Data Broker Radaris Loses Domains After New Jersey Privacy Law Judgment
What Happened – A New Jersey court ordered the transfer of radaris.com and more than a dozen related domains to plaintiffs after finding the data‑broker violated the state’s “Daniel’s Law,” which mandates removal of personal information about law‑enforcement officials and imposes $1,000 fines per violation.
Why It Matters for Trust & Control Assurance
- Demonstrates the risk of inadequate data‑subject‑request processes – a core control that continuous‑monitoring programs must evidence.
- Highlights the need for auditable, repeatable privacy‑governance workflows that can be inspected during regulator or third‑party reviews.
- Shows how a single control gap (failure to honor removal requests) can trigger legal loss of critical assets (domains) and reputational damage.
Who Is Affected – Online data‑broker and people‑search services, SaaS platforms aggregating public records, and any organization that publishes personal data without robust removal‑request handling.
Recommended Actions
- Map your privacy‑request handling to the control objective “processes to receive, verify, and act on data‑subject removal requests.”
- Deploy continuous evidence collection (e.g., ticket logs, request‑to‑deletion timestamps) to demonstrate compliance during audits.
- Review domain‑ownership and registration records to ensure they are protected against forced transfers. Source: Krebs on Security
Technical Notes
- No technical exploit; the issue stems from procedural non‑compliance with New Jersey’s Daniel’s Law.
- The court’s order transferred ownership of radaris.com and related domains to the plaintiff, Atlas Data Privacy Corp. Source: same