As reported by Krebs on Security, the data broker Radaris has been forced to surrender radaris.com and over a dozen associated domains after a judge ruled against the company in a lawsuit brought under New Jersey's Daniel's Law — a statute designed to protect law enforcement personnel, government employees, judges, and their families from having personal information published by commercial data brokers.
This case is far more than a single data broker losing its web properties. It represents one of the first instances where a privacy law has been enforced with a remedy that actually cripples the offending company's ability to operate. Fines are one thing — domain forfeiture is existential. That distinction matters enormously for how the data broker industry will respond going forward.
Why Domain Transfer Changes the Calculus
Most privacy enforcement actions end in settlements, fines, or consent decrees that data brokers treat as a cost of doing business. Daniel's Law provides for $1,000 per violation — a figure that scales rapidly when a broker publishes information on thousands of protected individuals. But the real deterrent in this case is the structural remedy: the court transferred the domains themselves to the plaintiffs. Radaris didn't just lose money. It lost its primary distribution channel.
When a legal framework can strip a data broker of its infrastructure — not just its margin — the risk model fundamentally changes.
For an industry built on aggregating publicly available records and reselling access through people-search websites, domain forfeiture is effectively a corporate death sentence. It sets a precedent that other plaintiffs and state regulators will inevitably study and replicate.
The Evasion Playbook and Its Limits
Krebs's reporting highlights a familiar pattern of corporate obfuscation: fictitious executives, last-minute court appearances, shifting ownership claims, and threats of defamation suits against journalists. These tactics are not unique to Radaris — they are common across the people-search ecosystem, where operators frequently hide behind shell entities, nominee directors, and offshore structures.
What's notable here is that the evasion playbook ultimately failed. Atlas Data Privacy Corp refiled, expanded the scope, and persisted through procedural delays. The court saw through the stonewalling. This outcome should give pause to other data brokers that have treated removal requests and legal action as nuisances to be outlasted rather than obligations to be met.
Broader Implications for the Data Supply Chain
Shield53 Recommendations
For Enterprises That Consume Brokered Data
- Audit your data vendor inventory. Identify every third-party data broker or people-search provider your organization uses, directly or indirectly through platforms and APIs.
- Contractually require vendors to certify compliance with Daniel's Law, CCPA, and other applicable state privacy statutes. Include indemnification for statutory violations.
- Implement a data provenance framework so you can trace the origin of personal data records and remove suspect batches quickly if a vendor faces enforcement.
- Establish a takedown and deletion response process. If a data broker in your supply chain loses its domains or faces legal action, you need to know within hours, not weeks.
For Organizations with Protected Personnel
- Proactively submit removal requests under Daniel's Law and equivalent statutes for all qualifying employees — not just senior leadership.
- Monitor people-search sites quarterly for residual or republished records. Removal is not always permanent; data resurfaces through syndication networks.
- Document all requests and responses. Incomplete or ignored requests are the foundation for statutory claims.
For CISOs and Risk Leaders
- Treat data broker compliance as a third-party risk management issue, not just a privacy compliance issue. Add it to vendor risk assessments.
- Brief executive leadership and legal counsel on the Radaris precedent. The combination of per-violation fines and structural remedies materially changes the risk landscape.
- Watch for copycat litigation. The Atlas model — private enforcement of data privacy statutes — is likely to expand to other states and other protected classes.
The Radaris case demonstrates that privacy laws are only as strong as their enforcement mechanisms. When courts are willing to transfer domains and disrupt operations — not just levy fines — the calculus for the entire data broker industry shifts. Organizations that depend on brokered data should treat this as a wake-up call to understand exactly where their data comes from and what happens when the source dries up.