conformitedata brokercalifornia delete actdata regulationbase legaleSeptember 7, 2026

Is Your Organization a California Data Broker? A Compliance Guide

Navigating the 'Direct Relationship' test and the operational costs of the new 45-day DROP deletion mandate.

As of August 1, 2026, the operational landscape for data monetization in the United States has undergone a fundamental shift. California data brokers are now required to interface with the state's "DROP" (Data Rights Oversight Portal) platform every 45 days to process centralized consumer deletion requests. For data owners, this requirement transforms compliance from a passive registration task into a high-frequency operational burden, while data buyers must now account for the increased risk of shrinking dataset volumes and potential chain-of-title liabilities.

Defining the 'Data Broker' Under California Law

The threshold for being classified as a data broker in California is deceptively simple but carries heavy legal weight. According to the California Privacy Protection Agency (CPPA), a data broker is defined as a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship (https://privacy.ca.gov/data-brokers/).

The "direct relationship" clause is the primary battleground for SMEs and organizations sitting on proprietary data. If you are a mobile app developer selling location data of your own users, you generally have a direct relationship. However, if you aggregate that data with third-party signals or purchase secondary datasets to enrich your own before selling the resulting insights, you may inadvertently cross the threshold into broker status. Before initiating any sale, it is critical to audit what you can legally sell under privacy frameworks to ensure your business model does not trigger unintended regulatory oversight.

The Operational Reality of the DROP Platform

The California Delete Act (SB 362) moved beyond simple disclosure. The introduction of the DROP platform creates a centralized "kill switch" for consumers. For registered brokers, the requirements are now strictly cyclical:

  • 45-Day Processing: Organizations must access the DROP platform every 45 days to retrieve and implement deletion requests (https://www.jdsupra.com/legalnews/drop-is-coming-due-what-california-s-8270453/).
  • Continuous Deletion: Once a consumer makes a request via DROP, the broker must not only delete existing data but also ensure that no new data from that consumer is sold or shared moving forward.
  • Audit Requirements: Starting in 2028, brokers will be subject to independent audits every three years to verify compliance with these deletion mandates.

The Financial Stakes: Fees and Penalties

Compliance is no longer a low-cost administrative exercise. The disclosed annual registration fee for data brokers is $400 (https://privacy.ca.gov/data-brokers/), which funds the CPPA’s oversight activities. However, the cost of non-compliance is significantly higher.

Failure to register as a data broker when required carries a disclosed administrative fine of $200 per day (https://cppa.ca.gov/announcements/pdf/20231010_press_release.pdf). For a mid-sized firm, a year of unregistered activity could result in over $73,000 in fines, plus the costs of the mandatory audit and potential civil penalties. For buyers browsing an institutional-grade dataset catalogue, the presence of a seller on the California Data Broker Registry has become a primary due diligence filter.

Strategic Implications for Data Buyers and Sellers

For Data Owners, the decision to act as a broker must be weighed against the operational overhead. The 45-day deletion cycle requires a robust data engineering pipeline capable of identifying and purging specific records across all production and backup environments. If your data monetization revenue does not significantly exceed the cost of maintaining this pipeline and the $400 annual fee, a direct-to-consumer or first-party data model may be more sustainable.

For Data Buyers, the DROP platform introduces "dataset decay." As more consumers utilize the centralized deletion tool, the volume of available third-party data is expected to decrease. Buyers must now demand transparency regarding how sellers handle DROP requests to ensure that the datasets they acquire do not contain "toxic" records that should have been deleted, which could lead to secondary liability under the CCPA/CPRA.

What this means for you

Whether you are listing assets or acquiring them on d-nvest, the California Data Broker Registry is now a critical component of your risk-adjusted valuation. If you meet the criteria for a data broker, immediate registration and integration with the DROP platform are non-negotiable for maintaining the marketability of your assets. For buyers, prioritizing sellers with a direct relationship to their consumers is the most effective way to hedge against the volatility of the third-party data market.

Get the next analysis

One deep-dive per edition on where valuable data is hiding — the evidence, the sources, and who would pay for it. No noise.

One email per edition. Unsubscribe any time. We never share your address.

From the marketplace

Explore live data opportunities

Browse datasets by sector & use-case
Found this useful? Share it

d-nvest turns the data assets behind these deals into scored, actionable opportunities.

Explore the pipeline →