Investors accumulate an enormous amount of personal information about people who never chose to give it to them. Names, addresses, phone numbers, financial circumstances, family situations and recorded conversations.
Most of that arrives through skip tracing, purchased lists and public records, and very few investors have thought about what obligations come with holding it.
Background only. Privacy obligations are expanding and thresholds differ by state. Check whether the statutes in your jurisdiction reach a business of your size.
What You Are Actually Holding
Worth cataloging, because the volume surprises people.
Contact details obtained through skip tracing. Purchased list data with demographic and financial attributes. Property and ownership records. Notes about why someone is selling, which frequently means a death, a divorce, an illness or a financial difficulty. Recorded calls. Photographs of the inside of people's homes. Occasionally financial documents.
An active investor holds this on thousands of people, most of whom have never contacted them and do not know the file exists.
That is not inherently improper. It does mean the casual attitude most investors take to storage and access is out of step with what they actually have.
The Legal Landscape, in Outline
Fragmented, developing quickly, and not something to assume you are outside of.
Several states have enacted comprehensive consumer privacy statutes, with more following. These typically give residents rights over data held about them, including rights to know what is held, to have it deleted, and to opt out of certain uses. They also typically apply above thresholds based on revenue or the volume of records processed.
Investors frequently assume they are too small to be covered. That may be right and it is worth checking rather than assuming, particularly for anyone processing large volumes of records, since some thresholds are based on record counts rather than revenue.
Separately, rules governing consumer reports can reach certain uses of certain data, and the rules on how you may contact people are a distinct regime again, per calling and texting rules.
The safe operating assumption is that this is tightening rather than loosening, and that practices built on the current absence of obligation may not age well.
Skip-Traced Data Specifically
The largest source of personal information in most investor businesses, and the least examined.
Skip tracing returns contact information the person did not give you. That has two consequences worth holding onto.
The first is that it is not consent for contact purposes. A phone number appearing in a skip trace result is not permission to call or text it, and treating it as such is the most common compliance error in this business.
The second is accuracy. Skip trace results are probabilistic, and a meaningful share are wrong. Contacting someone repeatedly about a property they do not own is both a nuisance to them and a signal of a process nobody is checking, covered in bulk skip tracing.
Practical steps: keep a record of where each contact detail came from, remove records that prove wrong rather than leaving them in the file, and honor removal requests permanently across every list you hold.
The Honest Question Worth Asking
Beyond legality, a test that clarifies most decisions here.
Would this person be comfortable if they knew exactly what you hold about them and how you obtained it.
For ordinary property research and contact details from public and commercial sources, most people would find that unremarkable, if slightly unsettling. For assembled profiles combining financial distress signals, family circumstances and behavioral inferences, many would not.
That discomfort is worth attending to, partly because it tracks where regulation is heading and partly because it tracks what recipients react badly to in marketing. Mail that reveals how much you know about someone's situation produces wariness rather than response, set out in talking to sellers in difficult circumstances.
Storage and Access
The practical half, and it is where most realistic risk sits for a small operation.
Most investor data lives in a CRM, several spreadsheets, an email inbox, a phone and a few platform accounts. Access is usually shared broadly because it is convenient.
What that means is that a departing assistant, a compromised password or a lost laptop exposes thousands of people's information, and you may have no way of knowing it happened.
The measures that address most of this are unremarkable: individual logins rather than shared passwords, permissions matched to the role rather than administrator access for everyone, two-factor authentication on anything holding records, encrypted storage, and an offboarding step that actually revokes access.
None of that is expensive. It is skipped because it is not urgent until it is, worked through in managing a remote team.
Sending Data Outside the Business
Where investors create exposure without noticing.
A list shared with a mail house. Records handed to a virtual assistant in another country. A database uploaded to a new tool for enrichment. A spreadsheet emailed to a partner.
Each of those is a transfer of personal information to a third party, and each deserves a moment's thought about what happens to it there. Whether it is retained, whether it trains anything, whether it ends up in a pool sold onward, per AI for data enrichment.
The question worth asking any vendor is direct: what happens to the records I upload, are they retained, and are they used for anything beyond my request. Vendors doing something real answer precisely, and vague answers are themselves informative.
Retention, and Why Keeping Everything Is Not Free
The default is to keep everything forever, because storage is cheap.
The cost is not storage. It is that everything you hold is something you are responsible for, something that can be exposed, and something a future obligation may attach to.
A defensible retention approach: keep transaction records for as long as your legal and tax obligations require and then some, which is a long time. Keep active lead records while there is a plausible relationship. Delete records for people who asked not to be contacted, other than the minimum needed to honor the request. Delete call recordings on a schedule rather than never.
Write the schedule down and actually run it. A policy nobody executes provides no benefit and documents that you knew what you should have been doing.
What to Do When Someone Asks
It will happen. Someone contacts you asking how you got their number, what you hold, or demanding deletion.
The instinct is to be defensive. A straightforward answer works better: where the information came from, what you hold, and confirmation that you have removed them.
Then actually remove them, everywhere, including the list you will pull again next quarter. The most common failure is removing someone from an active campaign and then re-adding them from the source data three months later, which converts a resolved complaint into an escalated one.
Maintain a permanent suppression list that survives every new data pull. That single mechanism prevents most repeat-contact complaints, detailed in segmenting your list.
The Breach Question
Rarely considered by investors and worth ten minutes.
If your CRM is compromised, or a laptop with a lead database is stolen, you have lost personal information belonging to thousands of people. Most states have breach notification statutes, and the obligations they impose can apply regardless of the size of the business holding the data.
Those statutes typically require notifying affected individuals within a defined period, sometimes notifying a state authority, and sometimes providing specific information about what was exposed.
The practical implication is that you should know, in advance, who you would call. An attorney familiar with the requirement in your state, and your insurance broker, since some policies include cyber coverage that funds exactly this response.
The preventive measures are the ordinary ones already described. What the breach obligation adds is a reason to know what you hold and where, because the first question in any notification analysis is which records were affected, and an investor with data spread across five systems cannot answer it.
Where This Is Going
Worth planning for rather than reacting to.
The direction across jurisdictions is toward more rights for individuals over data held about them, lower thresholds for who is covered, and more scrutiny of data brokers and the businesses that buy from them.
An investor whose model depends on practices that only work while nobody has rights over the data is building on ground that is moving. One who keeps source records, honors removals properly, limits access and deletes on a schedule is largely doing what future obligations will require anyway.
That is the practical case for getting ahead of it: most of the work is the same work either way, and doing it now is considerably cheaper than retrofitting it later, which sits alongside the rest of investor compliance.