O2.13.2Downstream data-broker traceabilitydesignresearch

Data brokers make final data users difficult to trace

Aliases: data-broker chain traceability · final data user · downstream recipient lineage

What it is

Downstream data-broker traceability follows data beyond a direct recipient as it is resold, licensed, joined, or used in later decisions. A broker can aggregate sources and derive attributes, leaving the original provider aware only of the first transfer while people experience later marketing, scoring, or targeting.

Why it happens

Each redistribution can change dataset name, identifier, and contractual role, while records enter statistical or profile products. A linear “we to partner” disclosure cannot represent branching, merging, and derivation. Stable provenance, transfer permissions, downstream registers, and return duties turn the opaque chain into an auditable lineage graph.

Studying it

Start with authorized synthetic or marked records and build an expected graph across direct recipients, subprocessors, resellers, and final uses. Confirm edges through contract schedules, recipient returns, catalogs, export, or correction receipts, recording untraceable paths, out-of-scope derivation, and provenance breaks. Seeding identifiable fake data among real people risks contamination and harm; prefer closed synthetic environments and authorized records.

Where it stops holding

Aggregated, robustly deidentified data may no longer map to one person, but deidentification requires testing against linkage capability and external data rather than a pipeline label. Trade secrets may limit product detail without hiding recipient type, data scope, and final purpose. Mark an unknown edge as a gap instead of making every edge vague with “may.”

Applying it

  • Assign stable provenance and license identifiers, recording onward transfer, joining, derivation, and allowed final uses.
  • Require direct recipients to maintain subrecipient and derived-product registers and return auditable deletion, correction, restriction, and termination results.
  • Show known paths, provenance uncertainty, and last confirmation, making each downstream node queryable or challengeable.
  • Exercise transfer, merge, correction, and deletion in closed synthetic records; queue every unconfirmed final-use edge as a gap, not a disclosure.

Related

  • Same group: O2.13.1 Named third-party disclosure · O2.13.3 Dynamic disclosure updates · O2.13.4 Sharing clauses in bundled terms
  • Adjacent: O1.07.5 Propagation of deletion to downstream recipients · O1.08 Contextual integrity
  • Search terms: data broker traceability · downstream recipient lineage · data provenance chain

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/O2.13.2