A marketing operations director is reviewing the company's customer acquisition strategy.
Everything looks familiar.
Website analytics. CRM data. Advertising platforms. Lead enrichment. Location intelligence. Identity resolution.
Then a privacy attorney asks a simple question:
"Have we determined whether our enrichment vendor qualifies as a California data broker?"
Silence.
Another question follows.
"If they qualify… are we sure we don't?"
What started as a routine vendor review suddenly becomes a governance problem.
Many Organizations Think They Purchase Intelligence. Some May Actually Be Data Brokers.
The same data ecosystem that makes modern marketing more effective can also move an organization into an entirely different regulatory category.
Many organizations think they simply purchase marketing intelligence. Some may actually be operating within California's data broker framework — and the definition is broader, and the enforcement more imminent, than most have assessed.
The Law, the Deadline, and the Definition Most Organizations Have Not Assessed
California's Delete Act (SB 362) created a centralized Delete Request and Opt-Out Platform — DROP — that allows California residents to submit a single deletion request to every registered data broker simultaneously. The platform opened January 1, 2026. As of April 2026, more than 260,000 Californians had already submitted requests, queued and waiting for processing. Starting August 1, 2026, registered data brokers — currently more than 600 companies — must access DROP at least once every 45 days, process deletion requests within 90 days of retrieval, delete all associated personal information including derived inferences, and report request status back to the California Privacy Protection Agency. The penalty for non-compliance is $200 per request per day with no cure period.
California Privacy Protection Agency General Counsel Phil Laird stated publicly at the 2026 IAPP Global Summit that one missed 45-day cycle carries $1.5 billion in theoretical liability for a single large-scale data broker — a ceiling, not a forecast, but the ceiling the law permits. CalPrivacy has already demonstrated enforcement willingness: Honda was fined $632,500 in a CPPA enforcement action, Accurate Append was fined $55,400 in July 2025, and National Public Data was fined $46,000 in May 2025 — all for registration failures, before the deletion processing deadline even arrived.
The definition of "data broker" is the governance problem most organizations have not formally assessed. California law defines a data broker as a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship. Recent CPPA regulations tightened that definition significantly: a business does not have a direct relationship simply because it collects data directly from a consumer — the consumer must intend to interact with that business. Direct relationships also expire three years after a consumer's last interaction. And selling data is not limited to financial transactions — sharing data in exchange for analytics, advertising services, or other valuable consideration qualifies. Many organizations using enrichment, identity resolution, audience activation, or data licensing services have not formally assessed where they sit in this framework.
5-Question Compliance Check
Do You Know Whether You Are a Data Broker?
Does your organization collect or sell personal information that it did not collect directly from consumers — or that consumers did not intentionally provide to you for your own products or services?
Do you purchase, license, enrich, or receive consumer data from third parties, and does any of that data leave your organization — in any form, for any consideration including analytics or advertising services?
Could your marketing operations, data products, or vendor relationships meet California's definition of a data broker under the CPPA's expanded "direct relationship" regulations, including the three-year expiration rule?
Have you formally assessed whether your enrichment vendors, identity resolution providers, and data partners are registered California data brokers — and confirmed whether their obligations flow downstream to you?
If DROP deletion requests arrived tomorrow, could your organization actually honor them across internal systems, data vendors, and service providers within the 90-day processing deadline?
Who This Affects and How
Marketing and Data Teams
The data ecosystem your team uses for audience targeting, enrichment, and identity resolution may include registered data brokers — and if your organization processes or resells that data in ways that lack a direct consumer relationship, you may have registration and deletion processing obligations you have not assessed. The question is not whether you think of yourself as a data broker. The question is whether California's definition applies to what you actually do.
Legal and Privacy Teams
The CPPA's expanded "direct relationship" definition is the governance question most organizations have not formally answered. A company can have a direct relationship with a consumer in one context and still qualify as a data broker for other datasets it acquires indirectly and sells. Your legal assessment needs to address each data flow independently — not the organization as a whole.
Compliance and Risk Teams
CalPrivacy has already fined organizations for registration failures before the deletion processing obligations even began. August 1 brings the more significant enforcement surface: $200 per request per day with no cure period. The organizations most exposed are the ones that assumed the data broker framework applied only to companies that explicitly sell data as a primary business model — and have not assessed whether their actual data practices bring them within scope.
For Organizations
- Conduct a formal data broker classification assessment against California's definition, including the CPPA's expanded direct relationship regulations, for every data flow in your organization.
- Map every vendor in your data ecosystem — enrichment, identity resolution, audience activation, location intelligence — and confirm whether each is registered as a California data broker.
- Assess whether any of your own data activities — collection, licensing, sharing for advertising or analytics value — meet the functional definition of data brokering under current California law.
- Confirm you have DROP integration ready if you are a registered data broker, and that you can process deletion requests across internal systems and vendor chains within the 90-day deadline.
- Document the assessment — both the conclusion and the reasoning — so you have a defensible record if CalPrivacy asks how you determined your registration status.
For Individuals
- Submit a deletion request through California's DROP platform at privacy.ca.gov/consumers/drop if you are a California resident.
- Verify the deletion was completed within 90 days by following up with CalPrivacy if you do not receive a status update.
- Review the registered data broker list at cppa.ca.gov/data_brokers to understand which companies currently hold data about California residents.
Unpopular Opinion
Most organizations that need to assess their data broker status have not done it — not because the law is unclear, but because the answer might be inconvenient. That is exactly the governance failure the CPPA's enforcement program is designed to surface.
Myth vs Reality
Myth: Only companies that explicitly sell data as a primary business model need to think about the Delete Act.
Reality: California's definition reaches any organization that knowingly collects and sells personal information about consumers it does not have a direct relationship with — including sharing data for advertising or analytics value. Marketing operations, enrichment vendors, identity resolution providers, and audience activation platforms all sit in that definition's blast radius. The question is not what your business model is called. The question is what your data actually does.
If a CalPrivacy investigator asked your organization today to explain how you determined you are not a data broker under California law, how confident are you in that answer — and does the documentation exist to support it?
Poll
Has your organization formally assessed whether it qualifies as a California data broker under the CPPA's current definition?