BeyondSingularity

← Data Privacy, Ethics and Society outline

Module 05 / 14  ·  Phase 2 — Architecture: law, technology, and the human cost

5. Data brokers and the invisible profile

This week in the arc

Coming from

Governing the risk: frameworks and their limits

Going to

When innocence stops protecting you

Core

The failure of every safeguard we've tested — personal (consent, anonymization) and institutional (a governance framework) alike — is structural, not personal: an individual-sized tool for a structural-sized problem. This week: the structure itself, and it has a name and a business model.

There is an entire industry — Acxiom, Experian, LexisNexis, Epsilon, and dozens more — whose product is you. Not a service you use; a dossier about you, assembled from thousands of scattered sources: purchases, locations, public records, app data, the “anonymized” driving data from Week 3’s car. You have no account with these companies. You never agreed to anything. Most people have never heard their names. And yet they hold a profile of you that you cannot see, cannot correct, and mostly cannot delete.

The key idea this week is aggregation — and it matters for the whole rest of the course. No single fact in your profile is a secret. That you bought a lamp, drove to a clinic, searched a symptom, live on a certain street — each is trivial alone. The harm is in the assembly: innocuous pieces combine into a portrait that reveals things you never disclosed and never would. Hold onto that idea. Some later harms will look like aggregation and turn out to be something else entirely.

Cases — tagged by category, name the kind before you react

The profile you've never seenharm from assembly

Brokers buy, combine, and sell detailed behavioral dossiers — financial records, health-adjacent inferences, purchase history, location, “personality segments” — for pennies per record, to retailers, insurers, political campaigns, and financial firms. You have no relationship with them, no easy view into what they hold, and no reliable way to correct or erase it. The portrait exists whether or not you ever consented to a single piece of it.

The location brokersharm from assembly

A layer of the industry harvests precise phone-location data through app SDKs — where you sleep, work, worship, seek care — and sells it. Regulators have moved against several for selling sensitive location data. Note where this points: some buyers are government agencies, who get the movements of millions without a warrant. Hold that thread — it’s next week.

Reading

Required Christl, “Corporate Surveillance in Everyday Life” Cracked Labs, 2017
Recommended Current reporting on FTC data-broker enforcement and the state ‘delete’ laws (California DELETE Act and others) 2025–2026

Assessment

Reconstruct the aggregation

~1 page. List a handful of ordinary, individually-trivial data points a broker could plausibly have about your last week — a purchase, a location, a search, a public record. Then show what could be inferred from the assembly that no single point reveals. Name the harm precisely, and run it through one lens. (Don’t include anything you’d be uncomfortable writing down — the point is the mechanism, not disclosure.)

Discussion

  • You have no account with these companies and never agreed to anything. In what sense, if any, did you consent to the profile they hold?
  • Every single fact in your broker profile is trivial on its own. So where, exactly, is the harm — and can you name it precisely?
  • You can see and correct what your bank knows about you. You can't with a data broker. Does that difference matter morally, or just practically?