As reported by Krebs on Security, the data broker Radaris has been forced to surrender radaris.com and over a dozen associated domains after a judge ruled against the company in a lawsuit brought under New Jersey's Daniel's Law — a statute designed to protect law enforcement personnel, government employees, judges, and their families from having personal information published by commercial data brokers.

Key Insight: Daniel's Law provides for $1,000 per violation — a figure that scales rapidly when a broker publishes information on thousands of protected individuals.

This case is far more than a single data broker losing its web properties. It represents one of the first instances where a privacy law has been enforced with a remedy that actually cripples the offending company's ability to operate. Fines are one thing — domain forfeiture is existential. That distinction matters enormously for how the data broker industry will respond going forward.

Why Domain Transfer Changes the Calculus

Most privacy enforcement actions end in settlements, fines, or consent decrees that data brokers treat as a cost of doing business. Daniel's Law provides for $1,000 per violation — a figure that scales rapidly when a broker publishes information on thousands of protected individuals. But the real deterrent in this case is the structural remedy: the court transferred the domains themselves to the plaintiffs. Radaris didn't just lose money. It lost its primary distribution channel.

When a legal framework can strip a data broker of its infrastructure — not just its margin — the risk model fundamentally changes.

For an industry built on aggregating publicly available records and reselling access through people-search websites, domain forfeiture is effectively a corporate death sentence. It sets a precedent that other plaintiffs and state regulators will inevitably study and replicate.

The Evasion Playbook and Its Limits

Krebs's reporting highlights a familiar pattern of corporate obfuscation: fictitious executives, last-minute court appearances, shifting ownership claims, and threats of defamation suits against journalists. These tactics are not unique to Radaris — they are common across the people-search ecosystem, where operators frequently hide behind shell entities, nominee directors, and offshore structures.

What's notable here is that the evasion playbook ultimately failed. Atlas Data Privacy Corp refiled, expanded the scope, and persisted through procedural delays. The court saw through the stonewalling. This outcome should give pause to other data brokers that have treated removal requests and legal action as nuisances to be outlasted rather than obligations to be met.

Broader Implications for the Data Supply Chain

Broader Implications for the Data Supply Chain
State-level privacy laws are gaining enforcement teeth. Daniel's Law is New Jersey-specific, but similar protections for law enforcement and public officials exist or are being considered in other states. California's CCPA/CPRA, Illinois's BIPA, and other frameworks are also maturing in enforcement.
Third-party litigation is emerging as a real threat. Atlas is not a regulator — it's a private company enforcing statutory rights. This model could proliferate, creating a class of privacy enforcement entities analogous to patent assertion companies but focused on data protection statutes.
Enterprise data sourcing faces new risk. Companies that purchase data from brokers like Radaris — for marketing, background checks, fraud prevention, or analytics — may find themselves holding data that was collected or published in violation of law. The downstream liability is uncharted but concerning.
Reputation and operational continuity are now legal weapons. Domain forfeiture demonstrates that courts are willing to impose remedies that destroy brand value and customer access, not just financial penalties.

Shield53 Recommendations

For Enterprises That Consume Brokered Data

  • Audit your data vendor inventory. Identify every third-party data broker or people-search provider your organization uses, directly or indirectly through platforms and APIs.
  • Contractually require vendors to certify compliance with Daniel's Law, CCPA, and other applicable state privacy statutes. Include indemnification for statutory violations.
  • Implement a data provenance framework so you can trace the origin of personal data records and remove suspect batches quickly if a vendor faces enforcement.
  • Establish a takedown and deletion response process. If a data broker in your supply chain loses its domains or faces legal action, you need to know within hours, not weeks.

For Organizations with Protected Personnel

  • Proactively submit removal requests under Daniel's Law and equivalent statutes for all qualifying employees — not just senior leadership.
  • Monitor people-search sites quarterly for residual or republished records. Removal is not always permanent; data resurfaces through syndication networks.
  • Document all requests and responses. Incomplete or ignored requests are the foundation for statutory claims.

For CISOs and Risk Leaders

  • Treat data broker compliance as a third-party risk management issue, not just a privacy compliance issue. Add it to vendor risk assessments.
  • Brief executive leadership and legal counsel on the Radaris precedent. The combination of per-violation fines and structural remedies materially changes the risk landscape.
  • Watch for copycat litigation. The Atlas model — private enforcement of data privacy statutes — is likely to expand to other states and other protected classes.

The Radaris case demonstrates that privacy laws are only as strong as their enforcement mechanisms. When courts are willing to transfer domains and disrupt operations — not just levy fines — the calculus for the entire data broker industry shifts. Organizations that depend on brokered data should treat this as a wake-up call to understand exactly where their data comes from and what happens when the source dries up.