Data Broker Laws
California Data Broker Registration Law: Requirements and Deadlines
What California’s data broker law requires, maintained by Stauss PLLC. Last reviewed August 2026.
What You Need to Know
California's legislature first passed the state's data broker registration law in 2019. In 2023, the California legislature amended the law through passage of the Delete Act. Among other things, the 2023 amendment transferred oversight authority for the data broker registry to CalPrivacy, required data brokers to provide significantly more information when registering, and increased penalties for noncompliance. The Delete Act also charged CalPrivacy with creating a new Delete Request and Opt-out Platform (DROP) to provide California residents with a one-stop shop to request that all registered data brokers delete their personal information. Starting August 1, 2026, data brokers must access the DROP at least once every 45 days to process deletion requests, including directing all service providers and contractors to delete the information. Failure to comply subjects a data broker to a $200 fine "for each deletion request for each day the data broker fails to delete information."
Official law text
How California defines and regulates data brokers
| Who counts as a data broker | A business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationshipnoteDirect relationship means “that a consumer has intentionally interacted with a business for the purpose of accessing, purchasing, using, requesting, or obtaining information about the business’s products or services. A consumer does not have a “direct relationship” with a business if the purpose of their engagement is to exercise any right described under Civil Code section 1798, or for the business to verify the consumer’s identity. A business does not have a “direct relationship” with a consumer simply because it collects personal information directly from the consumer; the consumer must intend to interact with the business. A business is still a data broker and does not have a direct relationship with a consumer as to personal information it sells about the consumer that it collected outside of a “first party” interaction with the consumer, as that term is defined in California Code of Regulations, title 11, section 7001.” |
| Which businesses it applies to | Must qualify as a business under California Consumer Privacy Act |
| Information covered | “Personal information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. Personal information includes, but is not limited to, the following if it identifies, relates to, describes, is reasonably capable of being associated with, or could be reasonably linked, directly or indirectly, with a particular consumer or household: (A) Identifiers such as a real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, social security number, driver’s license number, passport number, or other similar identifiers. (B) Any personal information described in subdivision (e) of Section 1798.80. (C) Characteristics of protected classifications under California or federal law. (D) Commercial information, including records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies. (E) Biometric information. (F) Internet or other electronic network activity information, including, but not limited to, browsing history, search history, and information regarding a consumer’s interaction with an internet website application, or advertisement. (G) Geolocation data. (H) Audio, electronic, visual, thermal, olfactory, or similar information. (I) Professional or employment-related information. (J) Education information, defined as information that is not publicly available personally identifiable information as defined in the Family Educational Rights and Privacy Act (20 U.S.C. Sec. 1232g; 34 C.F.R. Part 99). (K) Inferences drawn from any of the information identified in this subdivision to create a profile about a consumer reflecting the consumer’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes. (L) Sensitive personal information. |
| Other provisions | Third-party audit requirement starting July 1, 2028 |
| Penalties | $200 per day for failing to register + $200 per day for each deletion request not processed |
Compliance requirements5
| Requirement | Applies? |
|---|---|
| Annual Registration Requirement | Yes |
| Registration Disclosure Obligations | Yes |
| Privacy Policy Disclosure Obligations | Yes |
| Creates Substantive Consumer Rights *But creates DROP mechanism through which consumers can exercise rights | No |
| Delete Request & Opt-out Platform (DROP) Data brokers must process requests starting Aug. 1, 2026 | Yes |
Key dates10
| Date | What happens |
|---|---|
| August 1, 2026 | California data brokers must access an accessible deletion mechanism at least once every 45 days and process deletion requests |
| January 31, 2027 | Annual deadline for California data brokers to register |
| July 31, 2027 | Annual deadline for California data brokers to update their privacy policy with consumer request metrics |
| January 1, 2028 | Deadline for California data brokers to undergo a third-party audit to determine compliance with the Delete Act (must be completed every three years) |
| January 31, 2028 | Annual deadline for California data brokers to register |
| July 31, 2028 | Annual deadline for California data brokers to update their privacy policy with consumer request metrics |
| January 31, 2029 | Annual deadline for California data brokers to register; starting this year, California data brokers must also disclose whether they have undergone a third-party audit |
| July 31, 2029 | Annual deadline for California data brokers to update their privacy policy with consumer request metrics |
| January 31, 2030 | Annual deadline for California data brokers to register |
| July 31, 2030 | Annual deadline for California data brokers to update their privacy policy with consumer request metrics |
One link, every dated item SPARC tracks — Consumer Privacy, Data Broker, and AI Laws, not just this table.
Subscribe now (opens your default calendar app)
https://staussfirm.com/sparc/calendar.ics
Google Calendar: Settings → Add calendar → From URL → paste the link above.
Outlook: Add calendar → Subscribe from web → paste the link above.
Questions about California’s data broker law?
Stauss PLLC advises companies on state privacy, AI, and data broker compliance.
Contact Stauss PLLCFollow California’s data broker law
Our analysis, by email, as the law moves.
This page is provided for general informational purposes only, is not legal advice, and does not create an attorney-client relationship. State laws change frequently; coverage reflects this tool’s most recent update. Contact Stauss PLLC to confirm how these requirements apply to your organization.
