Data & identity
Data broker
A data broker is a company that collects personal information about consumers from many sources, often without a direct relationship with them, and sells or licenses it to others.
Data brokers gather information from public records, apps, websites, loyalty programmes, surveys, location data SDKs and other companies, then combine it into profiles and segments. They sell it for marketing, identity verification, fraud prevention, credit and risk, and sometimes more controversial uses.
In advertising, brokers supply third-party data segments, identity links for identity graphs and data onboarding. Well-known brokers include large credit bureaus and marketing data companies, but thousands of smaller firms exist.
Regulators have focused on brokers intensively. Several US states, including California, Vermont, Texas and Oregon, require brokers to register; California's Delete Act creates a single mechanism for consumers to request deletion from all registered brokers. The FTC has taken action against brokers selling sensitive location data. In Europe, GDPR makes most broker models hard to justify without consent. Advertisers using broker data should check provenance, consent and sensitive-category restrictions.
Think of it like this
A data broker is like a gossip who collects snippets about everyone in town from many sources and sells the compiled notebook to anyone who pays.
An example
A US advertiser buys a "new homeowners" segment from a data broker built from public property records and change-of-address data, and must honour California residents' opt-out requests.
Related terms
Third-party data
Third-party data is information about people collected by companies with no direct relationship to them, then aggregated and sold or licensed to advertisers, often as ready-made audience segments.
Identity graph
An identity graph is a database that links the many identifiers belonging to the same person or household, such as emails, device IDs, cookies and IP addresses, into one profile.
CCPA / CPRA
The CCPA, as amended by the CPRA, is California's consumer privacy law giving residents rights to know, delete, correct and opt out of the sale or sharing of their personal information.
GDPR
The GDPR (General Data Protection Regulation) is the European Union's data protection law, applying since May 2018, which governs how organisations collect and use personal data about people in the EU.
PII (personally identifiable information)
PII (personally identifiable information) is information that identifies, or can be used to identify, a specific person, such as a name, email, phone number or government ID number.
Sources: California Attorney General: CCPA, GDPR full text (gdpr-info.eu)