Your membership has expired

The payment for your account couldn't be processed or you've canceled your account with us.

Re-activate

Companies Make It Hard to Access Your Personal Data Under State Privacy Laws, CR Finds

One-quarter of companies and a third of data brokers failed to fulfill our volunteers' requests

Data brokers info with red X
Numerous companies couldn't or wouldn't confirm our volunteers' identities—and therefore refused to fulfill their data requests.
Illustration: Consumer Reports, Getty Images

Nearly every time you buy something online or sign up for a loyalty program, you leave behind personal information that can be collected, shared, and sold among companies including advertisers, retailers, and data brokers. This kind of information is sometimes used to charge consumers more for a range of products and services, from groceries to insurance to mortgages, and to target them for financial fraud and identity theft. 

A growing number of state privacy laws were designed to give consumers some control over that information, including the right to see what companies know about them. But a yearlong Consumer Reports investigation found that exercising those rights can often be extremely difficult—and that many companies and data brokers appear to be falling short of their legal obligations. 

Over the past year, CR worked with 84 citizen volunteers to request their personal data from 169 companies they regularly interact with and 22 data brokers. The results were concerning: Roughly 25 percent of requests to companies failed to receive a response. Among data brokers, the failure rate was 34 percent, even though some of those brokers claim to maintain data on the vast majority of U.S. households.

More on Privacy

The results echo previous research suggesting that consumer data privacy laws are not working as intended. A CR study with Wesleyan University in Middleton, Conn., published last year found that 12 of 40 companies that received an opt-out request from a customer still sent them targeted advertisements. 

Several large data brokers and companies fared particularly poorly in CR’s review. 

Civis Analytics, a data broker that counts among its clients the American Civil Liberties Union, the Human Rights Campaign, and the National Democratic Redistricting Committee, denied two-thirds of the 22 data access requests submitted by CR volunteers. Those failures included outright denials, errors on its submission portal, and two nonresponses. Civis also required customers to upload a government ID but then failed to send the promised link to do so. The company didn’t respond to CR’s request for comment. 

ZoomInfo, a near-ubiquitous internet data broker that now bills itself as an AI-enabled sales lead generator, successfully fulfilled just 29 percent of the volunteers’ access requests. 23andMe, the Palo Alto-based company best known for its direct-to-consumer genetic testing and now emerging from bankruptcy as a nonprofit, fared even worse, at 20 percent. 

ZoomInfo said in a statement that CR’s “generalized percentages can be misleading without accounting for the structural and operational realities of privacy request fulfillment.” The company said in August that it routinely processes thousands of requests and that, over the previous month, it had handled nearly 10,000 opt-out and deletion requests, along with access and correction inquiries, “with an average resolution time of 228 hours, well within any applicable statutory window.” 

23andMe said it designs its services to make it “as easy as possible” for customers to manage their privacy. The company said customers can submit access and deletion requests directly through their accounts, where they are processed automatically and customers can correct most of their information themselves.

Getting Your Own Data Can Be Surprisingly Difficult

One of the most common reasons CR volunteer requests failed was surprisingly basic: The companies were unable—or unwilling—to confirm that the requesters were who they claimed to be.

For example, Deloitte, the global audit, tax, and consulting firm that runs a customer data product called InSightIQ, found one requester’s name, address, and phone number in its data but said it couldn’t verify the person’s identity to a “reasonably high degree of certainty.” It therefore refused to disclose the information it held about the requester. 

In a statement, Deloitte said that “any such requests are handled individually and according to relevant legal requirements,” which may include identity verification meant to prevent personal information from being disclosed to bad actors making fraudulent requests.

LiveRamp, which describes itself as an AI-driven marketer, required volunteers to upload both a government-issued ID and a live selfie. But the link expired before a volunteer without a smartphone could complete the upload, and a replacement link failed as well. LiveRamp did not respond to CR’s request to comment. (CR uses LiveRamp to find new members.) 

Epsilon, one of the world’s largest data brokers, requires consumers requesting their personal data to verify their identity through third-party vendors. But those vendors repeatedly failed to verify our volunteers’ identities. One requester failed three separate times. Another called a vendor directly and was told there is no way for them to figure out who he is because he shared the same first and last names with another person in their database. If the vendor can’t verify a requester’s identity, Epsilon said, the consumer can’t get their personal data from the company.

Even when some of our volunteers did get their info, many reports were riddled with errors. 

