The FTC Just Reminded Data Brokers That Military Status Is Sensitive Data
The FTC sent warning letters to 13 data brokers over their obligations under PADFAA, highlighting military status alongside health, biometric, financial, and location data.
On February 9, 2026, the Federal Trade Commission said it sent warning letters to 13 data brokers about their responsibilities under the Protecting Americans’ Data from Foreign Adversaries Act of 2024, usually shortened to PADFAA. The announcement is easy to skim past as another compliance reminder. It is more revealing than that. The FTC singled out data products that offered “solutions and insights” about whether an individual was a member of the U.S. Armed Forces. That detail shows how the agency is thinking about sensitive data: not only as a medical record or a precise location, but also as information that can expose a person’s relationship to the state or military. What PADFAA restricts PADFAA restricts data brokers from selling, licensing, releasing, disclosing, or otherwise providing access to personally identifiable sensitive data about Americans to a foreign adversary, or to an entity controlled by a foreign adversary. The FTC’s notice identifies China, Russia, Iran, and North Korea among the countries covered by the law. The law’s sensitive-data categories include health, financial, genetic, biometric, geolocation, and sexual-behavior information. It also covers login credentials and government-issued identifiers such as Social Security, passport, and driver’s-license numbers. The important point is that the restriction is about access and transfer, not merely a traditional “data sale.” A broker can create risk through licensing, a data product, an API, an insight dashboard, or another arrangement that gives a recipient access to the information. Why the letters matter A warning letter is not the same thing as a final enforcement order. The FTC did not announce that all 13 recipients had violated PADFAA. Instead, the letters tell recipients to review their practices and make sure their products are not crossing the law’s line. That distinction matters for accuracy, but it should not make the warning seem toothless. The FTC said violations may lead to an enforcement action and civil penalties of up to $53,088 per violation. The agency is also making clear that a broker’s description of a product does not settle whether the underlying data is sensitive. A product marketed as an audience segment, a risk score, or an “insight” can still expose protected information if a buyer can use it to identify or target people. The data-broker problem is larger than one transfer Data brokers rarely hold just one clean field. They combine public records, commercial data, device identifiers, location signals, purchase histories, and inferred traits. A single field can look harmless in isolation while becoming sensitive when joined with other fields. That is why “we do not sell raw medical records” is not a complete privacy answer. A broker may still sell a score that predicts health status, a location history that reveals visits to a clinic, or a group membership that exposes a person to targeting or retaliation. PADFAA’s focus on foreign-adversary access adds a national-security lens to a familiar consumer-privacy problem. The same data infrastructure used for advertising can also become a channel for intelligence collection, influence operations, or targeted harassment. What people can do Individuals cannot audit every broker behind an advertising profile, but they can reduce the amount of data available for resale: Turn off unnecessary location access and reset advertising identifiers where your devices allow it.
Treat people-search sites and broker opt-outs as an ongoing task; deletion is not always permanent.
Use a separate email address for data-hungry services and avoid reusing phone numbers when an alternative exists.
Review account security and revoke old app connections, especially for services that expose contacts or location.
Ask companies what categories of information they share, not only whether they “sell personal data.” The FTC’s warning is a reminder that privacy risk is not limited to a dramatic breach. A data product can quietly turn a personal fact into a searchable category, and a searchable category can become a security problem when the wrong buyer gets access. The question is not only who collected the data. It is who can query it, infer from it, and receive the answer.