The Federal Trade Commission sent warning letters to thirteen data brokers on 9 February 2026, cautioning them about requirements under the Protecting Americans’ Data from Foreign Adversaries Act, which restricts the sale of US consumer data to designated foreign adversaries.
Warning letters are not enforcement. They indicate a regulator has looked at a market and concluded that a reminder is warranted, which is itself informative.
The Espionage Files And The Commercial Files Converge Here
This desk has spent a great deal of this year on state-aligned intrusion — the telecom campaign in 26-0715, pre-positioning in 26-0601, the harvest-now collection in 26-0106. All of it describes acquiring data covertly at considerable cost and risk.
Commercially available data reaches a similar destination by purchase. Location traces, device identifiers and behavioural profiles bought on an open market require no intrusion, generate no incident, and leave no evidence for anyone to file.
Onward Sale Is The Part Nobody Tracks
The structural difficulty is that a broker sells to a purchaser who may resell. Contractual restrictions bind the first buyer, and after two or three transfers nobody can establish where a dataset ended up.
A restriction on selling to a designated adversary is therefore hard to comply with in good faith and harder to enforce, because the seller frequently does not know who the ultimate recipient is.
Which Makes Collection The Only Tractable Control
If onward flows cannot be traced, restricting who may buy has limited effect. The point at which the data can actually be controlled is where it is collected — which is the argument for minimisation the industry has resisted for two decades.
Compiled from published regulatory analysis, listed below. Warning letters are not findings of violation, and we name no recipients. Corrections: corrections@forensicpost.com.