay exempt regardless of who holds it. Non-exempt brokers now face annual fees now ranging from $5,000 to $1.5 million, but a broker that reclassifies its data stream as GLBA-adjacent sidesteps the fee entirely.
Connecticut took a narrower approach. Its 2026 amendment keeps the FCRA, GLBA, and HIPAA carve-outs but adds a relationship-based exemption for contractual, investor, or donor data. That exemption is broader than GLBA alone, since it can exclude first-party data regardless of the sector it comes from.
What This Means for a Client You Manage
A client in financial services or healthcare is often assumed to be automatically compliant because the underlying data is GLBA or HIPAA covered. That assumption breaks down the moment the same client’s customer browsing history, device identifiers, or purchase behavior gets collected through a separate, unregulated pipeline. The exemption protects the data category, not the person. If your monitoring only checks the regulated dataset, you are covering the part of the client’s exposure that was already lower risk.
Loophole 2: The Publicly Available Information Exemption

Most state privacy statutes exclude “publicly available information” from the definition of personal data. On paper this sounds narrow. In practice it is one of the widest data broker loopholes still in use.
Under California’s framework, there is no categorical exemption for businesses relying on public records. The legal test instead asks whether the data still qualifies as publicly available once it has been aggregated, enhanced, or combined with other datasets. A voter registration record is public. The same record cross-referenced against a mortgage filing, a court judgment, and a social media handle is something else entirely, yet the aggregation itself is rarely what gets tested in practice.
Connecticut tightened its own definition in 2026, and now excludes data created by combining personal information with public records from the exemption. That single change closes a data broker loophole most other states still leave open, since combined datasets in most jurisdictions retain their exempt status as long as each individual input was technically public.
Vermont goes further in the other direction. Its exemption for 411 directory assistance providers lets telecom-adjacent firms compile and resell consumer contact data without being classified as a broker at all, since they are framed as a directory service rather than a data seller.
Loophole 3: The Data Laundering Gap
The third gap explains how sensitive data ends up in places no consumer would ever expect, including government purchase logs.
The Electronic Communications Privacy Act bars phone and internet companies from selling sensitive customer data directly to government agencies. That law dates to 1986, before commercial data brokers existed at meaningful scale. Companies barred from selling data to government buyers can instead sell it to a broker, and the broker can resell the same data to the same government agency for a profit. Legally, the transaction is clean. Functionally, the data gets laundered through a middleman that neither original law anticipated.
The Protecting Americans’ Data from Foreign Adversaries Act addressed one narrow slice of this problem. It restricts sales of sensitive personal data to foreign adversary countries including China, Russia, Iran, and North Korea. It says nothing about domestic government purchases, which remain the larger and more common version of the same laundering pattern.
Loophole 4: Opt-Out Without Deletion
Even where a consumer successfully submits a removal request, the data rarely stays gone. This is the loophole that affects the largest number of people directly, and it is almost never explained with real numbers.
A Consumer Reports field test tracked seven removal services across four months. Across every service tested, only thirty five percent of exposed profiles stayed removed. The best-performing service reached 68 percent. The most heavily marketed name in the category managed just 27 percent.
The mechanics behind that failure rate are structural, not incidental:
- Data brokers resell to smaller aggregators, so one removal does not propagate downstream.
- Routine life events such as a home purchase, a new job, or a voter registration update feed fresh records back into the same pipelines.
- California’s Delete Act requires brokers to process deletion requests only once every 45 days, which sets a floor, not a ceiling, on how quickly data can reappear.
Separately, a 2025 congressional inquiry found that more than 30 data brokers were hiding opt-out links from search engines using code that instructs Google and Bing to exclude those pages. The right to opt out existed. The path to exercise it was deliberately buried.
Why Removed Data Comes Back
Opt-out and deletion are treated as interchangeable terms in most consumer-facing content, but they are not the same legal action. An opt-out stops a specific sale going forward. It does not erase the underlying record from every downstream partner that already purchased it. That distinction is one of the most consequential data broker loopholes because it looks resolved to the consumer while the exposure quietly persists.
