Who Owns Your Cannabis Data? The Broker Race Heats Up
Photo by Budding . via Unsplash.
Buy a pre-roll at a licensed dispensary in Denver or Detroit and you're not just handing over cash for weed. You're handing over your driver's license to a scanner, your payment details to a processor, your product preferences to a point-of-sale system, and in medical-market states, sometimes the qualifying condition that got you a card in the first place. All of it flows into a state-mandated seed-to-sale tracking system that was built to stop diversion, not to build a customer profile. But somewhere between the scanner and the state database, that data picked up a second life as a commercial asset, and most of the people generating it have no idea where it ends up.
The federal backdrop just moved in a way that matters here. Executive Order 14370, signed December 18, 2025, directed the Department of Justice to expedite marijuana rescheduling, and on April 23-24, 2026, Acting Attorney General Todd Blanche and the DEA issued an order moving FDA-approved and state-licensed medical marijuana into Schedule III immediately. Recreational marijuana didn't move. It's still Schedule I. That split -- medical cannabis inching toward the regulatory treatment of a controlled pharmaceutical, adult-use cannabis staying in the same federal bucket as heroin -- is about to reshape who can legally touch, store, and monetize cannabis consumer data, and how.
Meanwhile, the commercial infrastructure for mining that data is already mature. Headset says it draws on the largest dataset in the industry, pulling consumer behavior signals from more than 3,000 connected retailers. BDSA runs a platform called GreenEdge that segments the buying public into Consumers, Acceptors, and Rejecters -- straight out of the consumer packaged goods playbook, applied to a plant the federal government still classifies as having no accepted medical use. And the incentive to keep collecting is concrete: Flowhub's own numbers show loyalty program members spend 3.5 times more annually than one-time buyers. This piece walks through who holds the data today, how the Schedule I/Schedule III split is about to collide with a wave of new state privacy law, and where the real business opportunity -- and the real liability -- sits over the next three to seven years.
The Data Pipeline Nobody Asked to Opt Into

Photo by Proxyclick Visitor Management System via Unsplash.
Every legal cannabis purchase leaves a paper trail that was never designed with the shopper in mind. State-mandated seed-to-sale systems -- METRC is the dominant one, BioTrack runs in a handful of states -- exist to track a plant from clone to sale so regulators can prove nothing walked out the back door into the illicit market. To make that system work, retailers scan a government ID, log the transaction, and in medical markets often record the patient's qualifying condition alongside the SKU. That's the compliance layer, and it's mandatory. Nobody at the counter is asking permission to collect it in the commercial sense, because legally they don't have to -- it's the price of a legal transaction.What happened next is the part regulators didn't fully anticipate. That compliance data turned out to be a goldmine of consumer behavior, and multi-state operators and third-party analytics firms started mining it. Headset built what it calls the largest dataset in the industry by aggregating purchase behavior across more than 3,000 connected retailers, giving brands and investors granular visibility into what's selling, to whom, and how often. BDSA's GreenEdge platform goes a step further, sorting the entire cannabis-buying population into three buckets -- Consumers, Acceptors, and Rejecters -- a segmentation model lifted directly from decades of Procter & Gamble-style CPG market research. It's a sensible business tool. It's also a strange thing to apply to a substance that's still a Schedule I narcotic at the federal level, where the government's official position is that there's no legitimate consumer market to segment in the first place.
The asymmetry is the real story here. A shopper who buys toothpaste at Target has a reasonably clear sense that a loyalty card feeds a marketing database. A cannabis shopper scanning an ID for a purchase mandated by state diversion-control law has almost no visibility into whether that same data point is being aggregated, sold, or licensed to a third-party analytics firm downstream. Retailers disclose this in privacy policies that essentially nobody reads at the counter, and the seed-to-sale vendors and analytics firms sit one or two steps removed from the consumer entirely, with no direct relationship or consent conversation. That gap between what the data was collected for and what it's now used for is exactly the kind of gap regulators tend to notice eventually -- just usually after the market built around it.
Two Schedules, One Industry: The Legal Split Shaping the Data Market

