Rampant Noncompliance with California Consumer Privacy Act Exposed by UC Irvine Study
A study conducted by the University of California, Irvine has uncovered widespread noncompliance with the California Consumer Privacy Act among state-registered data brokers. The investigation, funded by the National Science Foundation, found that nearly half of the data brokers investigated failed to respond to legitimate consumer requests. The study's findings highlight the need for stronger regulations to protect consumers' personal information.
Key Takeaways:
- The study examined 543 state-registered data brokers, with 57% responding to consumer requests and 43% failing to reply.
- Data brokers often required consumers to provide sensitive personal information to verify their identity, potentially exposing them to new privacy risks.
- The study identified six key aspects of the verifiable consumer request process that are burdensome for consumers, including the variability of identity verification and the response time differences among brokers.
- Composing and submitting verifiable consumer requests to data brokers is a complex and time-consuming process, with consumers often facing multistep submission forms, broken links, and live phone calls with untrained staff.
- The study's results reveal a broken system that fails to address the privacy needs of California consumers, undermining trust in and the spirit of the law.
- The International Association of Data Brokers, a trade organization, has called for stricter regulations to protect consumers' rights and prevent data brokers from exploiting loopholes in the law.
- Laws similar to California's Consumer Privacy Act have been enacted around the world, including in the European Union and Brazil, highlighting the need for stronger global regulations to protect consumers' personal information.
- The study's lead author, Elina van Kempen, Ph.D. candidate in computer science, emphasized that consumers are being forced to jump through hoops to exercise their privacy rights, with only about a 50-50 chance of receiving a reply from data brokers.
- Co-author Gene Tsudik noted that data brokers analyze and monetize consumers' information, often without their knowledge, and that stronger regulations are necessary to prevent malicious actors from exploiting consumers' personal information.
Statistics:
- 543 state-registered data brokers were investigated in the study.
- 57% of data brokers responded to consumer requests, with 43% failing to reply.
- 10 business days is the maximum time allowed for data brokers to confirm receipt of a consumer's request.
- 45 calendar days is the maximum time allowed for data brokers to respond to a consumer's request.
- 50-50% of consumers who submitted verifiable consumer requests received a reply from data brokers.
- 43% of data brokers required consumers to provide sensitive personal information to verify their identity.
- 57% of consumers who submitted verifiable consumer requests reported encountering multistep submission forms, broken links, and live phone calls with untrained staff.
Sources:
- National Science Foundation (NSF)
- University of California, Irvine (UCI)
- International Association of Data Brokers (IADB)
- European Union (EU)
- Brazil's General Data Protection Law (LGPD)
- California Consumer Privacy Act (CCPA)
- University of California, Irvine, news release, July 22, 2025
- Gene Tsudik, co-author of the study, and Elina van Kempen, lead author of the study, quoted in the UCI news release.