The Data Broker You Didn't Know You Were | Privacy Pulse
Data Privacy & Enforcement

The Data Broker You Didn't Know You Were

Privacy Pulse — Civora Advisory 8 min read
Week 14 · Q3 2026

Why You Should Care

More than 260,000 California deletion requests are queued and waiting. August 1 is the enforcement deadline. The biggest compliance risk is not failing to process a deletion request — it is never realizing your organization should have been prepared to receive one.

260K+
Deletion requests queued as of April 2026
$200
Per request per day, no cure period
$1.5B
Theoretical liability, one missed cycle — per CPPA General Counsel
Aug 1
Processing obligation begins

A marketing operations director is reviewing the company's customer acquisition strategy.

Everything looks familiar.

Website analytics. CRM data. Advertising platforms. Lead enrichment. Location intelligence. Identity resolution.

Then a privacy attorney asks a simple question:

"Have we determined whether our enrichment vendor qualifies as a California data broker?"

Silence.

Another question follows.

"If they qualify… are we sure we don't?"

What started as a routine vendor review suddenly becomes a governance problem.

Many Organizations Think They Purchase Intelligence. Some May Actually Be Data Brokers.

The same data ecosystem that makes modern marketing more effective can also move an organization into an entirely different regulatory category.

Many organizations think they simply purchase marketing intelligence. Some may actually be operating within California's data broker framework — and the definition is broader, and the enforcement more imminent, than most have assessed.

The biggest compliance risk is not failing to process a deletion request. It is never realizing your organization should have been prepared to receive one.

The Law, the Deadline, and the Definition Most Organizations Have Not Assessed

California's Delete Act (SB 362) created a centralized Delete Request and Opt-Out Platform — DROP — that allows California residents to submit a single deletion request to every registered data broker simultaneously. The platform opened January 1, 2026. As of April 2026, more than 260,000 Californians had already submitted requests, queued and waiting for processing. Starting August 1, 2026, registered data brokers — currently more than 600 companies — must access DROP at least once every 45 days, process deletion requests within 90 days of retrieval, delete all associated personal information including derived inferences, and report request status back to the California Privacy Protection Agency. The penalty for non-compliance is $200 per request per day with no cure period.

California Privacy Protection Agency General Counsel Phil Laird stated publicly at the 2026 IAPP Global Summit that one missed 45-day cycle carries $1.5 billion in theoretical liability for a single large-scale data broker — a ceiling, not a forecast, but the ceiling the law permits. CalPrivacy has already demonstrated enforcement willingness: Honda was fined $632,500 in a CPPA enforcement action, Accurate Append was fined $55,400 in July 2025, and National Public Data was fined $46,000 in May 2025 — all for registration failures, before the deletion processing deadline even arrived.

The definition of "data broker" is the governance problem most organizations have not formally assessed. California law defines a data broker as a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship. Recent CPPA regulations tightened that definition significantly: a business does not have a direct relationship simply because it collects data directly from a consumer — the consumer must intend to interact with that business. Direct relationships also expire three years after a consumer's last interaction. And selling data is not limited to financial transactions — sharing data in exchange for analytics, advertising services, or other valuable consideration qualifies. Many organizations using enrichment, identity resolution, audience activation, or data licensing services have not formally assessed where they sit in this framework.

5-Question Compliance Check

Do You Know Whether You Are a Data Broker?

1

Does your organization collect or sell personal information that it did not collect directly from consumers — or that consumers did not intentionally provide to you for your own products or services?

2

Do you purchase, license, enrich, or receive consumer data from third parties, and does any of that data leave your organization — in any form, for any consideration including analytics or advertising services?

3

Could your marketing operations, data products, or vendor relationships meet California's definition of a data broker under the CPPA's expanded "direct relationship" regulations, including the three-year expiration rule?

4

Have you formally assessed whether your enrichment vendors, identity resolution providers, and data partners are registered California data brokers — and confirmed whether their obligations flow downstream to you?

5

If DROP deletion requests arrived tomorrow, could your organization actually honor them across internal systems, data vendors, and service providers within the 90-day processing deadline?

Who This Affects and How

Marketing and Data Teams

The data ecosystem your team uses for audience targeting, enrichment, and identity resolution may include registered data brokers — and if your organization processes or resells that data in ways that lack a direct consumer relationship, you may have registration and deletion processing obligations you have not assessed. The question is not whether you think of yourself as a data broker. The question is whether California's definition applies to what you actually do.

Legal and Privacy Teams

The CPPA's expanded "direct relationship" definition is the governance question most organizations have not formally answered. A company can have a direct relationship with a consumer in one context and still qualify as a data broker for other datasets it acquires indirectly and sells. Your legal assessment needs to address each data flow independently — not the organization as a whole.

Compliance and Risk Teams

CalPrivacy has already fined organizations for registration failures before the deletion processing obligations even began. August 1 brings the more significant enforcement surface: $200 per request per day with no cure period. The organizations most exposed are the ones that assumed the data broker framework applied only to companies that explicitly sell data as a primary business model — and have not assessed whether their actual data practices bring them within scope.

For Organizations

For Individuals

Unpopular Opinion

Most organizations that need to assess their data broker status have not done it — not because the law is unclear, but because the answer might be inconvenient. That is exactly the governance failure the CPPA's enforcement program is designed to surface.

Myth vs Reality

Myth: Only companies that explicitly sell data as a primary business model need to think about the Delete Act.

Reality: California's definition reaches any organization that knowingly collects and sells personal information about consumers it does not have a direct relationship with — including sharing data for advertising or analytics value. Marketing operations, enrichment vendors, identity resolution providers, and audience activation platforms all sit in that definition's blast radius. The question is not what your business model is called. The question is what your data actually does.

Privacy Pulse — where law, technology, and human dignity meet.

If a CalPrivacy investigator asked your organization today to explain how you determined you are not a data broker under California law, how confident are you in that answer — and does the documentation exist to support it?

Poll

Has your organization formally assessed whether it qualifies as a California data broker under the CPPA's current definition?

Yes — formal assessment completed and documented
In progress — we are reviewing our data flows now
Not yet — we assumed it did not apply to us
We were not aware the definition had been expanded
#PrivacyPulse #DataBrokers #CaliforniaPrivacy #DeleteAct #DataGovernance