Definition
Rules aimed at companies that buy and sell personal consumer information in bulk, specifically addressing the risk that AI developers quietly source training data from these opaque middlemen rather than directly from consumers. Weak enforcement here means privacy protections consumers think they have can be routed around entirely.
Why it matters
If your company buys third-party data to train or fine-tune AI models, weak data-broker compliance upstream becomes your legal and reputational exposure downstream — 'we didn't collect it ourselves' is not a reliable defense.