Data Brokers: How Invisible Profiles Are Built and Regulated
A breakdown of how data brokers aggregate consumer information without direct interaction, and how new regulations in California and India are shifting the burden of proof for deletion and collection.
Article prepared with AI assistance, then verified, edited, and approved by Nicolas Coutant.
The short version
Data brokers build detailed profiles of individuals they have never met. This is not a glitch in a specific app, but a distinct industry mechanism where information is collected indirectly, inferred, and sold without the user’s direct knowledge. This guide breaks down how these profiles are constructed and examines two emerging regulatory shifts: a proposal in California requiring proof of deletion and a directive in India mandating data collection from online services.
This piece focuses on the mechanics of aggregation and compliance. It is not legal advice, nor a guide on how to evade these rules using tools like VPNs.
Defining the broker: Direct vs. inferred data
To understand the mechanism, one must distinguish between data collected directly by a service you use (like a shopping cart) and data collected by a broker. A broker does not need a relationship with you. Instead, they aggregate records from public registries, loyalty programs, and third-party data exchanges.
The core of the broker model is inference. By combining disparate data points—such as a purchase history from a grocery chain and a location ping from a mobile app—brokers construct a profile that predicts behavior, health status, or financial standing. The user often never interacts with the broker directly; the profile exists in a database that is then licensed to advertisers, insurers, or employers.
The invisible mechanism: Aggregation and resale
The process operates largely outside the visible interface of consumer apps. Data flows through a chain of intermediaries. A single piece of information collected by a website may be sold to a broker, who combines it with millions of other records to create a "persona."
This aggregation happens at scale. The resulting profile is a product. It is sold based on its predictive value, not necessarily on the accuracy of every single data point. Because the transaction happens between companies, the individual remains unaware of the profile's existence, its contents, or who currently holds it. The mechanism relies on the opacity of these data exchanges; without a direct user interface, there is no obvious place for a user to request changes or deletion.
From policy to proof: The California audit proposal
Regulators are now challenging the assumption that a company’s word is enough to prove data deletion. On 7 August, the California Privacy Protection Agency (CPPA) released a preliminary audit proposal targeting this exact issue. According to reporting by the IAPP, this proposal would require data brokers to prove that deletion requests actually work.
The shift is significant. Under current norms, a company might satisfy a request by pointing to a privacy policy or providing a management attestation stating the data is gone. The CPPA proposal moves beyond paper promises. It demands tangible evidence. As noted in the IAPP report, brokers would need to produce records demonstrating that deletion reached every place the data was copied, derived, or sent. This includes:
- System testing records;
- Logs of deletion commands;
- Data maps showing where records reside;
- Sampling and other verification records.
This proposal remains preliminary and has not entered formal rulemaking, but it highlights a move from trusting organizational promises to verifying technical execution.
The traceability challenge: Why logs and maps matter
The requirement for proof introduces a major operational challenge: traceability. In complex digital ecosystems, a single record may exist in dozens of backups, analytics servers, and third-party caches. Simply deleting a record from a primary database does not guarantee it is gone from the entire ecosystem.
To comply with a "proof of deletion" standard, companies must maintain rigorous data maps. These maps track the lifecycle of information, documenting every copy and derivative. Without these maps, a company cannot demonstrate that a deletion request was fully executed. The burden shifts from the regulator trying to find hidden data to the company trying to prove its absence. This creates a new layer of compliance where the internal architecture of data storage becomes a matter of public audit.
Global regulatory shifts: The CERT-in directive in India
While California focuses on the right to delete, other jurisdictions are tightening the rules on collection. In India, a new directive from the Computer Emergency Response Team (CERT-in) has mandated that various online services and companies collect their customers’ data. According to CyberGhost VPN, this directive requires companies to gather specific user information and store it for a period of 5 years.
This mandate affects a broad range of services, including those that previously operated on a "no-logs" or minimal-data basis. The directive aims to centralize data for security and investigative purposes, but it fundamentally alters the privacy landscape for users in the region. It creates a scenario where data collection is not just a business choice for profit, but a legal obligation enforced by state authorities. This contrasts sharply with the California approach, which seeks to limit the permanence of collected data through rigorous deletion verification.
The tension between management and protection
The current landscape reveals a tension between two regulatory philosophies. On one side, there is a push for accountability: ensuring that when a user asks for their data to be deleted, it is technically and verifiably gone. On the other, there is a push for retention: requiring services to collect and store vast amounts of user data for state oversight.
For the data broker industry, this means navigating a complex web of conflicting requirements. A broker operating globally must manage data maps to prove deletion in California while simultaneously ensuring they retain specific records for five years in India. The mechanism of profiling remains powerful, but the rules governing its lifecycle are becoming more granular and demanding of technical proof rather than legal promises.
Going further
- Notes from the IAPP Canada: Data deletion shifting from policy to proof — Explains the California proposal requiring system testing and logs to verify deletion.
- India Orders VPN Companies to Collect and Share User Data — Details the CERT-in directive mandating data collection and 5-year retention for online services.
Sources
Found an error? Email us — we correct factual mistakes and note significant updates on the article. Contact us
Keep exploring
Password managers: free vs paid, what actually matters
A Monday-morning scenario, security model, sync, recovery, free options (browser, Bitwarden, Apple, Google) and paid ones (1Password, Dashlane, Proton Pass, KeePass): an honest comparison to choose — and migrate in about an hour.
Read the article →Public Wi‑Fi: what’s true and what’s myth
Café, airport, hotel: what public Wi‑Fi can actually expose in 2026, what’s overhyped, and the simple habits that matter.
Read the article →What a VPN is actually for (and what it isn’t)
Encryption, IP address (your device’s network identifier), streaming, public Wi‑Fi: what a VPN really changes for your privacy — and which marketing promises to ignore.
Read the article →