One volunteer’s report from Acxiom, another large data broker, showed four different ages, listed him as both male and female, predicted three markedly different incomes, and listed his jobs as “farmer,” “homemaker,” and a “self-employed white collar.” (In fact, he’s none of those.)

A footnote in Acxiom’s reports said that the company excludes from the reports it provides to consumers any personal data it has obtained from public sources, meaning consumers do not see all of the information the company may hold about them. Acxiom also maintains parallel fair lending and Regulation B versions of its customer inferences, meaning this information complied with federal lending laws and could be used for credit, insurance, or employment eligibility. Another footnote in Acxiom’s reports said that the data broker doesn’t process sensitive personal information for residents of Colorado, Connecticut, Montana, Texas, Oregon, or Virginia (this is because these states have comparatively stronger privacy laws). But that leaves 44 other states, the District of Columbia, and other territories.

In a statement, Acxiom said it “exclusively utilizes data that has been ethically sourced,” and is committed to using it responsibly and transparently. The company said its client credentialing is “robust and multi-layered” and that it forbids clients from using its information in risk modeling, in underwriting, or to disadvantage consumers. (CR uses information derived from data brokers, including Acxiom, to understand consumer interests, including the likelihood of becoming a Consumer Reports member. It does not use Acxiom data to set prices for its products.)

CR volunteers who were able to obtain reports from data broker giant Epsilon were provided a “sensitive data” table containing information about their race, ethnicity, political leanings, finances, union membership, and health, which the company may sell to more than 250 other companies. Epsilon declined to comment for this article.

Other companies fared considerably better. Several complied with every request submitted by CR volunteers, including Amazon (17 out of 17), Equifax (5 of 5), LexisNexis (6 of 6), and Target (8 of 8).

25%

Portion of CR volunteer data requests to companies that received no response.

34%

Portion of CR volunteer data requests to
data brokers that received no response.

Source: CR research.

A Patchwork of Privacy Rights

Why do so many companies appear to have trouble complying with state privacy laws? The reasons may start with the laws themselves.

California enacted the nation’s first comprehensive privacy law in 2018, giving residents the right to request the data companies have compiled about them, opt out of further data collection, and ask companies to delete their information.

Twenty-two other states, and counting, have followed with their own privacy laws. By one estimate, roughly 43 percent of all Americans are now covered by a state privacy law, and that number will increase as laws passed in Alabama, Louisiana, Oklahoma, and Vermont go into effect over the next 18 months.

But those laws offer consumers substantially different levels of protection. A handful of states—including California, Colorado, Connecticut, Delaware, Maryland, Minnesota, and Oregon—have relatively strong protections for residents and meaningful enforcement provisions that can result in civil penalties and fines for companies found to be in violation. 

Other states have much weaker laws. Florida’s, for example, applies only to companies with at least $1 billion in annual revenues, among other conditions, leaving relatively few companies subject to it.

CR’s investigation suggests that where a consumer lives may make a difference. Residents of California and Maryland, two states with relatively strong privacy laws, had denial rates of roughly 5 percent and 4 percent, respectively, compared with an average of roughly 12 percent among residents of Delaware, Oregon, and Minnesota.

But having a strong law on the books is no guarantee that companies will follow it. Maryland offers a revealing example. The state’s privacy law, which went into effect in October 2025, is among the strongest in the country. It bans the sale of sensitive customer data, including health and biometric data. It also prohibits companies from collecting personal data beyond what is reasonably necessary to provide a particular product or service requested by the customer, a principle known as “data minimization.”

Yet, as part of CR’s project, one Gaithersburg, Md., resident who requested their personal data from the data broker Epsilon received a report that contained six years of itemized transactions covering 60 different purchases, ranging from home and garden products and food and drinks to apparel.

Each purchase was labeled with a source code indicating, among other things, whether it came from an internet purchase or through social media and whether it was purchased at full price. The records also included “yes” or “no” fields for “Do Not Mail” and “Do Not Rent,” corresponding to whether the customer had told the retailer not to share their info with other companies. Several purchases that were explicitly tagged as not shareable nevertheless ended up in the Epsilon report.

The Question of Enforcement

Even strong privacy laws may have a limited effect if companies don’t expect them to be enforced, says Sebastian Zimmeck, who runs a privacy tech lab at Wesleyan University and partnered with CR to create an internet browser extension called Global Privacy Control, which automatically tells websites you visit not to sell or share your data. 

