On February 9, 2026, the FTC sent PADFAA data broker warning letters to 13 companies, reminding them of their obligations under the Protecting Americans' Data from Foreign Adversaries Act. The agency published a template of the letter and said nothing about who received one. Nearly seven months later the recipients are still unnamed, and no PADFAA complaint has followed. If you have been trying to work out what a PADFAA violation looks like, or whether your own information could end up in a file bound for Beijing or Moscow, this is what is known, what isn't, and why the gap between the two matters.
What PADFAA actually prohibits
PADFAA was signed on April 24, 2024 as part of the foreign-aid package (H.R. 815) and took effect on June 23, 2024. It makes it unlawful for a data broker to sell, license, transfer or otherwise provide access to Americans' "personally identifiable sensitive data" to a foreign adversary country or to any entity controlled by one. The law names four countries: China, Russia, North Korea and Iran. Because it also reaches controlled entities (any company at least 20 percent owned from one of those countries, or headquartered or organized there), routing a sale through a shell company or an intermediary does not get a broker around the rule.
The law does not ban data brokering as a business. A broker can still sell your name and address to a marketer in Ohio tomorrow. What PADFAA bans is one category of buyer. That is a narrower target than the phrase "data broker crackdown" tends to suggest, and it is easy to walk away from this story thinking more changed than actually did.
The definition of "data broker" is narrow too. Under PADFAA a data broker is a company that sells or transfers data it did not collect directly from the person. A social network or a retailer selling data it gathered from its own users is outside the statute, even if the buyer is in Beijing.
What counts as "personally identifiable sensitive data"
The statute's text lists 17 categories, lettered (A) through (Q), and the list covers most of what a modern broker sells. It includes health, financial, genetic and biometric information, precise geolocation, information about a person's sexual behavior, private communications, log-in credentials for accounts or devices, government-issued identifiers such as Social Security, passport and driver's license numbers, information about minors, records of a person's online activity over time and across sites, and an individual's status as a member of the armed forces.
That list is the line between a routine listing and something more dangerous. A name-and-address record is legal to sell to almost anyone, foreign adversary or not. The categories PADFAA protects are the ones that turn a marketing list into a targeting tool: the data that lets someone track a person's movements, get into their accounts, or build a profile detailed enough for coercion.
What the FTC's PADFAA data broker letters said
The FTC's letters cited a specific pattern the agency says it found. In the template's words, the FTC had identified instances in which the recipient offers or has offered "solutions and insights involving the status of an individual as a member of the Armed Forces." Military status is one of the 17 enumerated categories, and it is a useful example of what "sensitive" means in practice: a data point with real value to a foreign intelligence service and close to none to an ordinary marketer, sitting for sale on the open market anyway.
The letters urged each recipient to conduct a comprehensive review of its practices and bring them into compliance immediately. They also spelled out the stakes: PADFAA violations are treated as unfair or deceptive practices under Section 5 of the FTC Act, which opens the door to court injunctions and civil penalties of up to $53,088 per violation.
What the FTC did not do is name the 13 companies, and the template itself, as Wiley's alert on the letters points out, alleges no specific violation. That is consistent with how warning letters function. A warning letter is a step that typically precedes a complaint or a consent order, and naming targets at this stage would tip off the companies and weaken the agency's hand if it later opens a formal investigation. If you have gone looking for a list of "the 13 PADFAA data brokers," it does not exist publicly, and it may never surface unless the FTC escalates against a specific company.
The penalty math, and the record it builds
The $53,088 figure is per violation, not per company. A broker with a large volume of affected records could theoretically face penalties far beyond the headline number, though a warning letter itself imposes nothing. Its function is to put the FTC's position on the record before penalties become an option. If a case eventually reaches court, the letter becomes evidence that the company was told and cannot claim it did not know.
This is also not the FTC's first move against sensitive-data sales. In January 2025 the agency finalized its order against Gravy Analytics and Venntel over location data precise enough to place people at clinics and churches, and in May 2026 it settled its four-year lawsuit against Kochava on similar terms (our FTC location data broker guide covers both). The PADFAA letters extend the same posture into a statute with a foreign-adversary angle. Read together, they show an agency paying attention to what kind of data gets sold and to whom, rather than only whether a broker disclosed its practices in a privacy policy nobody reads.
As of September 6, 2026, though, the letters are where PADFAA enforcement stops. Law firms tracking the statute noted in February that the FTC had yet to bring a public PADFAA action, and we could find no complaint announced since.
What a PADFAA data broker warning letter doesn't fix
None of this retroactively protects anyone. A warning letter changes a broker's incentives going forward and does nothing about data already sold, to anyone. PADFAA gives consumers no right to find out whether their record was part of a sale that broke the law, and it requires no notification after the fact. There is no lookup, no notice, no list to check your name against.
Scope is the other limit. PADFAA restricts sales to foreign-adversary buyers specifically. It does nothing about the much larger, entirely legal market: the hundreds of U.S. people-search sites and data brokers that list your address, phone number, relatives and background details for anyone in the country willing to pay a subscription. That market is untouched by this law, and it is the one most people run into when they search their own name.
The law is also a prohibition, not a disclosure regime. It creates no mechanism for a consumer to ask a broker whether their data was ever offered to a foreign buyer, and it does not oblige the FTC to publish who it is investigating until a case is formally filed. Anonymity at the warning-letter stage is how the process is designed to work until a company crosses from "warned" to "charged."
One state registry gives a partial view the federal law does not. California's Delete Act requires registered brokers to disclose whether they sold or shared consumers' data with a foreign actor in the past year. When we pulled the California data broker registry CSV on September 1, 2026, 26 of the 603 registered brokers answered yes to that question, and 42 said they collect government-issued identification numbers. Those are self-reported answers and "foreign actor" is broader than "foreign adversary," but it is the only public count of its kind we know of, and it is a list you can read.
What to actually do
If you are waiting on regulators to clean up your data footprint, the wait has no end date attached to it. PADFAA enforcement, when and if it happens, will target a narrow slice of the market. Getting your information off the domestic sites that show up when you Google yourself is still a manual, recurring job: find each listing, file an opt-out with each one, and check back, because listings come back.
From our own removal work, the friction has nothing to do with the law. The PeopleConnect suppression tool that covers TruthFinder, Intelius and Instant Checkmate asks for your email, name and date of birth before it shows you anything, then sends a verification code to a phone number it already holds for the record, which is frequently stale (our PeopleConnect guide walks through the workarounds). PeopleSearchNow parks its opt-out form behind an aggressive Cloudflare gate, and its free previews funnel straight into paid background-check sites. Our data broker opt-out guide covers the rest site by site.
That is the gap between "the FTC sent a letter" and "your data is safer." One is a regulatory signal aimed at a specific, narrow threat. The other requires someone removing your listings, site by site, on a schedule nobody in Washington is tracking. Delist My Data is being built to do that work and to re-file when a listing reappears. We're in pre-launch; join the waitlist for founding-member access.
Sources
- FTC reminds data brokers of their obligations to comply with PADFAA (February 2026)
- Public Law 118-50, Division I: Protecting Americans' Data from Foreign Adversaries Act of 2024 (govinfo)
- Wiley: FTC sends warning letters to data brokers on PADFA compliance
- Wiley: New federal data broker law will restrict certain foreign data sales effective June 23
- Morrison Foerster: U.S. cyber and privacy regulators intensify focus on data transfers to foreign adversaries (February 18, 2026)
- FTC finalizes order prohibiting Gravy Analytics, Venntel from selling sensitive location data (January 14, 2025)
- California Privacy Protection Agency: Data Broker Registry