Press Release: New Report Finds State Privacy Laws Fail to Protect Public Servants from Doxxing, Death Threats, and Violence

Novel Analysis of 19 State Consumer Privacy Laws Reveals Major Gaps in Protections For Public Servants That Unnecessarily Endanger Them

 

Washington, D.C. — As violent threats against America’s public servants rise across all levels of government, a new report from the Public Service Alliance (PSA) finds that state consumer privacy laws are largely failing to protect those who serve from the misuse of their personal information, putting them and their families at unnecessary risk.

The report is among the first to systematically analyze how so-called “comprehensive consumer data privacy laws” in 19 states address a critical but under-examined issue: how the availability, aggregation, and sale of public servants’ personal data enables doxxing, death threats, swatting, and other acts of intimidation and violence. PSA’s analysis of the “data-to-violence pipeline” shows that existing privacy frameworks leave a major vulnerability unaddressed: the role of public records and data brokers in exposing sensitive personal information such as home addresses and phone numbers.

“The widespread availability of personal information in public records — and its sale by data brokers — is exacerbating the rise in political violence. Protecting First Amendment principles and the physical safety of public servants, their families, and their colleagues are not mutually exclusive,” said Justin Sherman, Interim Vice President of the PSA Security Project and the report’s author. “No American should have to choose between serving their community and keeping their family safe. Closing the gaps in state privacy laws is essential to protecting the people who serve their communities and their country.”

Key Findings

PSA evaluated 19 state laws against four core questions related to data redaction rights, data broker obligations, and enforcement. The results reveal sweeping gaps:

  • Zero of the 19 laws give individuals who have been violently targeted — or who fear being targeted — the right to compel state agencies to redact sensitive personal data from public records.
  • Zero laws allow individuals to compel data brokers to stop selling personal data that brokers obtained from public records — even if those records are later redacted.
  • All 19 laws provide some right for consumers to opt out of the sale of their data by private companies, but those rights are limited.
  • Zero laws include a private right of action to allow individuals to sue data brokers that illegally refuse or fail to comply with opt-out requests.

In practical terms, a public servant receiving death threats cannot legally require the state to shield their home address in public records nor entirely stop data brokers from profiting off the sale of that data.

California: Strongest on Paper, But Still Limited

Among the states analyzed, California has the most robust framework in part due to a recently launched, state-run “one-stop shop” website that allows consumers to submit free deletion and opt-out requests to all registered data brokers. Even so, California’s system still reflects many of the same structural limits found elsewhere, particularly regarding public records and enforcement.

The Public Record Problem

Although comprehensive state privacy laws primarily regulate private companies, the report emphasizes that the exclusion of government-held public records is part of the problem. Public records that can be used for legitimate public-interest reporting can also be weaponized to locate, intimidate, or harm public servants and their families. Once digitized and widely accessible, public records can be scraped, aggregated, and resold by data brokers.

Policy Recommendations

To better protect public servants while preserving First Amendment principles, PSA recommends four key elements for state privacy laws going forward:

  1. Provide protections to all public servants — including to not only judges, prosecutors, and law enforcement officers (as some existing measures do), but also to state legislators, local elected officials, civil servants, educators, military service members, and other government employees.
  2. Require rapid data takedowns — mandating that government agencies and data brokers remove covered personal data within 10 days of a valid request.
  3. Address both private data sources and public records — not just privately obtained commercial data.
  4. Establish a private right of action — enabling individuals, including public servants in their personal capacities, to seek legal recourse outside of state regulatory enforcement when agencies or companies fail to comply.

About the Public Service Alliance

The Public Service Alliance (PSA) empowers America’s nearly 40 million current and former public servants, across political lines, to better and more affordably protect themselves and their families.

Through the PSA Marketplace, current and former government employees nationwide can save time and money on the services they need and deserve, including those to protect their privacy and security, and personal and professional well-being. Through the PSA Security Project, PSA is raising national awareness of the threats facing public servants, while advancing reforms that make public service safer, as permissible, so no American is forced to choose between serving their community and protecting their family.

Learn more at PublicServiceAlliance.com.