SECURE Data Act Data Broker Requirements — Registration, Disclosure & Compliance
What Is a Data Broker Under the SECURE Data Act?
A data broker is a controller that meets two conditions:
- It collects and processes personal data about consumers who are not its customers, clients, users, readers, or subscribers
- It derives 50% or more of its annual gross revenue from selling that personal data
If you’re selling data about people who have no direct relationship with your business, and that’s your primary revenue source, you are a data broker under this bill.
Data Broker Obligations
Data brokers face three specific requirements beyond the standard controller obligations:
1. Public Disclosure on Website
Every data broker must post a conspicuous notice on their public website or app that:
- Clearly states they are a data broker
- Is clear, not misleading, and easy to find
- Explains how consumers can exercise their privacy rights
2. Annual Registration with the FTC
Within 12 months of the law taking effect, and every year thereafter, data brokers must register with the Federal Trade Commission by filing a registration statement and paying a reasonable fee.
The registration must include:
- Legal name of the data broker
- Contact person, address, email, phone number, and website
- Description of each category of personal data sold
- Whether the data broker implements a purchaser credentialing process (vetting who can buy the data)
- Details of any data breach reported to federal or state authorities in the prior year, including number of consumers affected
- Link to privacy policy
- Link to a page explaining how consumers can exercise their rights
3. Public Registry
Within 18 months of enactment, the FTC must create and maintain a publicly searchable registry of all registered data brokers. This registry will include links to each broker’s privacy policy and consumer rights page.
Why This Matters
The data broker industry has operated largely in the shadows in the US. Companies like Acxiom, LexisNexis, and hundreds of smaller operators buy and sell detailed profiles on hundreds of millions of Americans — often without those Americans’ knowledge. This section brings mandatory transparency and creates a public record of who is operating in the space.
Key Takeaways
- Data brokers = companies deriving 50%+ of revenue from selling data about non-customers
- Must publicly disclose their status as a data broker on their website
- Must register annually with the FTC within 12 months of enactment
- FTC must publish a public searchable registry within 18 months
- Registration requires disclosing data categories, breach history, and purchaser credentialing
Frequently Asked Questions
Is a company like Facebook or Google a data broker under this definition? Likely not under this specific definition. The 50% revenue threshold is key — Meta and Google derive most of their revenue from advertising, not from directly selling data. However, they are still controllers subject to all other provisions of the Act.
What if a data broker fails to register? Failure to register would be a violation of the Act, enforceable by the FTC and state AGs with the full force of the Federal Trade Commission Act penalties.
Does the purchaser credentialing disclosure mean brokers must credential their buyers? No — it only requires disclosure of whether they do so. The bill does not mandate purchaser credentialing, only transparency about the practice.