Photo by Michael D Beckwith via Pexels.
The regulatory ground shifted meaningfully in late 2025 and early 2026, but it shifted in a way that splits the industry rather than unifying it. Executive Order 14370, signed December 18, 2025, told the DOJ to move faster on marijuana rescheduling after years of delay. That produced results: on April 23-24, 2026, Acting Attorney General Todd Blanche and the DEA issued an order placing FDA-approved and state-licensed medical marijuana into Schedule III effective immediately. That's a real, documented regulatory event, not a projection. What it did not do is touch recreational marijuana, which remains Schedule I -- the same category as heroin, with no federally recognized medical use.There's a second, unresolved process running in parallel: a broader DEA hearing on full Schedule III rescheduling for marijuana generally is set to begin June 29, 2026, with intent-to-participate notices due by May 28, 2026. That hearing could extend Schedule III treatment across the board, or it could stall the way similar administrative rescheduling pushes have stalled before. As of now it's a live proceeding with an uncertain outcome, and treating its result as settled would be getting ahead of the facts.
The practical effect of where things stand today is a two-tier data environment. Medical cannabis data, now sitting under Schedule III, has a plausible path toward HIPAA-adjacent treatment and eventual interstate legitimacy, because Schedule III substances can move through channels ordinary pharmaceuticals use. Adult-use data -- which represents the majority of dispensary transactions in most mature markets like Colorado, California, and Illinois -- stays governed almost entirely by whatever patchwork of state law happens to apply, with no federal floor underneath it.
History offers a useful, imperfect guide here. After Prohibition ended in 1933, alcohol didn't get one unified federal-state regulatory regime -- it got the three-tier system, with producers, distributors, and retailers kept legally separate, and states retaining wide latitude that persists nearly a century later. If cannabis follows that pattern, the medical/recreational data split could calcify into a semi-permanent feature of the industry rather than a temporary wrinkle. The counter-case is real too: if the June 2026 hearing produces full Schedule III movement for recreational marijuana, or if Congress finally passes something like the MORE Act after years of failed attempts, the two-tier system could collapse far faster than the eighty-year alcohol timeline suggests. Nobody should bet the business plan on either outcome yet.
The Privacy Backlash Is Already Here

Photo by FlyD via Unsplash.
While the federal picture inches forward, states have stopped waiting. Nearly 20 states now have comprehensive consumer privacy statutes on the books, and several explicitly classify health-related cannabis data -- purchase history tied to a medical card, qualifying condition records -- as sensitive personal information requiring heightened, opt-in consent rather than the default opt-out model that governs ordinary retail data. New Jersey's Data Privacy Act, which took effect January 15, 2025, is a useful example: it added specific consumer privacy duties for age-gated cannabis ecommerce, ID-scanning practices, and delivery services, treating cannabis transactions as a distinct risk category rather than folding them into generic retail rules.The urgency behind these laws isn't theoretical. In November 2024, STIIIZY disclosed a breach that exposed personal information belonging to roughly 380,000 customers, traced back to a compromised point-of-sale processing vendor rather than STIIIZY's own systems directly -- including medical cannabis card details and full transaction histories. Then in 2025, the Ohio Marijuana Card breach exposed close to one million patient records, including Social Security numbers, which triggered federal class-action lawsuits and drew investigations from Ohio's Division of Cannabis Control and the State Medical Board. These aren't edge cases; they're the two largest and most concrete signals yet that cannabis's data infrastructure carries the same breach risk profile as any other health-adjacent industry, minus the decades of hardened HIPAA enforcement that healthcare has already been through.
That trajectory looks familiar. The healthcare sector went through its own version of this in the early 2010s, culminating in the 2015 Anthem breach that exposed roughly 78.8 million records and helped push HIPAA enforcement into a much more aggressive posture over the following years. Cannabis is tracing a similar arc, just earlier and faster, without the benefit of an established federal health-privacy statute to fall back on. The reasoned projection here is that the next three to five years bring more state-level cannabis-specific privacy amendments, most of them modeled on existing health-data carve-outs rather than invented from scratch. What's much less likely in that window is a comprehensive federal cannabis privacy law -- that kind of unifying statute typically waits until the underlying scheduling question is settled, and as Section 2 laid out, that question is still open.
Why Operators Keep Collecting Anyway: The Loyalty Math

Flowhub data shows loyalty members far outspend and out-engage one-time buyers, spending 3.5x more annually, visiting 1.4x more often, and being 5x more likely to try new products.
Operators aren't collecting all this data recklessly -- they're doing it because the math is genuinely compelling. Flowhub's data shows loyalty program members spend 3.5 times more annually than one-time buyers, visit dispensaries 40% more often, and are five times more likely to try a new product when it's recommended to them. Those aren't soft engagement metrics; they translate directly into revenue per square foot in a retail category where margins have been squeezed hard by state tax structures and oversupply in mature markets like Oregon and Michigan.Consumer survey data from 2026 backs up why operators keep leaning in. Eighty-six percent of shoppers say they'd return to a dispensary that offers personalized recommendations. Seventy-one percent call digital tools -- online menus, in-store kiosks -- essential to the shopping experience rather than a nice extra. Seventy-five percent want one-click reordering, and 67% now consider delivery a must-have rather than a bonus service. Every one of those preferences requires collecting and retaining more customer data, not less: you can't personalize a recommendation without a purchase history to draw on, and you can't offer one-click reorder without storing payment and order details indefinitely.
That's the tension operators now have to manage out loud, not just quietly absorb. The exact data that makes loyalty programs profitable -- purchase history, product preferences, sometimes health-adjacent details in medical markets -- is precisely the data category that new state privacy statutes are targeting for heightened consent, and precisely the category that showed up in the STIIIZY and Ohio Marijuana Card breaches. An operator maximizing loyalty revenue and an operator minimizing breach exposure are, in practice, often pulling on the same lever from opposite ends.
Smaller, single-state operators generally don't have the capital or technical staff to build compliant data infrastructure in-house, so they're increasingly licensing analytics and CRM platforms from third parties rather than owning the stack themselves. That outsourcing decision is exactly the opening that dedicated data brokers and analytics vendors are stepping into -- and it's worth looking at, concretely, who's actually positioned to own that role.
Who's Actually Positioned to Own This Market