Zimmeck says representatives of one of the largest U.S. automakers contacted him for advice in 2024 when they realized the company was subject to California’s landmark privacy law—some six years after it was passed. For Zimmeck, the episode illustrated why enforcement matters: Companies can’t be expected to consistently comply with privacy laws if states don’t enforce them consistently and robustly.

Some states are now doing just that. 

Maryland’s attorney general has received about 60 privacy-related consumer complaints since the state’s law went into effect and is reviewing them for possible violations, the office told CR.

Oregon is further along. Its Department of Justice has fielded more than 500 consumer complaints since its law was enacted in July 2024. And its attorney general’s office has sent 33 warning letters to allegedly noncompliant companies, including BeenVerified, FastPeopleSearch, ID.me, Intelius, Nielsen, SocialCatfish, and Radaris, according to copies of those letters obtained by CR through open-records requests.

Connecticut announced the first settlement under its law in 2025, an $85,000 fine against TicketNetwork. In February, the attorney general disclosed investigations into several as-yet-unnamed companies, including a hormonal fertility tracking app, a messaging platform “popular with kids and teens,” and an AI chatbot that allegedly harmed children because of unspecified “design features.”

Small fines and warning letters, however, may have limited effect on some of the largest companies in the data economy, says Caroline Kraczon, counsel at the nonprofit Electronic Privacy Information Center and who focuses on consumer privacy issues. Many large companies simply “budget in the cost of noncompliance,” she says.

But Texas and California have been testing whether much bigger penalties can change that calculation. 

In 2024, Texas launched a consumer data privacy initiative in Attorney General Ken Paxton’s office, notifying more than 100 companies that they were out of compliance with its data broker law, which imposes civil penalties of $100 per day. It also announced a $1.4 billion settlement with Meta under its biometric privacy law over allegations that the company used facial recognition tools without users’ consent.

And last year, Paxton’s office sued Allstate and one of its subsidiaries for allegedly collecting and selling driving data of roughly 45 million Americans through their smartphone apps without proper user disclosure. That case is ongoing, but a similar lawsuit filed against Google resulted in a $1.375 billion settlement in May 2025.

In many ways, though, California remains the most developed experiment in privacy enforcement. 

It is the only state in the country with a dedicated privacy regulator, California Privacy Protection Agency, or CalPrivacy, which works with the state’s attorney general to police consumer privacy violations. Regulators have also created a Data Broker Enforcement Strike Force, which investigates privacy-law violations and data breaches that result in consumer data ending up in the hands of bad actors and scammers.

That coordinated approach has resulted in some major cases. 

In May, California reached a settlement with General Motors that included $12.75 million in fines, the state’s largest financial penalty to date, and permanently banned the automaker from selling customers’ location and driving data to data brokers. Similar fines and settlements have been levied against American Honda Motor Co., PlayOn Sports, and Tractor Supply.

CalPrivacy recently settled with 12 data brokers for failing to register as required by the Delete Act, a state law designed to let residents delete their personal data from hundreds of registered data brokers with a single request. Among the data brokers regulators said had not registered was DataMasters, a Texas company that bought and resold personal information about millions of Alzheimer’s and other patients for targeted advertising. Another, Background Alert, agreed to shut down after regulators found it had promoted its ability to uncover “scary” amounts of information about people.

And additional consumer privacy protections will soon take effect in California.

Under the Delete Act, data brokers in the state are beginning to process consumer deletion requests through a first-in-the-nation system called Delete Request and Opt-out Platform, or DROP. As of Aug. 1, data brokers have 45 days to download lists of customers who requested deletion and remove their information from their servers. (Consumer Reports developed its own product to help consumers delete and opt out, which was recently acquired by Delete Me.)

Since it launched, roughly 325,000 Californians have signed up for California’s DROP deletion platform, out of a state population of more than 39 million. A broker audit requirement starts in 2028.

For Jennifer King, PhD, a privacy and data policy fellow at Stanford’s Institute for Human-Centered Artificial Intelligence, who has advised CalPrivacy, California illustrates both the promise and limitations of state enforcement.

“California is putting all the right tools in place. They’re small but mighty,” she said. “But they are still small.”


Derek Kravitz

Derek Kravitz is an investigative journalist on the special projects team at Consumer Reports. He joined CR in 2024, covering the digital marketplace. He has worked as a reporter and editor for more than 15 years and teaches at Columbia University. Three projects he has worked on, for The Washington Post and ProPublica, have been finalists for the Pulitzer Prize. Send him tips or feedback at derek.kravitz@consumer.org or via Signal: @derek_kravitz.31