What happened
A New Jersey court has ordered radaris.com and more than a dozen related domain names transferred away from the Radaris group of data brokers and handed to Atlas Data Privacy Corp, a company that has filed roughly 150 suits against people-search sites under a New Jersey statute.
That statute, Daniel's Law, lets judges, law enforcement officers, prosecutors and other public officials have their personal information removed from commercial data brokers. It carries penalties of $1,000 per violation for companies that ignore removal requests. Atlas first sued Radaris in February 2024 and refiled in June 2025, widening the number of Radaris-linked sites accused of breaching the law.
On August 26 the judge found the defendants had been given repeated chances to appear and defend the claims and had not done so. The New Jersey court has transferred 14 domain names so far. Radaris.com now redirects to a notice describing the court-ordered transfer, and it no longer sells personal dossiers.
Radaris' attorney told KrebsOnSecurity that the company has moved to vacate the default judgment because the domain is not a legal entity, and intends to appeal on the basis that the transfer amounts to a forfeiture. Atlas says documents from the litigation show at least twenty-five people-search sites operated as one business, sharing mailboxes, bank and payment accounts and a single virtual office address.
Daniel's Law itself is under challenge. Roughly 70 of the Atlas suits were moved to federal court, where the data broker industry argues the statute is overly broad and breaches the First Amendment. The Third Circuit has not ruled, and the case is widely expected to reach the Supreme Court. At least 14 other states have passed similar laws, while West Virginia's version was ruled unconstitutional on its face by a federal district court in August 2025.
Why this is a GRC story
Privacy enforcement has spent a decade producing fines. This case produced a structural remedy: the asset itself changed hands, because the operators could not be pinned down. That is the part worth studying.
The failure here was accountability, not compliance paperwork. The pattern described in the litigation, a shifting set of corporate vehicles across several jurisdictions, privacy notices updated to match whichever entity was convenient, and a management structure that made it hard to say who was responsible, is a governance failure before it is a privacy failure. That arrangement has discouraged plaintiffs for years, because untangling it costs more than most are willing to spend.
For anyone running a privacy programme the practical question is simple: can you name the legal entity responsible for each set of personal data you hold, the person accountable for it, and the contract that permits the processing? If the answer requires research, an incident will find the gap before you do.
What to watch
Watch the motion to vacate the default judgment and any appeal. If the transfer survives, domain seizure becomes a remedy other plaintiffs will test.
Watch the Third Circuit's ruling on Daniel's Law. Its decision will shape whether copycat statutes in at least 14 other states hold up, or fall back into private litigation.
Watch whether Congress moves at all. State privacy laws generally exempt publicly available records, which is much of the raw material people-search sites rely on, so the federal gap is structural rather than incidental.
Attribution: Analysis based on KrebsOnSecurity's reporting and related public reporting. This article is original commentary, not a repost of the source material.
