Privacy-Preserving Consumer Rights Requests to Data Brokers
Skip to main content
eScholarship
Open Access Publications from the University of California

UC Irvine

UC Irvine Electronic Theses and Dissertations bannerUC Irvine

Privacy-Preserving Consumer Rights Requests to Data Brokers

Creative Commons 'BY' version 4.0 license
Abstract

Data brokers collect and sell people's personal information, often without their knowledge, to advertisers, employers, insurers, government agencies, and other third parties, creating risks that range from unwanted profiling to identity theft and stalking. Privacy regulations such as European Union's General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and Brazil's Lei Geral de Proteção de Dados Pessoais (LGPD) are meant to provide consumers with agency over their data, granting them rights to access, delete, or opt out of the sale of their data. Effectively exercising these rights, however, is contingent on verifying that the person making the request is who they claim to be. This dissertation shows that identity verification, rather than protecting consumers, becomes a privacy threat. We establish this systematically through two large-scale studies covering the entire California data broker registry. The first study submits data access requests to all 500+ registered brokers: over 40% never respond, pointing to a systemic failure to comply. The second study targets opt-out and deletion, the two most commonly exercised rights, and finds a similar pattern of non-compliance. More than one-fifth of brokers demand identity verification for opt-out requests, despite the CCPA explicitly prohibiting it. Across both studies, brokers consistently request a variety of personal information they do not already hold, for identity verification purposes: consumer requests are a new source of data collection. This dissertation addresses this threat directly and proposes two systems that make identity verification private by design. PIVA lets a consumer prove their identity to a broker using a private set intersection variant, private list intersection, guaranteeing that the broker learns no new personal information about the consumer through the request. PIVOT further reduces consumer burden, allowing a consumer to submit a single request that reaches every registered broker, through an intermediary that performs proxy re-encryption on the consumer's behalf and remains oblivious to the consumer's personal information. Both systems are implemented and benchmarked for efficiency, demonstrating that privacy-preserving identity verification is practical at scale.