杜克大学-数据经销商和美军人员数据出售(英)-2023.11-51页_604kb
报告摘要
Summary of Data Brokers and the Sale of Data on U.S. Military Personnel Risks to Privacy, Safety, and National Security
Overview
This report examines the multi-billion-dollar data broker industry and its sale of sensitive information about U.S. military personnel and veterans. The study investigated what data brokers collect and sell regarding active-duty military, veterans, and their families, and the associated risks to national security. Key findings reveal that personally identifiable information, including health data and location details, is readily available through data brokers at low costs, with minimal verification processes.
Methodology
The research involved three phases:
- Web scraping of 533 data broker websites to identify mentions of military-related terms.
- Purchasing data from U.S. and non-U.S. domains (e.g., .asia) through deceptive means to assess availability and controls.
- Analysis of purchased data to confirm sensitivity and verifiability.
Key Findings
- Data brokers advertise and sell a wide range of sensitive, individually identifiable data, including health records, financial information, political affiliations, and geolocation data.
- It is easy to obtain this data with as little as $0.12 per record, often purchased without identity verification, demonstrating low barriers to access.
- The data can be purchased both from U.S.-based domains and internationally (e.g., .asia), raising concerns about foreign exploitation.
- This ecosystem poses significant risks, including profiling, blackmail, stalking, and targeting by malicious actors, due to inadequate controls and lack of anonymization claims.
Risks to National Security
Foreign adversaries could use the sold data to compromise U.S. military personnel through profiling, blackmail, information campaigns, or espionage, leveraging detailed personal and location data. Existing regulatory gaps allow such data flows without sufficient safeguards.
Policy Recommendations
- Congress should pass comprehensive privacy legislation (e.g., similar to the American Data Privacy and Protection Act) to restrict data broker activities, including bans on third-party data sales and enhanced security requirements.
- Regulatory agencies need to enforce rules against re-identification and unauthorized data sharing, with specific focus on military-related data.
- The Department of Defense must assess data flows in its contracts and implement stricter vetting for contractors to prevent data leakage.
- A federal privacy law should preempt state-level efforts to ensure uniform protection across all U.S. citizens.
试读结束,高清完整版pdf/doc/ppt,请点下载