Where the Gaps Differ by State
No two state frameworks treat the same exemption identically, which is exactly why data broker loopholes look different depending on which state a partner or client operates in. The table below summarizes how four representative laws diverge on the exemptions that matter most.
| State / Law | Regulated-Entity Exemption | Publicly Available Data Treatment | Registration Fee | Deletion Mechanism |
| California (CCPA, Delete Act, SB 361) | FCRA, GLBA, insurance carve-outs | Case-by-case, no blanket exemption for aggregated public records | Registration required, escalating fines for non-compliance | DROP platform, live January 2026 |
| Connecticut (CTDPA, SB 4) | FCRA, GLBA, HIPAA, DPPA | Combined public and personal data excluded from exemption | Registration from 2027, audits from 2031 | Accessible deletion mechanism by 2028, 45-day cycle |
| New Jersey (A5328) | GLBA entity-level, FCRA/GLBA/HIPAA data-level | Publicly available and human subject research data exempt | $5,000 to $1.5 million annually | Registry established, rulemaking ongoing |
| Vermont | Broad relationship-based exemptions, 411 directory carve-out | Business and professional public data exempt | Registration required, lower enforcement profile | No dedicated single-request platform |
What Changes With California’s DROP Platform
California’s DROP platform closes the enforcement-friction problem starting August 2026, when unfulfilled requests trigger daily penalties. That is the first meaningful financial deterrent tied directly to non-compliance in any state broker law to date. It does not touch the exemptions described above. A GLBA-covered entity or a business selling only publicly available aggregates stays outside DROP’s reach entirely. This means that the platform closes the enforcement gap without closing the definitional one. DROP fixes the friction of filing a request. It does nothing for the data broker loopholes that decide who has to answer that request in the first place.
The Real Questions This Raises for an MSP Adding This to a Security Bundle

Generic privacy content stops at “protect your data.” The harder questions about data broker loopholes sit one layer down. They matter most to an MSP or reseller responsible for a client’s compliance posture, not just its own:
- If a client’s data qualifies for a GLBA or HIPAA exemption, does that protect every data stream connected to that client, or only the specific regulated category?
- What is the actual cost difference between building in-house broker monitoring and opt-out infrastructure versus reselling an existing API layer built for that purpose?
- Given a 35 percent average removal success rate industry-wide, what ongoing monitoring cadence can you actually stand behind when a client or their regulator asks for proof, rather than a one-time removal claim?
- How does adding this line item change renewal conversations with clients who already pay for antivirus or endpoint protection?
Answering these requires operational detail an MSP can act on, not another summary of what a data broker is.
Where PureVPN White Label Fits Into This
For an MSP adding this coverage to an existing security bundle, the operational question is not whether broker exposure matters. It is whether your team can prove a client’s data stayed removed without hiring someone to check manually every few weeks.
PureVPN White Label VPN Solution’s digital privacy protection layer is built around that specific gap. The underlying data privacy protection architecture covers more than 400 data brokers. Its no-log policy carries third-party audit verification. In this way, a client’s own compliance team has something concrete to check against instead of taking your word for it.
The provisioning side runs through a documented API: identity exposure checks, continuous dark web monitoring, and data broker opt-out requests tracked through their full lifecycle, from submission through re-listing. Instead of re-running manual checks on a schedule, your team registers a client’s assets once and gets a webhook alert the moment a monitored identifier resurfaces.
One MSP client, running this alongside an existing antivirus and VPN suite, added broker monitoring as a line item and saw enterprise clientele grow 20 percent and client retention rise 15 percent within two months, while manual removal workload dropped 32 percent.
Closing the Gap Starts With Knowing Where It Is
Data broker loopholes will not close through a single federal law. Nothing on the current legislative calendar suggests that changes soon. For an MSP, that means the gap does not close on its own either. What changes is who bears the cost of it. The client whose data resurfaces every 45 days with no one watching. Or the provider that built monitoring into the bundle before a client’s compliance team asked why it was not there.
The exemptions, the aggregation gray zones, and the opt-out-without-deletion pattern covered here are not edge cases. They are the default state of the market. Any MSP making privacy claims to its own clients needs to know exactly where those defaults still fail.


