September 7, 2026
Foreign Companies Are Quietly Rewriting Your Privacy Rights
A British conglomerate and an Irish credit bureau are spending millions to erase the privacy protections American states gave you. Thatβ¦

By mePrism Privacy
5 min read
- 1 A British conglomerate and an Irish credit bureau are spending millions to erase the privacy protections American states gave you. That should bother you regardless of your politics.
- 2 Meet the outsiders at the table
- 3 Why "foreign" actually matters here
- 4 The database that already feeds the government
- 5 What the SECURE Data Act would lock in
A British conglomerate and an Irish credit bureau are spending millions to erase the privacy protections American states gave you. That should bother you regardless of your politics.
Here is a question that ought to unsettle anyone, left or right: Should a company headquartered in London get to help decide what privacy rights you have in California?
Because that is, functionally, what is happening in Washington right now. A federal privacy bill called the SECURE Data Act β H.R. 8413 β is working its way through the House. It would override the strongest state privacy laws in the country and replace them with a weaker national standard. And some of the most aggressive lobbyists pushing that outcome are not American companies at all. They are foreign corporations whose entire business is buying and selling the personal lives of Americans, and who would very much like the rules governing that business to be as lax as possible.
This isn't a xenophobia argument. Foreign companies operate in America all the time, and that's fine. It's a sovereignty-and-conflict-of-interest argument, and it cuts to something basic about self-government: the people who write your laws should answer to you. When the loudest voices shaping a privacy statute belong to firms accountable to shareholders in London and Dublin rather than voters in Sacramento or Austin, something in that chain of accountability has broken.
Meet the outsiders at the table
Start with the two names most people have never heard but whose databases almost certainly contain a file on you.
The first is RELX, a British multinational headquartered in London and listed on the London Stock Exchange, where it's a FTSE 100 component, as its own corporate filings confirm. RELX owns LexisNexis, and its LexisNexis Risk Solutions arm is one of the most consequential data brokers on earth β a company that aggregates billions of records on individuals and sells access to that dossier.
The second is Experian, one of the three great credit-bureau giants, and a company the SECURE Data Act would directly govern. Despite its ubiquity in American financial life, Experian is headquartered in Dublin, Ireland, and trades as a FTSE 100 company on the London Stock Exchange, per the company's own investor materials. When you check your credit score, request a report, or find yourself denied a loan because of a number some algorithm assigned you, you are interacting with an Irish-domiciled corporation.
Both companies are among the most persistent lobbyists on U.S. privacy legislation. And their interest is not abstract. They are spending real money to shape an American statute that would strip American voters of privacy rights those voters currently hold under their own state laws.
Sit with the strangeness of that for a moment. A British analytics conglomerate and an Irish-domiciled credit bureau are lobbying the United States Congress to preempt β to legally override β the privacy protections that states like California passed for their own residents. The shareholders who profit, the headquarters that set strategy, the loyalties that ultimately govern these firms: none of them are located in the districts of the Americans whose data is the product.
Why "foreign" actually matters here
The instinctive objection is: so what? A data broker is a data broker; its passport doesn't change its incentives. Domestic brokers like TransUnion in Chicago and Equifax in Atlanta lobby toward the exact same weak-rules goal, shoulder to shoulder with their foreign counterparts. The coalition's loyalty, as the pattern makes plain, runs to the data β not to any country.
All true. But nationality matters for a specific, structural reason that has nothing to do with flags and everything to do with accountability.
When an American company lobbies to weaken American law, at least the feedback loop is intact. Its executives are Americans subject to the same laws. Its shareholders are disproportionately American. Its employees vote in American elections. There is a rough, imperfect alignment between the company's fate and the country's. You can boycott it, its workers can push back, its investors bear the reputational cost of what it enables at home.
A foreign corporation faces none of that domestic friction in the same way. RELX answers to a board and a shareholder base oriented around London and the interests of a global information-services empire. Experian's center of gravity is Dublin and the FTSE 100. Their obligation is to maximize returns from selling data about Americans β and if weaker American privacy law makes that data cheaper to collect and more profitable to sell, weaker law is simply good business. The Americans whose lives are catalogued in their databases are not their constituents, their neighbors, or their voters. They are inventory.
That is the conflict of interest in its purest form. The privacy of American citizens is being treated as an asset to be optimized by firms with no democratic tie to the citizens in question.
The database that already feeds the government
If you want to see where this leads, look at what LexisNexis already does with its American data trove.
LexisNexis Risk Solutions β the RELX subsidiary β holds a contract with Immigration and Customs Enforcement worth roughly $22 million, giving the agency access to billions of aggregated records on citizens and noncitizens alike, as documented in a University of Colorado Law Review analysis and years of reporting. RELX has repeatedly objected to proposed limits on third-party data sold for "public safety" purposes β which is a polished way of saying it would prefer the pipeline from broker to government stay open.
This is the data-broker loophole in miniature: the government buying from a commercial broker what the Fourth Amendment would otherwise require it to obtain with a warrant. And here, the broker on the selling end is a foreign-owned company. A British corporation is, in effect, a paid intermediary in the surveillance of Americans by their own government β and it is lobbying to keep the rules that enable it from getting any stricter.
Whatever your politics, that arrangement should give you pause. Immigration hawk or civil-libertarian, the underlying structure is the same: a foreign firm profiting from selling Americans' data to the state, while working to prevent Americans' elected representatives from constraining the practice.
What the SECURE Data Act would lock in
The reason this all matters now is that the SECURE Data Act would cement the outcome these firms want. Its two defining features are a sweeping preemption clause that overrides stronger state privacy laws, and the removal of your private right of action β meaning if a company misuses your data, you cannot sue; enforcement runs only through the FTC and state attorneys general.
The Electronic Privacy Information Center testified that the bill is "weaker than the weakest state law." The California Privacy Protection Agency warned it would effectively kill California's Delete Act and its DROP platform β the tools that let you, or an authorized agent, delete your data from brokers at scale. Those are precisely the mechanisms that let ordinary people push back against exactly the brokers doing the lobbying. Erase them, and the balance of power tilts decisively toward the data industry β foreign and domestic alike.
The bill's marketing says it fixes a chaotic "patchwork" of state laws. But the practical effect is to replace strong, enforceable, locally accountable protections with a weaker federal ceiling β one that firms answering to London and Dublin have every incentive to keep low.
What you can actually do
Two things are worth holding onto.
First, the bill is not a done deal. It has zero Democratic cosponsors, and the same preemption and right-to-sue fights that killed comprehensive privacy legislation in 2022 and 2024 are alive again. Legislative trackers rate its odds of passage very low. Contested, not inevitable β which means public attention still counts. If you care about this, the offices of your representatives are the correct venue, and "don't let foreign data brokers write our privacy law" is a message that lands across the political spectrum.
Second, your exposure doesn't have to wait on Congress. Use your state's deletion and opt-out rights while you still have them β these are exactly what preemption would erase. Reduce the number of brokers holding your profile, and treat it as ongoing maintenance, because brokers repopulate your data months after you opt out. The smaller your footprint, the less there is for anyone to buy, sell, or hand to the government β regardless of which flag flies over the company doing it.
The privacy of American citizens should not be an asset auctioned to the highest foreign bidder through the machinery of a Congress those citizens elected to protect them. That it currently is β quietly, legally, and at scale β is the part worth getting angry about.