Photo by Luke Chesser via Unsplash.
Right now, breadth of retailer integration is the moat, and Headset and BDSA hold it. Both have spent years wiring themselves into point-of-sale systems across thousands of retailers, which means any new entrant trying to compete on data scope alone has to replicate integration work that took incumbents years to build -- a real structural barrier, not just a head start.But the POS vendors sitting even closer to the actual transaction are starting to squeeze that position from the other direction. Flowhub and Dutchie process the sale itself, and both have been layering their own analytics and loyalty tools directly on top of that transaction data rather than leaving that value on the table for a third party to harvest. Over a five-to-seven-year horizon, that's a real disintermediation threat to pure-play data brokers: if the company already running the register also owns the loyalty and analytics layer natively, the retailer has less reason to pay a separate vendor for insights it already has access to.
The Schedule III shift for medical cannabis opens a genuinely different door. Traditional healthcare data intermediaries -- the pharmacy benefit managers and health-data clearinghouses that already move prescription and claims data at scale -- have infrastructure built for exactly the compliance regime medical cannabis is now inching toward. That's a niche the general-purpose cannabis analytics firms haven't had to compete in, because until April 2026 there was no federal pathway for medical cannabis data to look anything like ordinary pharmaceutical data. Watch for pharmacy-adjacent players testing the waters here before they commit fully -- the regulatory ground is still shifting under the June 2026 hearing.
Consolidation is the other predictable pattern. As MSOs expand across state lines, expect the larger platforms to acquire smaller regional analytics shops rather than compete with them indefinitely -- a rollup pattern that echoes how ad-tech consolidated in the 2010s, when Acxiom- and Epsilon-style firms absorbed smaller regional data brokers to build national profiles. The clearest opening for a genuinely new entrant isn't better analytics at all -- it's privacy-compliance-as-a-service: a layer that sits on top of existing seed-to-sale and analytics infrastructure and actively reconciles state privacy statute obligations with mandatory diversion-tracking reporting. None of the current major players fully own that yet, and given the STIIIZY and Ohio breaches, someone's going to need to.
Strip away the cannabis-specific details and this is a familiar story. Ad-tech took web browsing behavior collected for one purpose and turned it into a targeting industry, then got hit with GDPR and, eventually, a wave of US state privacy laws. Healthcare took claims and treatment data collected for billing and turned it into research and marketing gold, then got hit with tightened HIPAA enforcement after breaches like Anthem's in 2015. Cannabis is running the same play -- compliance data collected for diversion control, repurposed into commercial consumer intelligence by firms like Headset and BDSA -- and it's already catching the same kind of regulatory attention, just years earlier in the cycle. STIIIZY and Ohio Marijuana Card weren't outliers. They were the industry's Anthem moment, arriving faster because cannabis skipped straight from illicit market to data-rich legal retail without the intermediate decades other industries had to build up defenses.
The mid-term opportunity isn't a smarter recommendation engine. Operators already know loyalty data is worth 3.5 times the spend of a one-time buyer -- that math isn't going to change anyone's mind. What's genuinely underbuilt is the trust layer sitting underneath it: transparent, plain-language consent at the point of ID scan, breach-resistant architecture that doesn't leave Social Security numbers sitting in a vendor's unencrypted database, and a compliance framework that treats a state privacy statute and a seed-to-sale reporting mandate as two obligations to satisfy simultaneously, not two competing headaches. Whoever builds that well gets to keep the loyalty economics without becoming next year's class-action headline.
Keep an eye on June 29, 2026. That's when the DEA's broader Schedule III hearing opens, and its outcome will decide whether medical and recreational cannabis data keep drifting into separate regulatory tracks -- the alcohol three-tier scenario -- or eventually get folded back into one framework the way healthcare data operates today. Until that's resolved, anyone building a data business in this space is building on ground that's still moving underneath them, and the smartest operators are the ones designing for both outcomes rather than betting the business on one.



