Fentner

Markets · Opinion

Buyers of behavioural data are about to inherit their vendors' lawsuits

Ambient capture is flooding broker supply chains with data nobody agreed to share. B2B marketers who buy it without checking provenance will end up sharing the legal bill.

Apple's new Watch can listen to every word near it and turn the day into a Siri Recap. Meta wants something like a hundred glasses models in shops before this year is out. I read The Verge's account of the backlash expecting a consumer story about creeps in cafes. I finished it thinking about the enrichment line in every B2B marketing budget I have seen.

The article is about wearers and bystanders. I think the money, and eventually the liability, sits somewhere else: with the companies that buy the exhaust. Apple insists its features transcribe only a rolling 15 seconds and never identify speakers, and I have no evidence it sells any of this. But the device culture it is normalising, where capture is the default and the bystander's job is to notice a chime, is the same culture that fills broker warehouses. Every app with a location SDK, every connected car, every always-on gadget feeds a supply chain that ends in a CSV on a demand-gen manager's laptop.

Look at how that chain works. According to the FTC's complaint, Gravy Analytics has no direct relationship with consumers. It buys data, including precise geolocation, from suppliers and sells it to commercial and government customers. In January 2025 the FTC finalised orders against Gravy and Mobilewalla. Days before that, Gravy was reported to have suffered a breach, and it now faces a proposed class action in federal court in New Jersey. That is a vendor carrying regulatory orders, breach exposure and plaintiffs' lawyers at the same time, and it is exactly the kind of company whose output ends up in intent scores and audience segments sold to software firms.

Most buyers I talk to assume the vendor carries that risk. The regulators have started to disagree. In March 2025 California's privacy agency fined American Honda $632,500, and one of the violations was failing to have the required contracts with the ad-tech companies it shared personal data with. The agency went after Honda, the company handing the data over, while the ad-tech recipients stayed out of that order. In January 2025 the Texas Attorney General sued Allstate and its subsidiary Arity, alleging they collected driving data through apps and sold it without consent, in what was reported as the first case under the state's comprehensive privacy law. California's AG took $1.55 million from Healthline Media for sharing data with advertisers after people had opted out.

Then there is the Delete Act. Since 1 August 2026, registered data brokers in California must process deletion requests through the state's DROP platform, with penalties of $200 per day for each request they fail to honour. Consumers have been able to file through it since January. I would not want to be the marketing lead explaining why a list bought in March still holds thousands of people who have since told the broker to erase them, and why nobody asked the broker whether it had.

The sceptic's case is real and I take it seriously. The CFPB withdrew its proposed rule treating many brokers as consumer reporting agencies in May 2025. America still has no federal privacy law. Enforcement against companies that merely buy B2B data has been rare. If you run pipeline for a mid-market SaaS firm, the odds of an FTC letter landing on your desk this year are low, and your CFO knows it.

I think that reading looks in the wrong direction. Federal inaction pushes the fight to state regulators and plaintiffs, who are less predictable and far more numerous. And they read the room. The Verge describes people vandalising Flock cameras, an app that sniffs out nearby smart glasses climbing into the App Store's top paid charts, and bars and nightclubs banning anyone wearing them. Jenna Sherman of UltraViolet put it plainly: "Opt-out models are not consent." When that sentiment reaches a jury in a data-breach class action, the defendant list will not stop at the broker. Discovery will ask who bought the records, what they paid, and what diligence they did. Pointing at the vendor's own assurance of compliance will sound thin next to a Honda-style finding about missing contracts.

The vendors know this, which is why so many enrichment contracts now carry indemnities that are generous on paper and backed by companies whose balance sheets could not survive a single serious judgment. An indemnity from a broker that is itself being sued is worth roughly nothing.

So run a test before your next renewal. Pull a random sample of records from your last enrichment or intent purchase and send them back to the vendor. Ask, for each one, where it came from, when it was collected, what consent basis applied, and whether the person has filed a DROP deletion request. Give them until the renewal date. If they cannot answer for most of the sample, cancel the renewal and delete the file. I think that within a year a state regulator will name a B2B buyer of broker data, rather than the broker itself, in an enforcement action, and the fine will be larger than Honda's.

Prompted by Everything is spying on you and there’s no opting out, The Verge.